Listing Thumbnail

    Avalor Data Fabric for Security

     Info
    Sold by: Avalor 
    Avalor's Data Fabric for Security™ automates data integration, enrichment, and cross-contextualization, providing security organizations a complete and real-time view of their cybersecurity posture.
    3.9

    Overview

    Avalor is on a mission to transform the way security teams use data, making every piece of security data useful for better decisioning in one comprehensive solution. Security teams leverage many solutions to secure their technology, all of which produce a lot of valuable data. The missed opportunity is that the data is siloed, often duplicative, and inefficient as systems and people don't often talk to each other. This makes connecting the dots in your security program a real challenge. That is, until now. Avalor's proprietary Data Fabric for Security™ ingests, normalizes, and enriches data from any source, with zero friction, providing a complete and real-time view of your cybersecurity posture in a way your teams need to see it. With full control over their data, security teams can understand and take action on a multi-dimensional view of risk quickly and efficiently. Avalor's flexible platform empowers teams with the architecture to connect any data across their entire security stack, enhance their workflows with critical business context, and expand into any use case to support and optimize security operations. With Avalor's Unified Vulnerability Management application, customers can seamlessly blend multiple sources with business context to build actionable insights that power full cycle risk assessment, prioritization, remediation dispatch, and analytics - customized entirely to their organizational needs.

    Highlights

    • Aggregate, normalize, de-duplicate, and track risk from discovery to remediation. Avalor's data fabric acts as a source of truth for assets, controls, identities, vulnerabilities, security bugs, and other related data points. Gain a holistic view of data across your organization to identify patterns, prioritize work, and quickly make decisions.
    • Ingest any data in any format, no matter how obscure or custom the source using Avalor's AnySource™ Connector Along with 150+ of out-of-the-box integrations for security tools, cloud platforms, and more, the AnySource™ Connector ensures that all data can be ingested, parsed, and mapped into your security knowledge graph.
    • Enrich remediation decisions with business context Easily connect your vulnerability data to asset metadata, organization charts, and any other data source using our robust library of integrations.

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Avalor Data Fabric for Security

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Avalor Data Fabric
    Avalor Security Platform
    $300,000.00

    Vendor refund policy

    No refunds available.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Email support is offered Monday - Friday during normal business hours. support@avalor.io 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Security Observability
    Top
    50
    In Agile Lifecycle Management

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    1 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    4 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Data Ingestion and Integration
    Ingests data in any format from any source using AnySource Connector with 150+ out-of-the-box integrations for security tools and cloud platforms
    Data Normalization and Deduplication
    Aggregates, normalizes, and de-duplicates data from multiple sources to eliminate redundancy and create a unified source of truth
    Real-time Security Posture Visibility
    Provides real-time, multi-dimensional view of cybersecurity posture across assets, controls, identities, vulnerabilities, and security bugs
    Data Enrichment with Business Context
    Enriches security data with business context including asset metadata and organizational information to support informed decision-making
    Unified Vulnerability Management
    Supports full cycle risk assessment, prioritization, remediation dispatch, and analytics through seamless blending of multiple data sources
    Attack Surface Visibility
    Provides complete internal and external views of attack surface with asset enrichment from first-party and third-party data sources
    Risk Prioritization and Scoring
    Delivers risk scoring and threat-aware risk context to identify toxic combinations and prioritize remediation based on business impact
    Compliance Monitoring and Enforcement
    Discovers assets missing required controls or permissions and enforces organizational policies with automated alerts upon configuration drift detection
    Multi-Layer Exposure Detection
    Aggregates findings from native exposure detection capabilities combined with on-premises VM, cloud security, and application testing assessments
    Native Automation and Integration
    Supports no-code automation with more than 450 out-of-the-box integrations to popular security and ITOps tools for automated remediation and ticketing
    Risk Contextualization Engine
    Proprietary Risk Graph that contextualizes security findings from third-party tools and native solutions based on likelihood and impact of risk to minimize backlogs and triage time.
    Multi-Tool Security Integration
    Aggregates and enriches security findings from SAST, SCA, CSPM, runtime API security tools, and manual processes including bug bounty programs and penetration testing.
    Supply Chain Security Monitoring
    Monitors commits to flag anomalous developer behavior and surfaces risky material code changes for integrated software supply chain security assessment.
    Source Control Integration
    API-based integration with source control managers to create complete inventory of applications, supply chain components, their risks, and changes over time.
    LLM-Enriched Remediation Guidance
    Provides large language model-enriched remediation guidance tied to code owners and root causes to improve remediation cycles and reduce developer friction.

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.9
    7 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    43%
    43%
    14%
    0%
    0%
    2 AWS reviews
    |
    5 external reviews
    External reviews are from PeerSpot .
    Shaamim Ahmed

    Unified vulnerability management has strengthened credential defenses and improves risk-based decisions

    Reviewed on Aug 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I am familiar with Unified Vulnerability Management through Tenable, which serves as my primary tool and playground. Unified Vulnerability Management is a universal vulnerability management tool. I have been using Tenable AI, Tenable AD, and Tenable IO for more than eight to nine years, approaching close to ten years of experience.

    I worked for TD Synnex, the largest distributor in the USA and globally. In my role as a senior cyber security architect, I implemented their Unified Vulnerability Management application across approximately 9,000 servers with global operations. I also worked for Caterpillar as a data security admin level four, which is the highest level of engineering role beside the America Tech. I found that they used vulnerability tools including Tenable and other vulnerability management solutions. Based on my understanding of the rhythm of business, I applied Unified Vulnerability Management principles and evaluated their capabilities from an engineering perspective.

    How has it helped my organization?

    During my experience with Unified Vulnerability Management at TD Synnex in 2022, I was involved when they merged two large organizations, Tech Data and Synnex, becoming TD Synnex with approximately twenty organizations altogether. I was responsible for the merger and acquisition program, and I proposed implementing Unified Vulnerability Management from the root with the new application. I rebuilt their naming convention, which was a substantial task, and discovered many gaps in the process.

    What is most valuable?

    From Unified Vulnerability Management, credential scanning emerged as the most significant feature. Credential scanning identifies when someone attempts to log in to our network from outside, a capability that no other application recognizes. If someone tries to log in inside our network from outside, it will not be recognized by any other application, but Unified Vulnerability Management, especially through credential scanning, recognizes and prevents the operation.

    Credential scanning is important for Unified Vulnerability Management as it serves as the first line of defense against hackers attempting to enter your network. From my role as a cybersecurity design architect, this capability is crucial. Most EDR, XDR, and other protection tools may not catch these sophisticated attacks because hackers use AI and different methodologies to gain access. They act as real users, injecting usernames and passwords, which can easily compromise credentials and allow them inside the network. Other tools cannot detect such activity, which is why I focus intently on this and secured my credential environment.

    Unified Vulnerability Management is a very important part of my security strategy. My understanding shows that I have worked with many complete security postures, and vulnerability management is one of my areas of expertise. I believe that Unified Vulnerability Management is the backbone of any organization's security posture.

    Unified Vulnerability Management means a comprehensive security approach that combines vulnerability discovery, assessment, prioritization, remediation, validation, and reporting into a single centralized program platform. I can secure servers, workstations, network devices, and cloud resources including Azure, AWS, and GCP, especially from an American market perspective. It also includes applications, APIs, containers, Kubernetes, mobile devices, IoT, and DevOps elements. Unified Vulnerability Management prioritizes vulnerability scans to detect CVEs, ensuring continuous monitoring and assessment, tracking remediation progress, and automating patch deployment. It integrates threat intelligence and complies with standards including NIST CSF, 853, CIS control, ISO 27001, PCI DSS, and HIPAA.

    The features I rely on most day-to-day in Unified Vulnerability Management are asset discovery, vulnerability management, patching, remediation, and threat intelligence. These are the most significant aspects for me. Additionally, I work to reduce security tool sprawl, achieve faster remediation patching, improve compliance readiness, enhance risk-based decision-making, and maintain visibility across hybrid and multi-cloud environments.

    I have used various solutions including Microsoft Defender Vulnerability Management, Tenable One, Rapid7, InsightVM, and CrowdStrike Falcon for vulnerability management. Additionally, I also utilize Wiz for cloud vulnerability management tools.

    Unified Vulnerability Management has centralized the process of identifying, assessing, prioritizing, remediating, and monitoring vulnerabilities across my organization's entire IT ecosystem through a single integrated platform and governance framework, making this the most significant advantage.

    I observe that Unified Vulnerability Management provides significant asset discovery, vulnerability scanning, and the capability to detect vulnerable CVEs, ensuring continuous monitoring and assessment that creates alerts if anything occurs. It also uses risk prioritization based on CVSS scores, threat intelligence, exploit availability, and business impact while emphasizing patching prioritized exploiting vulnerabilities.

    What needs improvement?

    I believe Unified Vulnerability Management can improve by emphasizing continuous monitoring, which necessitates a dashboard for users. Creating more mobility, especially since many incidents occur outside regular hours, would be beneficial. If anything goes wrong, a mobile version or mobile dashboard could be extremely helpful. Mobility is now a mandatory capability, allowing users to manage vulnerabilities through mobile applications.

    Beyond mobility for Unified Vulnerability Management, more flexibility is also required. For example, vulnerability scanners routinely scan and create reports. It would be beneficial if I could create a runbook so that if any unwanted events occur, it generates alerts and stops operations. This would create a complete package for secure posture and management, allowing me to protect not just through scans but also through prevention.

    For how long have I used the solution?

    I have been working with Unified Vulnerability Management for more than eight to nine years, approaching close to ten years of experience.

    What do I think about the stability of the solution?

    Unified Vulnerability Management is stable and should be since organizations are investing heavily. As a cybersecurity engineer, I prefer more than one tool, especially EDR and XDR, to ensure dual protection as any failure could jeopardize your entire business. Using two tools instead of one provides an extra layer of security for the environment, especially within enterprises.

    What do I think about the scalability of the solution?

    Unified Vulnerability Management demonstrates scalability. For instance, I currently manage 9,000 servers while only purchasing licenses for 3,000 applications, enabling me to expand from 9,000 to 12,000 servers when needed without disruption.

    How are customer service and support?

    Customer support varies. After COVID, I find customer support lacking, and I am not sure why the principals do not prioritize it more. They focus on technology but also created community sites for users to ask questions, which often provides automated responses for common queries. For new issues, there might be a delay in receiving help, and sometimes it involves answering machines when calling for support, which can be frustrating. I believe OEM should consider refining their support strategies, employing better AI agents that can cover frequent questions and enhance their response to users.

    Which solution did I use previously and why did I switch?

    I previously used other solutions before Unified Vulnerability Management, particularly Tenable products including Tenable, Tenable IO, and Tenable vulnerability management for vulnerability scans.

    Before using Unified Vulnerability Management, I evaluated options including Azure Security Center, Microsoft Defender, Qualys, and Splunk, integrating these to enhance capabilities for vulnerability management. My primary focus is on Microsoft and Tenable, with limited use of Microsoft Defender vulnerability management before switching.

    What was our ROI?

    I observe that Unified Vulnerability Management leads to significant returns on investment, in which automation reduces the need for human intervention. I can configure everything to operate on schedule; therefore, no need for manual operation is required. Everything scans automatically, creates reports, and generates ServiceNow tickets for remediation. It becomes a hands-free application that streamlines my processes greatly.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is not directly managed by me; however, I strongly recommend Tenable as I view it as a prime vulnerability management application worldwide. Even when comparing other tools, I vote for Tenable because they continuously research and tackle challenges faced by many organizations. Pricing-wise, vulnerability management generally involves two types of models: one for licensing individual devices and another for environments. It is advantageous as you may not need licenses for all 9,000 servers but can effectively manage and scan even with fewer licenses for prioritized servers.

    What other advice do I have?

    My advice to others looking into Unified Vulnerability Management is to consider Tenable One as my first choice. I tend to favor Tenable and its different use cases. For example, Microsoft Defender is advantageous only within Microsoft platforms, whereas Wiz is beneficial for cloud-only environments. Given more comprehensive needs, Tenable One stands out as compatible with most infrastructures. ServiceNow has a vulnerability response function, but I have limited experience with that. I have also looked into CrowdStrike, particularly their Exposure Management, but I have not explored it fully as it is newly released.

    Every technology is developing rapidly, and there is a growing emphasis on AI within this evolution. Just three years ago, AI was not as prevalent, but now it significantly enhances productivity and efficiency. However, it represents a double-edged sword; while largely beneficial, AI can also create risks. It learns from inputs, and if anyone employs bad prompts within an enterprise context, they might expose vulnerabilities without recognizing it. Therefore, I need to safeguard AI use alongside utilizing DLP systems to protect such instances, ensuring protective measures are in place for any potentially harmful inquiries made to AI.

    I rate this solution a nine out of ten based on my overall experience.

    Marco Spagnoletti

    Streamlined workflows have improved vulnerability response and prioritized critical risks

    Reviewed on Aug 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Unified Vulnerability Management is to identify and mitigate vulnerabilities effectively. We have a unique workflow that helps streamline our vulnerability management process.

    How has it helped my organization?

    Unified Vulnerability Management has positively impacted my organization by improving our response time to vulnerabilities significantly. Our average response time was reduced by 40%, and we have seen measurable improvements in our security posture.

    What is most valuable?

    The best features Unified Vulnerability Management offers include comprehensive scanning and detailed reporting.

    The risk-based prioritization helps my team by allowing us to focus on the most critical vulnerabilities first.

    One aspect that stands out is the user-friendly interface, though there are enhancements I wish it had.

    What needs improvement?

    I believe Unified Vulnerability Management can be improved by refining its reporting capabilities.

    I would particularly like to see enhancements related to the user interface to make navigation even easier.

    For how long have I used the solution?

    I have been using Unified Vulnerability Management for a significant time in my organization.

    What other advice do I have?

    My advice for others looking into using Unified Vulnerability Management is to fully understand their specific needs and tailor the implementation accordingly. Overall, I have found it to be an invaluable tool in our security arsenal. I would rate this product a 9 out of 10.

    Utpal Sinha

    Centralized vulnerability insights have improved risk-based patching and reporting workflows

    Reviewed on Aug 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Unified Vulnerability Management is used for vulnerability management, involving finding vulnerabilities on devices and providing recommendations. Based on these recommendations, we manually check the vendor pages for the necessary patches and version upgrades, and that work is manual, as we are not using any software for it.

    What is most valuable?

    In Unified Vulnerability Management, the best features include the ability to consolidate each and every device without dependency on other patch vulnerability management software, such as Qualys and SolarWinds, which have limited modules. It can work on both web and on-premises servers through a single centralized module that scans all platforms, including cloud and Software-as-a-Service, and can assess vulnerabilities related to TLS and DTLS, while on-premises scanning is also possible with a simple connector.

    We have configured automated scanning in Unified Vulnerability Management, but we also take precautions during this process. We implement temporary firewall blocks for specific ports that could damage the product, such as Portwide, which acts like a trojan; thus, we maintain limited automation, scanning for a specific duration on particular TCP ports within a determined IP range. The software includes an exclude option, which we utilize to avoid certain IP addresses or URLs.

    I can assess the ability to generate customizable compliance reports as effective; internally, it includes a tool, and if necessary, we export these reports into CSV format. Once in CSV format, we use Power BI for graphical presentation to stakeholders.

    What needs improvement?

    In Unified Vulnerability Management, the area that needs improvement is DNS-level security, which has been lacking for the last ten years. Other vendors, such as Cloudflare and Netskope, excel in DNS-level security that is crucial for reducing bandwidth utilization. With Unified Vulnerability Management, since we send all data to their cloud, we utilize internet bandwidth; ideally, blocking at the DNS level means only sending DNS queries to the cloud, conserving bandwidth. Competitors in ZTNA vulnerability management such as Cloudflare, Netskope, and Cisco Umbrella have better capability in this area.

    For how long have I used the solution?

    I have around eight years of experience using Unified Vulnerability Management.

    What do I think about the stability of the solution?

    Currently, the stability of Unified Vulnerability Management is commendable; after evaluating two or three products, we selected Unified Vulnerability Management, and following deployment, it has remained stable, which I rate as ten out of ten for stability.

    What do I think about the scalability of the solution?

    Regarding scalability, I find it excellent; whenever required, we can deploy in AWS or other platforms. Even though we currently do not use AWS extensively, we could easily integrate it if we need more VMs, employing a straightforward, single-time token-based authentication to connect to the cloud.

    How are customer service and support?

    I rate the technical support at Unified Vulnerability Management as very good; they respond immediately when I call for assistance. If necessary, they escalate issues to senior staff, and I have seen R&D personnel come and help us with problems, such as fixing certificate issues during calls. I give the support a rating of ten.

    What was our ROI?

    In terms of return on investment, I estimate it at around thirty percent annually. In a five-year period, we can see a full payback; for instance, comparing the cost with vendors such as Secureworks, hiring them for monthly scanning would yield higher expenses than maintaining Unified Vulnerability Management. Thus, we save around thirty to forty percent over five years.

    Which other solutions did I evaluate?

    I would compare Unified Vulnerability Management with other solutions and rank it around eight or eight point nine, definitely not reaching nine. Qualys is a good product in this space, but the challenge with Qualys is that multiple modules need to be purchased.

    What other advice do I have?

    For a review, I can provide solutions such as Unified Vulnerability Management, Fortigate, Palo Alto firewall, and based on Gartner, I can see that Forescout is also a notable mention.

    We do use Unified Vulnerability Management.

    We have used the remediation workflow tools, but we do not fully trust auto-remediation. First, we manually validate whether it is truly a vulnerability or just a false positive alert because sometimes the version indicates a vulnerability, yet there is an available patch for that version. In those cases, we can exclude it manually, so there is no necessity to upgrade certain applications or servers. These false positive vulnerability logs do arise, and we manually filter those before applying changes to avoid potential outages. For instance, this week we focus on critical vulnerabilities, while in the next fifteen days, we will address high vulnerabilities, then move on to medium and low vulnerabilities, which we will prioritize only after more than ninety days.

    The integration capabilities notably influence our security strategy, as we have it integrated with Microsoft Defender, a scanner that provides critical input. We also utilize a DLP solution and a CASB solution, using ChatGPT and Copilot, with the current integration being mainly with Windows Defender.

    Risk-based prioritization is vital for resource allocation; for instance, we treat a CVE of ten as critical, and anything from nine point eight down to eight is considered critical. Between eight and seven is high, while below that becomes medium and low. Vulnerabilities rated six or seven are not acted upon urgently, while we respond immediately to vulnerabilities rated at ten and nine, aiming to fix them within the next fifteen days. During our quarterly scans, if we find three or four vulnerabilities across twenty to twenty-four different assets, we allocate tasks to the respective owners, providing them with the remediation steps and necessary patch details for formal change requests.

    Regarding the pricing for Unified Vulnerability Management, it is definitely not cheap; when compared to Qualys, it is more reasonable. It ranks high among the best software available, nearly matching the price of the Gartner number one product, which is Qualys. Rapid7 is also present, and it is lesser in cost than Unified Vulnerability Management.

    We have deployed Unified Vulnerability Management in both cloud and on-premises environments.

    I have been working with Unified Vulnerability Management products for a total of ten years, and specifically, we have been using the Unified Vulnerability Management scanning product for about four years. We initially checked it in two thousand nineteen and purchased it for five years back then, marking our experience with the product from its first stage.

    My overall rating for this product is nine out of ten.

    reviewer2223654

    Limited hands-on experience has raised awareness of unified risk insights and data aggregation

    Reviewed on Jul 23, 2026
    Review provided by PeerSpot

    What is most valuable?

    For me, the most appealing aspect of Unified Vulnerability Management for a customer or potential customer is the functionality. It is the grouping of numerous inputs into the solution.

    Unified Vulnerability Management collects information from other products and aggregates that information. The other products are the ones that perform all the scanning. Unified Vulnerability Management takes all of those inputs, bundles them into one platform. For instance, I have an antivirus solution that collects information about my workstations and provides the workstation name. I also have a vulnerability management solution that collects information about that laptop. Unified Vulnerability Management joins them all together using the key that is the laptop name and combines all that information from different sources.

    What needs improvement?

    I cannot answer what could be improved about Unified Vulnerability Management because I have not implemented it. I am not in a position to give feedback.

    I cannot comment on what other features or functionality I would like to see included in Unified Vulnerability Management because I do not know the price of the product, so I cannot comment on whether it is competitive in the market space. I have not done an analysis of that. All I have done is keep abreast of the technology as an architect, but nothing further.

    For how long have I used the solution?

    I have known about Unified Vulnerability Management since it was first launched because Zscaler bought into this product during their initial roadshows. That was approximately two to three years ago.

    What do I think about the stability of the solution?

    I have no idea how stable Unified Vulnerability Management is. If I must provide a number, I would rate the stability as five because I have no idea.

    How are customer service and support?

    Zscaler's technical support is responsive and helpful.

    How was the initial setup?

    I have not implemented Unified Vulnerability Management. The only tool that I have is Zscaler Internet Access.

    What other advice do I have?

    I have not gone any further than initial awareness regarding Unified Vulnerability Management. I must admit that I did not know they even had an on-premises version.

    I have no idea if there were any challenges or complexities with the implementation of Unified Vulnerability Management because I have not deployed it.

    I suspect that Unified Vulnerability Management can generate customizable reports, but since I have not implemented it, I do not know.

    From my perspective, I use an antivirus solution and a vulnerability management solution. I also have a CMDB, so I already have those. Unified Vulnerability Management could potentially be my CMDB, but I do not know.

    My understanding is that Unified Vulnerability Management integrates with a number of known vendors that are in the marketplace, popular and common vendors. Therefore, I am guessing that the integration will work, but not having deployed it, I do not know.

    I cannot rate Unified Vulnerability Management in general from one to ten because I have not implemented the product. Conceptually, I think Unified Vulnerability Management is a great idea, but I do not know if it delivers. I can only tell the marketing information and not the real-life information.

    My overall review rating for Unified Vulnerability Management is five.

    Bhaskar Rao

    Secure access has protected sensitive data and provides controlled visibility for external users

    Reviewed on Apr 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We integrated Unified Vulnerability Management with the FortiGate firewall, and as of now, there are no challenges found. It is very easy to implement Unified Vulnerability Management with the FortiGate firewall.

    What is most valuable?

    The best feature of Unified Vulnerability Management is that it never shows actual details publicly and provides different virtual information to those coming from outside the company. It does not give any actual information about any companies, making it very safe for any organization to protect their networks, which is why it is in high demand right now.

    What needs improvement?

    Improvements are necessary because Unified Vulnerability Management has been in the market for only seven or eight years, and a lot of improvement must be required for performance. Automatic scaling is needed, especially since sometimes a data center can be down, particularly in certain geographical locations.

    For how long have I used the solution?

    I have been familiar with Unified Vulnerability Management for around five years, and as of 2020, it has been almost six years.

    How was the initial setup?

    Regarding implementation, I can say it is moderate, not easy and not very difficult. It should be a knowledgeable person who can deploy it easily, but for a non-knowledgeable person, it is difficult. I did not face any problems.

    Deployment for Unified Vulnerability Management may take a couple of months after planning, which takes about one and a half months. After planning, the deployment is a one-day job. Impact analysis, reviewing changes, and risk analysis take time, but with proper planning, the job for deployment will take one day.

    What about the implementation team?

    Currently, for Unified Vulnerability Management implementation, there are five members taking care of the operations and three members for the monitoring.

    What's my experience with pricing, setup cost, and licensing?

    I purchased Unified Vulnerability Management directly from Zscaler, not from AWS Marketplace.

    What other advice do I have?

    We do use automated scanning, and it will generate a report if any of our organization's assets have some unauthorized software that is non-compliant. Based on the report, we will work on understanding why it is non-compliant and what the reason is for its installation on end user assets, and we will mitigate that.

    I have not yet used Unified Vulnerability Management's remediation workflow tools, but we are working on it right now as that project is ongoing.

    About pricing, it is higher compared to others because Unified Vulnerability Management is demanding and more secure than other products since it does not give actual information of the customer, so it is a bit expensive. Organizations should choose to work on the pricing.

    I rate this solution an 8 out of 10.

    View all reviews