Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

8 AWS reviews

External reviews

23 reviews
from

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    Bharawaj S

Makes remediation, policy management, and compliance reporting easy

  • December 02, 2024
  • Review from a verified AWS customer

What is our primary use case?

We use TotalCloud for CSPM or Cloud Security Posture Management. We have integrated our cloud accounts with TotalCloud, allowing us to do the posture management of those accounts and virtual machines.

By implementing TotalCloud, we wanted configuration compliance reports. We wanted to determine the compliance percentages of our infrastructure. We wanted to see if particular mandatory controls have been implemented.

How has it helped my organization?

It provides information about where a particular data or issue exists. If we want to remediate, there is also a remediation option. It gives a brief description, and there are also some URLs that we can refer to remediate. We have security posture visualization, and we also have detailed information with cloud posture ID, etc.

TotalCloud reduces the work we would have to do to combine multiple sources to prioritize risk. We have a dashboard to prioritize the security posture-related information based on criticality.

What is most valuable?

The best feature would be the ability to create policies. It is easy to control and update policies as required. Additionally, it is easy to check the security posture through the UI. We could segregate based on three different providers or an EC2 instance. This kind of virtual machine-related segregation is very easy.

What needs improvement?

In TotalCloud, I would suggest improvements in policy checks to cater to various inventory types like VPCs, subnets, S3 buckets, or IAMs. There is a lack of data segregation according to criticality or inventory. For example, they should provide percentages for security posture scores at the VPC level. Further differentiation and risk percentages should also be improved.

For how long have I used the solution?

I have been using TotalCloud for about ten months.

What do I think about the stability of the solution?

The stability is good, and I would rate it as a nine out of ten.

What do I think about the scalability of the solution?

Its scalability is good as well. I would rate it ten out of ten.

How are customer service and support?

Technical support for TotalCloud is satisfactory, but there have been multiple glitches here and there, so I would rate them as an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, we did not use any cloud management solutions. TotalCloud is the first solution we are utilizing for this purpose. We were tracking everything manually, so we did not have visibility into everything. After implementing TotalCloud, we could see how many machines have not been updated and where data has not been properly configured. We were able to get all the details in a single report.

How was the initial setup?

The deployment was easy because our integration was done at the tenant level, which simplified the process.

We have used it for AWS, Azure, and GCP clouds. Its maintenance is handled by Qualys. It is a SaaS platform.

What other advice do I have?

I would recommend TotalCloud from the posture management and integration perspectives, as these areas are strong. However, due to limitations in risk and inventory management, one might consider waiting until those features are improved. Overall, I would rate TotalCloud an eight out of ten.


    ShantanuChoubal

Boosted cloud security with enhanced asset categorization and AI-powered insights

  • November 22, 2024
  • Review from a verified AWS customer

What is our primary use case?

We use Qualys TotalCloud to assess the security posture of our cloud-hosted environment. This tool allows us to access real-time data, categorize assets, prioritize critical vulnerabilities, and establish regular patching policies to mitigate our overall vulnerability risk.

We are eager to utilize Qualys TotalCloud to create a ticketing system integrated with our SecOps module, such as ServiceNow or a similar tool. This integration will enable automated ticket creation following assessments and vulnerability identification within our environments. The system should assign tickets to respective team members, prioritize fixes, and provide comprehensive dashboards for tracking progress and visualizing generated reports.

How has it helped my organization?

Qualys TotalCloud provides written explanations to help with remediation paths and eliminate cyber risk, significantly reducing our time spent on these tasks. It ensures that we can minimize manual efforts and prioritize security issues identified by the platform, allowing us to focus on critical areas and improve overall efficiency.

Qualys TotalCloud has significantly improved our organization by automating our reporting processes, reducing the time spent on report creation from two hours to less than fifteen to twenty minutes. It offers complete visibility of our cloud environment, which aids in prioritizing vulnerabilities and security risks effectively.

It provides unified vulnerability and threat assessments across both Infrastructure as a Service and Software as a Service, significantly improving our overall cloud security posture management. Compared to our previous Managed Cloud environment, even within this organization, we have made substantial progress. Previously, we relied on different tools with limited features for vulnerability posture management. However, with Qualys TotalCloud, we have implemented new policies and processes for remediation, resulting in a 70 to 90 percent improvement in our security standards.

Qualys TotalCloud offers a consolidated, prioritized view of risk across our chosen scope, allowing us to focus on specific vulnerabilities and security threats within a single dashboard. This streamlined approach eliminates the need to collate data from multiple sources, improving efficiency and providing comprehensive visibility into our cloud environment.

TruRisk Insights considers multiple factors, including Qualys detection score, asset scoring, risk, and CVSS scoring, to generate a comprehensive priority rating. Additionally, customization options allow for incorporating factors like internet exposure, public accessibility, or intranet presence, further refining the risk scoring and prioritization process.

Vulnerability identification is inconsistent, especially for assets with high vulnerability scores. This is influenced by the environment and project of the asset, and potential oversight during migration between versions. This may lead to a few individuals discovering significant vulnerabilities. However, Qualys' TruRisk Insights can identify the post-migration version of an asset, enabling us to determine the specific vulnerability and appropriate remediation actions, such as patching.

TruRisk Insights has significantly improved our security posture by automating our reporting process. Previously, creating reports required manually identifying assets, categorizing their environment, and calculating scores in Excel, which was time-consuming. Now, with TruRisk Insights, we can generate reports in less than 20 minutes by simply using the Qualys TotalCloud console to download the desired information.

What is most valuable?

One of Qualys' best features is its categorization, which allows us to see the types of assets, their security postures, and the AI-powered version of the tool. The AI enhancements simplify vulnerability management by eliminating the need for SQL queries to create policies. Now, we can simply input our requirements, such as critical vulnerabilities in the production environment or specific operating systems, and the tool generates the results accordingly. Additionally, we can create custom dashboards to monitor specific areas of interest, like vulnerabilities affecting a particular OS, exposed ports, majorly targeted vulnerabilities, or the most exploited vulnerabilities in the environment.

What needs improvement?

Two areas for improvement in Qualys TotalCloud are the speed of the public cloud platform and vulnerability detection. While the public cloud platform is necessary due to the lack of a private cloud infrastructure, page load speeds could be faster. Additionally, vulnerability detection needs improvement, as it currently takes several days for new vulnerabilities to be added to the knowledge base, hindering prompt detection and remediation. Ideally, updates should be more immediate, enabling quicker implementation of solutions.

For how long have I used the solution?

I have been using Qualys TotalCloud for two to three years.

What do I think about the stability of the solution?

The stability is excellent, with well-planned maintenance schedules communicated in advance by Qualys. This ensures business continuity and preparedness for any planned downtime.

What do I think about the scalability of the solution?

I would rate the scalability of Qualys TotalCloud nine out of ten.

How are customer service and support?

The Qualys customer support is exceptional.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?


How was the initial setup?

The deployment was straightforward, taking less than a day.

What about the implementation team?

The implementation involved four or five team members on our side. It's unclear how many were involved from the Qualys side.

What was our ROI?

Regarding return on investment, it is going well, although we are yet to complete year-end assessments. Qualys TotalCloud has saved us approximately 15 to 20 percent of our efforts.

What's my experience with pricing, setup cost, and licensing?

Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly.

Which other solutions did I evaluate?

We evaluated other solutions such as Rapid7 and Falcon CrowdStrike. However, Qualys provides more comprehensive features.

What other advice do I have?

I would rate Qualys TotalCloud a nine out of ten.

We recommend and provide Qualys TotalCloud to our clients in various locations. We also utilize it internally across our global organization, spanning multiple countries in Asia, Europe, the US, and other regions. Therefore, Qualys TotalCloud is deployed globally. We have approximately 850 users with varying levels of access. Many have read-only access to view reports and the status of their environment. However, only a limited number of users have the necessary permissions to perform scans and make changes. The majority of users have read-only access.

Qualys TotalCloud, while generally reliable, occasionally requires maintenance and may experience downtime. Qualys performs its quarterly maintenance, but infrequent issues can arise, perhaps once or twice a year, causing crashes or slowdowns within the system. These rare instances may result in limited or delayed portal access, hindering report generation and dashboard viewing.

As a satisfied user, I recommend Qualys TotalCloud to other organizations or clients. I see myself as biased because I am a fan of the product and extensively use it.


    DurgeshGupta

Provides unified vulnerability and threat assessment across both IaaS and SaaS

  • October 30, 2024
  • Review from a verified AWS customer

How has it helped my organization?

Qualys TotalCloud provides a holistic view and insights into vulnerabilities, helping identify and track risks effectively.

It provides unified vulnerability and threat assessment across both IaaS and SaaS.

It helps to prioritize risks. The TruRisk Insights feature is particularly helpful in providing a comprehensive range of risks. We also have a TruRisk score for vulnerabilities. We can filter vulnerabilities based on the TruRisk score. For example, we can filter vulnerabilities with a TruRisk score of 500 to 700 and prioritize them.

What is most valuable?

The most valuable feature is the consolidated information that it provides from various platforms. We can find most of the things related to vulnerability management in one place.

What needs improvement?

There is room for improvement in the support. When deploying a Qualys solution at any client location, effective support should be there for all modules.

For how long have I used the solution?

We have been using it for seven months.

What do I think about the stability of the solution?

Qualys TotalCloud is stable. I would rate it a nine out of ten for stability.

What do I think about the scalability of the solution?

It is scalable. I would rate it a nine out of ten for scalability.

As of now, we are only using it at multiple locations in India. We have about seven members working with Qualys.

How are customer service and support?

Their support could be improved. I would rate their support a six out of ten due to availability issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We were using another solution. That solution was more environment-specific, whereas Qualys provides a hybrid approach. It is better in terms of vulnerability correlation and prioritization.

How was the initial setup?

The deployment is easy. It takes about a month if everything is already in place.

In terms of maintenance, we just have to ensure that all the risks are identified and the reporting and configurations are correct. These are our daily operations.

What other advice do I have?

If you want a single-page view of vulnerabilities in your environment, you should go with Qualys TotalCloud. The correlation is very good.

Qualys TotalCloud is a comprehensive solution. Expert knowledge is required to implement it according to the organization's needs. It should be aligned with the organization's requirements. It is a continuous learning and improvement process.

I would rate Qualys TotalCloud an eight out of ten.


    Robert Gauna

Provides extensibility, custom controls, and good overview

  • October 15, 2024
  • Review from a verified AWS customer

What is our primary use case?

We use Qualys TotalCloud for compliance monitoring and compliance checking.

How has it helped my organization?

TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risk. It is very satisfactory.

I could see its benefits immediately after the deployment. I was using another product, and I was trying to switch over to this product.

TruRisk Insights provides a good view of the situation from different perspectives, such as the policy compliance side, the vulnerability side, and a few others. It gives us a better view of what is going on versus just piecemeal from one UI to another and then trying to make sense and sorting things or combining data together.

TruRisk Insights feature found a small number of assets with high vulnerability scores. I reported them to the owner, and then they are going to work on it.

TruRisk Insights are a good indicator, but long term, the managers still want to use the ServiceNow integration. We have this in our back pocket to verify.

What is most valuable?

The most valuable feature is the extensibility. I can create custom controls and rely on Qualys TotalCloud to provide me with updated controls as they come from CS benchmarks.

What needs improvement?

I have already put in a few feature requests. There are features that I would like to have. I would like the ability to disable certain default built-in policies as they can be misleading when creating dashboards. That is the top one.

Additionally, I would like the ability to generate reports on a schedule and send them via email to the scheduler.

It is a bit cumbersome to apply some of the features built into policy compliance.

TotalCloud provides a single, prioritized view of risk, but it can be better. I was hoping that they would integrate TruRisk into it, but that is forthcoming. I have already put in the request a while back to add TruRisk, and they are working on it.

For how long have I used the solution?

I have been using the solution for around two years.

What do I think about the stability of the solution?

I have not seen any events like lagging, crashing, or downtime.

What do I think about the scalability of the solution?

It is very scalable, and I would rate it a ten out of ten for scalability.

How are customer service and support?

I usually do not have to contact support. I last contacted them a month or two months ago. They usually respond within 48 hours. I can always escalate as needed. It is not an issue. Overall, their support is top-notch.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I used Dome9 which is under Check Point. I switched to TotalCloud because of better extensibility.

How was the initial setup?

We had some challenges with permissions, but other than that, it was fine. Its implementation took about 60 days.

It requires maintenance on our end. We need to maintain the permissions and the connections to whatever AWS accounts we need to have scanned.

What about the implementation team?

We had an in-house team involved along with Qualys support. Three people were required for the deployment.

What's my experience with pricing, setup cost, and licensing?

The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription.

What other advice do I have?

New users should have a deeper understanding of how to use the cloud API because the extensibility is based on that. If they do not understand how to use the API, it would not be effective for them.

TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS, but we do not use that. We do not have a use case for that.

I would rate TotalCloud an eight out of ten.


showing 1 - 4