Listing Thumbnail

    Qualys TotalCloud

     Info
    Sold by: Qualys 
    Deployed on AWS
    Free Trial
    AWS Free Tier
    Qualys TotalCloud: Making your cloud secure by providing the only solution that assesses, communicates and eliminates an organization's security risk.
    4.3

    Overview

    TotalCloud is a Cloud Native Application Protection Platform (CNAPP) built to detect, prioritize, and mitigate risks within multi-cloud and hybrid-cloud environments. As the most thorough cloud security solution, TotalCloud identifies, ranks, and facilitates the remediation of risks from key vulnerabilities, misconfigurations, and threats that other tools might miss, including potential attack paths and lateral movements targeting critical cloud resources. By integrating a wide range of solutions, including CSPM, KSPM, CWPP, CIEM, CDR, Workflow Automation and Remediation, TotalCloud provides a seamless cloud security management experience, without the complexity of managing multiple tools. For more details: https://www.qualys.com/apps/totalcloud/ 

    *Qualys provides custom pricing for customers via Private Offer. Please contact https://www.qualys.com/forms/request-a-call/  for a better understanding of our pricing model and products.

    Highlights

    • 6 Sigma Accurate Vulnerability Prioritization:Combines threat feeds from over 25 sources to create a unified vulnerability score. This score dynamically adjusts risk priorities based on patch availability, vulnerability criticality, and organizational context.
    • Integrated no-code/low-code remediation: Enable custom remediation workflows out of the box with Qualys QFlow Cloud Workflow Automation, allowing drag and drop of no-code/low-code workflows.
    • FlexScan : Allows security teams to combine agent and agentless scanning for workload protection across ephemeral and long-lived environments, including hosts, VMs, Containers, Kubernetes, and Serverless setups.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Qualys TotalCloud

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Total Cloud package 16
    Package of 16 Hosts for Total Cloud
    $5,400.00

    AI Insights

     Info

    Dimensions summary

    This listing offers one contract package covering 16 hosts of Qualys TotalCloud. Pricing works as a fixed bundle, priced per unit, where each unit represents one package of 16 hosts. To cover more hosts, you buy additional packages, so cost scales in blocks of 16 rather than one host at a time. TotalCloud is a cloud security platform that discovers assets, manages posture and compliance, and prioritizes risk across cloud and container environments. This package gives you access to those capabilities for the host count you commit to under the contract term.

    Top-of-mind questions for buyers

    A host is a workload the platform discovers and protects across cloud and container environments. This includes virtual machines and compute instances. Each virtual machine counts as one host, even when several share a physical machine. Container hosts are also counted. One package covers 16 such hosts.
    Coverage scales in blocks of 16. To protect more hosts, you buy additional packages, each adding another 16 hosts of coverage. Cost rises in fixed increments rather than one host at a time. Plan your purchase around the total host count you expect during the contract term.
    The package gives access to TotalCloud capabilities for your covered hosts. This includes asset discovery, cloud security posture and compliance management, container security, risk-based prioritization, and automated remediation workflows. These capabilities apply across cloud and container environments. Coverage is limited to the number of hosts you purchase.
    www.qualys.com
    Helpful?

    Vendor refund policy

    Licensed Qualys customers should refer to their Service User Agreement (SUA) or contact their Qualys Technical Account Manager if they have questions about refund or cancellation policies which would apply to them

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Qualys' policy is to respond to all Qualys customer cases promptly as per SLA. An incident ticket is assigned a priority number based on the nature of the issue. || Service Level Agreement (SLA): https://www.qualys.com/support/sla/  https://www.qualys.com/support/  || support@qualys.com  || US/Canada: +1 (866) 801-6161 (toll free) or +1 (650) 801-6161 || UK/Europe/International: +44 (0)1753 872102 || France: +33 1 41 97 35 81

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.3
    49 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    51%
    47%
    2%
    0%
    0%
    16 AWS reviews
    |
    33 external reviews
    External reviews are from G2  and PeerSpot .
    Sanchit Makkar

    Unified control plane has improved multi-cloud visibility and accelerated vulnerability remediation

    Reviewed on Sep 19, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Qualys TotalCloud for the last eight months to scan the hardware and the virtual devices in our infrastructure.

    Our main use case for Qualys TotalCloud is to secure our multi-cloud environment containers and workloads across AWS, Azure, GCP, and OCI as a single control plane.

    Having a single control plane helps my team manage those multi-cloud environments more efficiently because it allows us to consolidate multiple cloud assets, configurations, and security postures into a single dashboard.

    We also use Qualys TotalCloud to automate remediation plans, which offers one-click fixes and workflows that automate the resolution of misconfigurations quickly.

    What is most valuable?

    In my experience, the best feature Qualys TotalCloud offers is the FlexScan feature, which delivers multi-modal asset discovery using agentless and agent-based network and pipeline scanning.

    The FlexScan feature has benefited our environment because we recently found a vulnerability rated high to medium risk in our assets, which we were able to discover and fix using Qualys TotalCloud.

    Qualys TotalCloud positively impacts our organization by helping to minimize downtime in relation to asset scanning and by improving the overall cyber inputs in the enterprise.

    Since using Qualys TotalCloud, we have noticed faster remediation times and improved compliance because the single scanning dashboard allows us to see all our assets in multi-cloud as well as on-premises deployment, which helps the cyber team quickly remediate any open vulnerabilities across different assets.

    What needs improvement?

    In terms of improvements, the features we are using in Qualys TotalCloud are working in the best optimal way, and I do not have any suggestions for them.

    I chose a rating of nine out of ten because there is a complex interface that sometimes overwhelms new engineers. One would need additional training and learning to cope with day-to-day activities, and I feel they can improve the overall layout of the console for initializing scans across different assets.

    For how long have I used the solution?

    I have been working in the network domain for the last twelve years.

    What do I think about the stability of the solution?

    Qualys TotalCloud is stable in my experience.

    What do I think about the scalability of the solution?

    Qualys TotalCloud's scalability is high because it allows us to scale agent-based probing and scanning of our assets in a multi-vendor environment whenever we want, and it can be deployed on hypervisors, public and private clouds as well as hardware infrastructure.

    How are customer service and support?

    I have not had any interaction with customer support, but from what I have heard, it is good.

    How was the initial setup?

    I was not involved in the pricing, setup cost, or licensing of Qualys TotalCloud, as I am the administrator of this tool.

    What was our ROI?

    We have seen a return on investment since using Qualys TotalCloud, as we are able to scan all our assets with less human intervention and achieve overall effective outcomes.

    What other advice do I have?

    Regarding Qualys TotalCloud's AI capabilities, I have not noticed any reliability issues or anything worth mentioning; it is overall the best tool available in the market for scanning purposes.

    Qualys TotalCloud is deployed on-premises in our physical data centers.

    Qualys TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS, and this unified view has helped our overall cloud security posture management by reducing false positives in our scanning results. Qualys has made the scanning and performance of all assets quite effective.

    The TrueRisk Insights feature has helped in unified risk prioritization by consolidating vulnerabilities, misconfigurations, and threat intelligence into a single risk score, allowing our team to fix critical issues first.

    I assess the comprehensiveness of FlexScan in providing visibility across our on-premises, multi-cloud, and container environments as excellent because it allows our organization to combine agentless scanning for quick setup with agent-based scanning for deep continuous operating system inspections.

    Qualys TotalCloud has helped my team identify hidden cloud, runtime, data, identity, SaaS, application, or Shadow AI exposures before they became exploitable risks by providing a single control plane that reduces the need for separate security tools for different cloud vendors.

    We are using Qualys TotalCloud's flexible scanning options, specifically agent-based scanning, to improve coverage across long-lived and ephemeral cloud workloads.

    My advice for others looking into using Qualys TotalCloud is to be vigilant about the vulnerabilities that emerge and to have a remediation plan in place, as Qualys TotalCloud may trigger a lot of risks and vulnerabilities across many different assets in a multi-cloud environment. I provide this product with a rating of nine out of ten.

    reviewer2859021

    Risk-based triage has transformed container security and now prioritizes high-impact threats

    Reviewed on Sep 18, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been using Qualys TotalCloud for two years.

    My main use case for Qualys TotalCloud is vulnerability management.

    As a specific example of how I use Qualys TotalCloud for vulnerability management, it creates a Jira ticket for any vulnerability that it finds in our containers, as well as in any of our platforms and other cloud resources.

    What is most valuable?

    The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances.

    In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.

    What needs improvement?

    Qualys TotalCloud could be improved by enhancing the UI/UX experience; the console interface looks very outdated and should be more modern. Additionally, there should be direct developer remediation, as it lacks automated pull request generation for infrastructure fixes in GitHub, leaving manual patching work for the developers.

    For how long have I used the solution?

    I have been using Qualys TotalCloud for two years.

    What do I think about the stability of the solution?

    Qualys TotalCloud is stable because we are very happy with the results. It has no downtime currently, so we have been scanning. It depends on whether we are using the back-end collection, but it has a lot of scanning mechanisms, which are agentless APIs, eBPF, and cloud agents, that are highly reliable.

    What do I think about the scalability of the solution?

    Qualys TotalCloud's scalability is highly scalable because it has multi-cloud API connectors, and it does Kubernetes and container scaling. It reliably ingests and processes security telemetry for large multi-cloud environments. Though security teams operate at a massive scale, we expect occasional lag during heavy data indexing cycles.

    How are customer service and support?

    Customer support with Qualys TotalCloud needs a little improvement with the response times. Other than that, they are technically capable, but occasionally they are slow on low-tier tickets.

    Which solution did I use previously and why did I switch?

    I used a different solution previously, but I cannot disclose the name of it. Comparing it with TotalCloud, it allowed our team to shift from volume scanning to context-aware risk management. Qualys TotalCloud was a better solution for us.

    How was the initial setup?

    I was not involved in pricing, setup cost, and licensing, but I can say that the setup was fast, within a quarter, and it scales well with a stable infrastructure. I think it is highly dynamic.

    What was our ROI?

    I was not involved in the investment part of it, but I definitely know that it has delivered a high return on investment based on the drastically reduced triage labor and tool consolidation, rather than reducing the headcount outright.

    What's my experience with pricing, setup cost, and licensing?

    I was not involved in pricing, setup cost, and licensing, but I can say that the setup was fast, within a quarter, and it scales well with a stable infrastructure. I think it is highly dynamic.

    What other advice do I have?

    My overall impression of the combination of detection and protection features in Qualys TotalCloud is that we were using another vulnerability management tool. The reason we changed was because Qualys has risk prioritization, CVE depth, and unified patch management. It is excellent at cutting down on false positives using runtime network context, and it focuses on pipeline prevention and guided workflow remediation.

    TruRisk has fundamentally shifted our cloud security from reactive vulnerability management to targeted, business-context risk reduction. Instead of just flagging an isolated CVE, TruRisk tells us a narrative, such as, "This isn't just a CVSS flaw; it is a publicly accessible virtual machine running an actively exploited vulnerability with root privileges." TruRisk insights isolate 2% to 3% of workloads.

    Using TruRisk to mitigate noise from raw CVEs has transformed our vulnerability management, shifting teams away from basic CVSS scores and toward risk-driven reduction. In practice, relying strictly on CVSS results in an overwhelming alert volume, with 40% to 50% of the environment labeled as critical. TruRisk typically reduces the actionable queue to the top 2% to 5% of assets that pose a real operational danger.

    FlexScan has strong, multi-layered visibility across diverse environments by letting us blend agentless and agent-based assessment methods into a single view. Its overall comprehensiveness varies slightly depending on the specific tier of my stack. For us, it is mostly the container and Kubernetes environment, and the visibility is in-depth. Combining eBPF sensor technology allows for deep execution monitoring inside Kubernetes pods and hosts. It also scans container images, registries, and infrastructure as code before deployment, catching flaws upstream.

    Qualys TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS environments. This is achieved by CSPM, CWP, and SSPM for a unified engine. For example, in IaaS, an S3 bucket or a GCP storage account might be restricted to internal access. However, if a user lacks MFA or has compromised credentials with wide-ranging read access to both SaaS and cloud infrastructure, TotalCloud will flag this combination as a risk factor. Seeing identity and infrastructure together prevents attackers from abusing over-privileged SaaS accounts to pivot to IaaS assets.

    Automating the risk-based triage with Qualys TotalCloud has freed up significant engineering bandwidth every week. This lets the team focus on proactive security architecture, platform automation, and strategic initiatives rather than manual ticket triage. There were around 10,000 tickets, but we are now able to track them sooner and faster and assign them to the correct teams to fix.

    Once it is set up, Qualys has proved to be one of our greatest assets. I rate this product an overall 8 out of 10.

    reviewer2875785

    Risk-based visibility has transformed how I prioritize cloud vulnerabilities and protect key assets

    Reviewed on Aug 21, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I mainly use Qualys TotalCloud for vulnerability management and cloud security to identify vulnerabilities in cloud assets, assess their severity, prioritize remediation, and track the overall security posture.

    When reviewing cloud assets for newly identified vulnerabilities, I check the vulnerability details and severity in Qualys TotalCloud, prioritize the high-risk findings, and share the remediation requirements with the relevant team while following up on progress.

    I found the visibility provided across cloud assets useful in Qualys TotalCloud as it made it easier to identify high-risk vulnerabilities, prioritize them based on severity, and track the remediation with the relevant teams.

    The AI governance and security capabilities of Qualys TotalCloud are useful, especially for visibility and risk control. From my experience, I primarily value having visibility into AI-related assets and configurations and being able to identify security or compliance risks. The risk-based approach also helped me prioritize the issues that needed attention first.

    What is most valuable?

    The best features Qualys TotalCloud offers are cloud asset visibility, vulnerability assessment, and risk prioritization. This risk-based prioritization helped me quickly identify high-risk vulnerabilities and focus on remediation instead of going through every finding. TrueRisk-based prioritization is useful for understanding which vulnerabilities need attention first.

    It improved our workflow mainly by giving us a single view of cloud assets and their risk, so we could focus on the higher priority vulnerabilities instead of reviewing every finding manually. This helped us prioritize remediations more efficiently and reduce the time spent on vulnerability assessment and follow-up.

    Qualys TotalCloud helped us identify exposures that might otherwise have been missed, especially across cloud assets, vulnerabilities, and identities. With the SaaS configuration, the unified inventory and risk view made it easier to connect vulnerabilities with asset criticality, exposure, and access permissions, allowing us to investigate high-risk exposures first and address them before they could become bigger security issues.

    What needs improvement?

    One thing that could be improved is the user experience and navigation. With the amount of information available, it can sometimes take a few extra steps to get to the exact vulnerability or asset details that I needed. I believe that is the only improvement needed.

    For how long have I used the solution?

    I have used Qualys TotalCloud for one year.

    What do I think about the stability of the solution?

    Qualys TotalCloud is stable according to my experience, and I did not find any downtime or related issues.

    What do I think about the scalability of the solution?

    I had a good experience with the scalability of Qualys TotalCloud because it scales very well as the number of assets or cloud workload increases.

    Which solution did I use previously and why did I switch?

    We did not use a different solution before Qualys TotalCloud.

    How was the initial setup?

    I recommend starting with a clear asset and inventory and properly configuring the cloud connector first. Once the environment is visible, it is important to spend time understanding TrueRisk prioritization instead of treating every severe finding equally. The initial setup and tuning of connectors, permissions, and policies is also important.

    What was our ROI?

    I do not have any relevant metrics available, but I can definitely say Qualys TotalCloud has saved our time by giving us better asset visibility and risk-based prioritization, as it has reduced the time spent manually reviewing CVEs and deciding what to address first.

    What other advice do I have?

    I found the overall asset visibility with the unified risk view useful, as having vulnerabilities, cloud assets, and risk context in one place made investigation easier and reduced the need to switch between different tools.

    It has helped me focus on the vulnerabilities that actually needed attention instead of treating every finding equally, as I used the risk score and asset context to identify higher risk issues first, making it easier to prioritize remediation and reduce the time spent manually reviewing lower risk findings.

    I found the output generally reliable for identifying and prioritizing security risks, as the results were useful for deciding which findings needed attention first, although I would still validate the important findings before taking any remediation actions.

    It helped identify a smaller set of assets with higher TrueRisk scores. I use that information to prioritize those assets for further investigation, review the vulnerabilities and exposures contributing to the score, and coordinate remediation with the relevant teams. This helped us focus on the assets with higher potential impact instead of treating all vulnerabilities equally.

    TrueRisk helps reduce the noise from raw CVEs by putting them into business and threat context. Instead of treating every high severity CVE equally, we could focus on vulnerabilities that were actually more likely to be exploited or affect important assets, which made prioritization and remediation much more efficient.

    Overall, I have a positive impression of the combination of detection and protection features in Qualys TotalCloud. The main advantage for me is having vulnerability assessment, cloud posture monitoring, and risk prioritization in one platform. Compared with more point-focused solutions, Qualys TotalCloud gives us a more unified view which makes it easier to prioritize risks and decide what needs attention first. I rate this review a 10 out of 10.

    reviewer2866401

    Cloud risks have been prioritized with unified visibility and automated multi-cloud monitoring

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously.

    Previously, we were just looking at critical vulnerabilities and patching them. Now with Qualys TotalCloud, we can distinguish between critical vulnerabilities and what is internet-facing, what is a sensitive workload, and excessive permissions that are given to unauthorized users in the cloud environment. This gives us more visibility towards what is happening in the cloud.

    Another use case I have for Qualys TotalCloud is identifying misconfigurations within the cloud environment and how any configurations might impact the organization's cloud assets. Those were the two main use cases.

    The integration with Qualys TotalCloud worked very well with tools such as Exonius and Splunk, wherein we were easily getting automated alerts and incidents that we could automate into emails and reach out to stakeholders without manual intervention.

    Qualys TotalCloud is definitely helpful for our vulnerability management. It did help in CSPM and also in looking at cloud inventory, not just when a vulnerability or misconfiguration is happening, but I could look at what is happening in my cloud environment, who is really having any entitlements, what access exists, what unauthorized access anyone has, and so on.

    Qualys TotalCloud does provide both IaaS and SaaS when it comes to threat assessment.

    EASM finds assets that are exposed to the internet such as domains, IPs, applications, and services. When it comes to SaaS, it assesses the SaaS applications and their security posture. We could also look at what SaaS services we are using and what risks they introduce.

    We were narrowing the risk and threat down to a much smaller group of assets where multiple factors came together. For example, a highly vulnerable asset that was internet-facing and business-critical had additional exposure of configuration issues. We used those insights to prioritize the assets for immediate remediation.

    What is most valuable?

    Qualys TotalCloud is a one security platform where we could leverage the existing Qualys platform and not any other different agent or different platform for cloud visibility and cloud security. We had multi-cloud visibility where both AWS and Azure could be controlled and monitored for misconfigurations and security issues.

    We had better integration with tools, which is where Qualys TotalCloud was useful.

    TruRisk insights have been useful in helping us move from a traditional vulnerability counting approach to a risk-based approach.

    What needs improvement?

    In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys TotalCloud. Qualys TotalCloud can identify the problem, but changing an AWS security group still requires the appropriate cloud owner or process. If there was also a response capability within Qualys TotalCloud in addition to detection, that would have been better.

    The CNAPP capability is a major feature of Qualys TotalCloud, but when you drill down, there are a lot of modules that you need to enable. I think organizations need to know which modules they need for their use case and for their cloud environment usage. This gives the exact implementation strategy as well.

    For how long have I used the solution?

    I have been using Qualys TotalCloud for one year.

    What do I think about the stability of the solution?

    Qualys TotalCloud is stable.

    What do I think about the scalability of the solution?

    It is pretty scalable in our organization.

    How are customer service and support?

    From what I have experienced, I have had interactions with them a couple of times and it turned out to be good. I would give a nine out of ten.

    What other advice do I have?

    I would give Qualys TotalCloud an eight out of ten rating. The remaining two points I would take out due to the improvements I have mentioned.

    The biggest strengths of Qualys TotalCloud are that it is pretty good at cloud visibility, has easy integration, and also has multi-cloud compatibility.

    I would probably do a traditional CVE-based approach otherwise. A large number of vulnerabilities can be classified as critical or high, but treating all of them with the same priority is not practical.

    Qualys TotalCloud compares well because it combines breadth and integration. I am pretty sure VMDR gives strong vulnerability visibility. But when we want visibility for the cloud environment, that is where Qualys TotalCloud comes into the picture. The biggest advantage is correlating the findings that we receive from these security tools and through the risk prioritization and managing the entire cloud ecosystem.

    Prajwal Chougale

    Centralized visibility has streamlined cloud security posture and accelerated vulnerability remediation

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I primarily use Qualys TotalCloud for Cloud Security Posture Management, vulnerability management, asset visibility, and continual monitoring of cloud assets, maintaining the cloud resources that we use.

    One of the main advantages for us is having multiple security capabilities available through this tool, instead of maintaining several completely separate tools for each one of them, such as vulnerability management, audit asset visibility, and cloud security management.

    During our security rehearsal or weekly customer meetings, we need to check about site compliance, and Qualys TotalCloud was very helpful because instead of using other tools where we had to pull reports from different sources, we could check compliance all in one place.

    When one hundred fifty vulnerabilities were identified on cloud, production, or any endpoint, it was useful for us to identify which asset was affected and to look at the details and share the findings with the customer and the remediation infrastructure team.

    What is most valuable?

    Qualys TotalCloud offers several valuable features, including monitoring visibility as an EDR tool and cloud asset inventory capabilities, which help in centralized asset management and prioritizing risk.

    It is particularly useful because it gives us visibility across cloud resources from different environments in one place, making it easy for organizations to understand their security postures without manual checking with cloud consoles.

    The vulnerability management capabilities are another strong point where we can review security risks for vulnerabilities on cloud workloads and prioritize issues based on CVSS scores.

    When we were using different cloud solutions, it was tedious to find compliance for assets, especially during monthly meetings.

    Qualys TotalCloud is very useful in day-to-day security operations, particularly at monthly review meetings. It was helpful to maintain all the assets in one place, and when investigating vulnerabilities, we can first identify affected cloud assets from the inventory and look at their release details and security findings which helps in understanding the actual scope of an issue and identifying which team needs to take action.

    I believe it saves us more time because we do not have to gather asset information from different sources and tools. We can search and filter inventory, group assets, and use asset context to move quickly from understanding what an asset is to identifying required security patches.

    Qualys TotalCloud has positively impacted our organization by helping us save time and manage all assets and remediation, allowing us to achieve quarterly and half-yearly goals.

    It has improved our visibility and made vulnerability management more structured, helping us reach our remediation goals while reducing manual effort from security reporting and patch management.

    Before implementing Qualys TotalCloud, we used to have around ten thousand vulnerabilities on critical servers, and after using it, we reduced the vulnerabilities by thirty to forty percent in just two months.

    We could identify vulnerabilities and their affected assets within five to ten minutes. This has also improved our investigation efficiency, allowing the team to spend more time on actual remediation rather than data collection.

    What needs improvement?

    Regarding improvements to Qualys TotalCloud, I suggest that user navigation can be enhanced because initially, many users found it complicated and had trouble understanding the platform due to information being spread across multiple tabs.

    Making some dashboards and reports customizable would also help, as different teams have their own requirements.

    I have covered most of the necessary improvements regarding navigation and customizable dashboards, which would help make work easier.

    For how long have I used the solution?

    I have been working as a SOC analyst for almost three years.

    What other advice do I have?

    Most recommendations and findings are accurate and reliable. While the AI output is helpful, it is crucial to validate actions against actual safety configurations, as human intelligence is still necessary in decision-making.

    My advice for others considering using Qualys TotalCloud is that if you want all vulnerability management and cloud asset management in one place, then it is the best solution. Good configuration makes finding vulnerabilities and managing alerts much easier.

    My overall rating for this product is nine out of ten.

    View all reviews