TrustRadius: an HG Insights company

Qualys TruRisk Platform

Score6.1 out of 10

83 Reviews and Ratings

What is Qualys TruRisk Platform?

Qualys TruRisk Platform (formerly Qualys Cloud Platform, or Qualysguard), from San Francisco-based Qualys, is network security and vulnerability management software featuring app scanning and security, network device mapping and detection, vulnerability prioritization schedule and remediation, and other features to provide vulnerability management and network attack surface reduction.

Top Performing Features

  • Automated Alerts and Reporting

    Systems in place to automatically alert, report, or notify of issues that may need timely remediation.

    Category average: 8

  • Network Analytics

    Analyzes various data reports and logs (DNS, firewall, user data, security information etc.) to identify threats in a network.

    Category average: 7.8

  • Threat Intelligence Reporting

    Generates reports that display information on threats (such as name, type, frequency of attack, area affected, etc.)

    Category average: 7.7

Areas for Improvement

  • Threat Recognition

    Detection and recognition of malicious software within a network that could pose a threat to sensitive information.

    Category average: 7.9

  • Threat Analysis

    Analyzing known factors such as behavior patterns, affected areas, and other specific features to more easily identify a threat.

    Category average: 8.1

  • Authentication

    Authentication of users and services within a network to prevent vulnerabilities from being introduced to the network.

    Category average: 8.1

Qualys Cloud Platform is a great program.

Use Cases and Deployment Scope

The performance that we have had with this program has been great since it has been the only program that has offered us a long list of options to scan as well as manage the level of vulnerability in all the applications and websites where our system runs, thanks With the help of Qualys Cloud Platform you can see in detail all the IT services that I use the most.

Pros

  • One of the main features that I like about this program is the multiple options and powerful functions that I have at my fingertips to strengthen the security of my system.
  • Qualys Cloud Platform is a great program that gives the opportunity to all its users to keep track of each of the processes on the web, complying with the mandatory policies and manipulating the least risky applications.
  • Thanks to the support of this program, all my commercial projects on the web are entirely safe; Qualys Cloud Platform will take care of avoiding each of the threats on the web.

Cons

  • This program is really complicated, the multiple functions that are presented to us are not very clear and in some cases, it is a matter of intuition to execute a function, it is not very informative.
  • The interface of this program can be a real problem; for our taste, this program looks a bit messy, and the interface does not help or guide you to find the options you need.

Most Important Features

  • The main function of the Qualys Cloud Platform in my workplace is to keep each of the jobs and projects we have on the web secure.
  • Qualys Cloud Platform is by far one of the best programs we test to analyze our vulnerability status and eliminate the multiple threats that constantly attack us.

Return on Investment

  • The most important thing that happens with this program is to automate one hundred percent the security of my system since this program is in charge of supervising each of the applications and websites in detail.
  • One of the purposes for which we trust Qualys Cloud Platform is to keep our system clean and secure; the ability of this software to manage our vulnerability makes us more cautious about working with it.

Other Software Used

Adobe Experience Platform Launch, Accutive Security - Data Discovery and Masking (ADM), Micro Focus Universal Discovery and Universal CMDB

A single guard on door with thousand hands.

Use Cases and Deployment Scope

Integration was one of our key challenges as we were going through a consolidation of many tools. Bringing everything together and getting visibility in one Qualys dashboard has helped us. To secure our IT infrastructure and manage all risks related to our assets in one place is very easy now. Now we can see everything related to asset on dashboard and take action quickly.

Pros

  • Infrastructure Security
  • Network Security
  • Cloud Security
  • Asset Management

Cons

  • Patch Management
  • Application Security
  • Ghost/Shadow Asset Scanning

Most Important Features

  • Asset Management
  • Cloud Security
  • Compliance

Return on Investment

  • It Increases Visibility
  • It robust security posture
  • Sometimes Bit slow because of bandwidth

Alternatives Considered

Tenable.io

Other Software Used

Tenable.io, Tanium, Rapid7 InsightVM

Qualys Policy Compliance - You are covered every second in this Cyber Security world.

Use Cases and Deployment Scope

Qualys Policy Compliance helps an organization to create policy, establish controls, write user-defined controls and manage the entire compliance of the organization. It also has an easy-to-use UI and creates a unified dashboard that helps C-level executives with decision-making based on the security posture of the organization. Based on the reports and dashboard, it's easy to take corrective action.

Pros

  • Controls Management.
  • Unified dashboard for security posture.
  • Organization security policy effectiveness.
  • Ease of configuration.

Cons

  • Some of the tasks to select sensors can be automated.
  • Controls customisation can be improved.
  • Technology support can be improved.

Return on Investment

  • Enhanced security visibility.
  • Better and granular control.
  • Single pane of glass view.

Alternatives Considered

Tenable.sc (formerly SecurityCenter)

Other Software Used

Splunk Cloud, Jira Service Management (Jira Service Desk), Splunk SOAR (Security Orchestration, Automation and Response) (formerly Phantom)

Qualys Cloud: Holistic approach to Cloud Security

Use Cases and Deployment Scope

<div>** To use Qualys Cloud to continuously assess the workloads in the multi-cloud environment and make sure they are in line with our security policies</div><div>** Application Security and Policy Compliance</div><div>** Reduce risk and increase their levels of

compliance in a cost-effective manner</div><div>**Detect and prioritise

vulnerabilities and misconfigurations across the IT estate, as well as

supporting automated patching and remediation activities</div>

Pros

  • Vulnerability management
  • Patch management
  • Reporting and alerting mechanism

Cons

  • Addressing false positives
  • JIRA Integration
  • UI interface could be cumbersome for first time users

Most Important Features

  • Policy Compliance
  • Continuous visibility
  • Web App Scanning

Return on Investment

  • Maintain Compliance Status
  • Streamline risk management program
  • Save on cyber insurance

Alternatives Considered

Nessus and IBM Security QRadar

Other Software Used

Palo Alto Networks Prisma Cloud, VMware Carbon Black EDR, Guardicore

Automated Threat Protection reaches all corners of our organization to provide an end-to-end security solution for the 21st Century

Use Cases and Deployment Scope

Qualys Cloud Platform provides our organization with the tools needed to protect our organization, from end-to-end. It bolsters our security stance in a multi-faceted approach, including our IT infrastructure, our data and applications in the cloud, our endpoints, and compliance all over the world. The best feature of Qualys would be it's automated threat protection which gives us alerts &amp; warnings in realtime, leading to actionable insights that keep our business secure.

Pros

  • Real time threat protection, with alerts & remediation
  • Total visibility into the security of our organization via a single-pane
  • Easily scalable for additional infrastructure, end users, and policy updates

Cons

  • Customer support tends to be slower, often leading to the tail end of guaranteed SLA's
  • Major downside is that QCP charges you for each scanner, leading to high cost
  • False positives can end up wasting more time, rather than saving it

Most Important Features

  • Real time threat protection & quick notifications
  • End to end security solution which includes compliance
  • Much faster detection of Log4J compared to other products we tested/used

Return on Investment

  • Less threats and incidents means more time saved fixing issues, large improvement on our ROI
  • Less vulnerabilities and incidents also means a positive public image, which can greatly impact our business in a negative way, this also provides a large improvement on ROI
  • False positives on threats/risks leads to time wasted remediating, and also makes us question the validity of a threat, mildly negative impact on ROI

Alternatives Considered

Nessus