Cloud Platform
Support
Contact us

Qualys VMDR 2.0 with Qualys TruRisk

Redefining Cyber Risk Management

Cyber risk is business risk - with risks growing faster than what traditional VM and SIEM tools can manage. Security and IT teams need a new approach to tackle cyber threats with a clear understanding of cybersecurity risk and automate workflows for rapid response.

Aflac

Qualys VMDR 2.0 has helped us improve our program by providing additional threat and risk context to better identify high-risk vulnerabilities. The transparency of the rating algorithm also made it easy to justify prioritization and align all relevant security and IT stakeholders so we could move quickly to remediate the risk.

Scott Crawford Brian Penn Manager, Security Posture at Aflac
451 Research

With VMDR, Qualys integrates highly valued and much-needed asset visibility with vulnerability management so that IT teams can have full visibility of their global IT assets (known and unknown).

Scott Crawford Scott Crawford Research Vice President at 451 Research
Toyota

VMDR raises the maturity of our Vulnerability Management program to its next level. It provides focus on actionable issues to drive the reduction of imminent risk without doing the analysis outside of the Qualys platform.

Georges Bellefontaine Georges Bellefontaine Manager of Vulnerability Management at Toyota Financial Services
Armor

VMDR delivers unprecedented response capabilities including options for protecting remote users, which has become a top priority for CISOs in the current environment.

Ryan Smith Ryan Smith Vice President of Product at Armor
Omdia

VMDR brings Vulnerability Management to the next level as it provides customers with a comprehensive platform that is easy to use and deploy across complex hybrid environments, which are a challenge for companies to secure.

Rik Turner Rik Turner Principal Analyst at Omdia

Qualys VMDR 2.0 with TruRisk

With VMDR 2.0, enterprises are empowered with visibility and insight into cyber risk exposure - making it easy to prioritize vulnerabilities, assets, or groups of assets based on business risk. Security teams can take action to mitigate risk, helping the business measure its true risk, and track risk reduction over time.

Elevating the #1 Vulnerability Management solution to the next level

Discover, assess, prioritize, and patch critical vulnerabilities and reduce cybersecurity risk in real time and across your global hybrid IT, OT, and IoT landscape.

Understand and manage cybersecurity risk

Quantify risk across vulnerabilities, assets, and groups of assets to help your organization proactively mitigate risk exposure and track risk reduction over time with Qualys TruRisk

Automate remediation with no-code workflows

Save valuable time by automating and orchestrating operational tasks for vulnerability management and patching with QFlow

Prevent attacks from ever happening

Leverage insights from over 180k vulnerabilities sourced from over 25+ threat sources to receive preemptive alerts on potential attacks with the Qualys Threat DB

Identify all assets in your environment

Detect all IT, OT, and IoT assets for a complete, categorized inventory enriched with details such as vendor lifecycle information and much more

Analyze vulnerabilities and misconfigurations with six sigma accuracy

Automatically detect vulnerabilities and critical misconfigurations per Center for Internet Security (CIS) benchmarks, by asset

Quickly remediate threats at scale

Rule-based integrations with ITSM tools such as ServiceNow and JIRA automatically assign tickets and enable orchestration of remediation to reduce MTTR

A single solution for cybersecurity risk, discovery, assessment, detection, and response

Qualys VMDR 2.0 offers an all-inclusive risk-based vulnerability management solution to prioritize vulnerabilities and assets based on risk and business criticality. VMDR seamlessly integrates with configuration management databases (CMDB) and patch management solutions to quickly discover, prioritize, and automatically remediate vulnerabilities at scale to reduce risk. Additionally, it integrates with ITSM solutions such as ServiceNow to automate and operationalize vulnerability management end-to-end.

Get an all-Inclusive risk-based vulnerability management solution that prioritizes vulnerabilities, misconfigurations and assets based on risk, reduces risk by remediating vulnerabilities at scale, and helps organizations measure security program effectiveness by tracking risk reduction over time.

VMDR 2.0 Key Features

Qualys VMDR 2.0 covers all your rapid remediation needs, leveraging risk-based VM and easy-to-use no-code workflows. VMDR 2.0 is priced on a per-asset basis and does not require a software update to start. Sign up for a free trial or request a quote.

Qualys Cloud Platform, combined with its powerful lightweight Cloud Agent, Virtual Scanners, and Network Analysis (passive scanning) capabilities bring together all four key elements of an effective vulnerability management program into a single app unified by powerful out-of-the-box orchestration workflows.

Qualys VMDR enables organizations to automatically discover every asset in their environment, including unmanaged assets appearing on the network, inventory all hardware and software, and classify and tag critical assets. VMDR continuously assesses these assets for the latest vulnerabilities and applies the latest threat intel analysis to prioritize actively exploitable vulnerabilities.

Finally, VMDR automatically detects the latest superseding patch for the vulnerable asset and easily deploys it for remediation. By delivering all this in a single app workflow, VMDR automates the entire process and significantly accelerates an organization’s ability to respond to threats, thus preventing possible exploitation.

VMDR all-in-one workflow with QFlow

Qualys VMDR covers all your needs and workflows with no-code. Priced on a per-asset basis and with no software to update, VMDR drastically reduces your total cost of ownership. Sign up for a free trial or request a quote.

Apps and services
What it does
Included
Add on

Asset Management

Detect and inventory all known and unknown assets that connect to your global hybrid-IT environment - including, on-premises devices and applications, mobile, OT and IoT. Includes Qualys Passive Scanning Sensors.

Included

check mark
Asset Inventory
Get up-to-date real-time inventory for all IT assets.

On-premises Device Inventory – Detect all devices and applications connected to the network including servers, databases, workstations, routers, printers, IoT devices, and more.

Certificate Inventory – Detect and catalog all TLS/SSL digital certificates (internal and external facing) from any Certificate Authority.

Cloud Inventory – Monitor users, instances, networks, storage, databases and their relationships for a continuous inventory of resources and assets across all public cloud platforms.

Container Inventory – Discover and track container hosts and their information – from build to runtime.

Mobile Device Inventory – Detect and catalog Android, iOS/iPadOS devices across the enterprise, with extensive information about the device, its configurations, and installed apps.

Included

check mark
Asset Categorization and Normalization
Gather detailed information, such as an asset’s details, running services, installed software, and more. Eliminate the variations in product and vendor names and categorize them by product families on all assets.

Included

check mark
Enriched Asset Information
Get advanced, in-depth details including, hardware/software lifecycles (EOL/EOS), software license auditing, commercial and open source licenses, and more.

Add on

check mark
CMDB Synchronization
Bi-directionally synchronize asset information between Qualys and the ServiceNow CMDB.

Add on

check mark

Vulnerability Management

Continuously detect software vulnerabilities with the most comprehensive signature database, across the widest range of asset categories. Qualys is the market leader in VM.

Included

check mark
Assess, report and monitor security-related misconfiguration issues based on the Center for Internet Security (CIS) benchmarks.

Included

check mark
Assess your digital certificates (internal and external) and TLS configurations for certificate issues and vulnerabilities.

Included

check mark
ITSM Tool Integration
Rule-based integrations with ITSM tools (ServiceNow, JIRA) automatically assign tickets and enable orchestration of remediation, further reducing mean time to remediation (MTTR).

Included

check mark
Additional Assessment Add Ons

Mobile Device Vulnerability & Misconfiguration Assessment – Continuously detect device, OS, apps, and network vulnerabilities and monitor critical mobile device configurations.

Cloud Security Assessment – Continuously monitor and assess your PaaS/IaaS resources for misconfigurations and non-standard deployments.

Container Security Assessment – Scan container images and running containers in your environment for high-severity vulnerabilities, unapproved packages and drive remediation efforts. Includes the ability to scan in the build phase with plug-ins for CI/CD tools and registries.

Add on

check mark
Qualys TruRisk

Accurately quantify cybersecurity risk across vulnerabilities, assets, and groups of assets measuring and providing actionable steps that reduce exposure and increase cybersecurity program effectiveness.

Included

check mark
QFlow

Automate and orchestrate operational tasks with a no-code visual workflow building environment to rapidly streamline security programs and responses.

Included

check mark
Custom Assessment & Remediation (CAR)

Custom Assessment & Remediation (CAR) as paid add-ons with their one-liners.

Add on

check mark

Threat Detection & Prioritization

Alerts you in real time about network irregularities. Identifies threats and monitors unexpected network changes before they turn into breaches.

Included

check mark
Pinpoint your most critical threats and prioritize patching. Using real-time threat intelligence and machine learning, take control of evolving threats, and identify what to remediate first.

Included

check mark

Response

Automatically correlate vulnerabilities and patches for specific hosts, decreasing your remediation response time. Search for CVEs and identify the latest superseding patches.

Included

check mark
Speed up patch deployment by eliminating dependence on third-party patch deployment solutions using Qualys Cloud Agents.

Add on

check mark
Uninstall or update vulnerable apps, alert users, reset or lock devices, change passcodes, and more.

Add on

check mark
Secure, protect and monitor running containers in traditional host-based container and Container-As-A-Service environments with granular behavioral policy enforcement.

Add on

check mark
Certificate Renewal
Renew expiring certificates directly through Qualys.

Add on

check mark

QUALYS SENSORS

Qualys Sensors With Unprecedented Scalability
VMDR includes, UNLIMITED: Qualys Virtual Passive Scanning Sensors (for discovery), Qualys Virtual Scanners, Qualys Cloud Agents, Qualys Container Sensors, and Qualys Virtual Cloud Agent Gateway Sensors for bandwidth optimization.

Included

check mark
Other Integrated Qualys Cloud App Add Ons
Endpoint Detection & Response, Web Application Scanning, Web Application Firewall, Policy Compliance, PCI Compliance, File Integrity Monitoring, Security Assessment Questionnaire, Out-of-Band Configuration Assessment. Learn more

See for yourself. Try Qualys VMDR for free.

Start your free trial today. No software to download or install. Email us to request a quote or call us at 1 (800) 745-4355.

Qualys VMDR: Global IT Assets view | Qualys
ASSET MANAGEMENT

Automated asset identification and categorization

Knowing what’s active in a global hybrid-IT environment is fundamental to security. VMDR enables customers to automatically discover and categorize known and unknown assets, continuously identify unmanaged assets, and create automated workflows to manage them effectively.

After the data is collected, customers can instantly query assets and any attributes to get deep visibility into hardware, system configuration, applications, services, network information, and more.

Qualys VMDR: Global IT Assets view | Qualys
Qualys VMDR: Vulnerability Management dashboard | Qualys
VULNERABILITY MANAGEMENT

Real-time vulnerability and misconfiguration detection

VMDR enables customers to automatically detect vulnerabilities and critical misconfigurations per CIS benchmarks, broken out by asset. Misconfigurations lead to breaches and compliance failures, creating vulnerabilities on assets without common vulnerabilities and exposures (CVEs). VMDR continuously identifies critical vulnerabilities and misconfigurations on the industry’s widest range of devices, including mobile devices, operating systems and applications.

Qualys VMDR: Vulnerability Management dashboard | Qualys
THREAT PRIORITIZATION

Automated vulnerability remediation prioritization with context

VMDR uses real-time threat intelligence, advanced correlation and powerful machine learning models to automatically prioritize the riskiest vulnerabilities on your most critical assets – reducing potentially thousands of discovered vulnerabilities, to the few hundred that matter. Indicators such as Exploitable, Actively Attacked, and High Lateral Movement bubble up current vulnerabilities that are at risk while machine learning models highlight vulnerabilities most likely to become severe threats, providing multiple levels of prioritization.

Further prioritize remediation by assigning a business impact to each asset, like devices that contain sensitive data, mission-critical applications, public-facing, accessible over the Internet, etc.

Qualys VMDR: Patch management and remediation | Qualys
PATCH MANAGEMENT

Patching and remediation at your fingertips

After prioritizing vulnerabilities by risk, VMDR rapidly remediates targeted vulnerabilities, across any size environment, by deploying the most relevant superseding patch. Additionally, policy-based, automated recurring jobs keep systems up to date, providing proactive patch management for security and non-security patches. This significantly reduces the vulnerabilities the operations team has to chase down as part of a remediation cycle.

Powered by Qualys Cloud Platform

Single-pane-of-glass UI

See the results in one place, in seconds. With AssetView, security and compliance pros and managers get a complete and continuously updated view of all IT assets — from a single dashboard interface. Its fully customizable and lets you see the big picture, drill down into details, and generate reports for teammates and auditors. Its intuitive and easy-to-build dynamic dashboards to aggregate and correlate all of your IT security and compliance data in one place from all the various Qualys Cloud Apps. With its powerful elastic search clusters, you can now search for any asset – on-premises, endpoints and all clouds – with 2-second visibility.

Centralized & customized

Centralize discovery of host assets for multiple types of assessments. Organize host asset groups to match the structure of your business. Keep security data private with our end-to-end encryption and strong access controls. You can centrally manage users’ access to their Qualys accounts through your enterprise’s single sign-on (SSO). Qualys supports SAML 2.0-based identity service providers.

Easy deployment

Deploy from a public or private cloud — fully managed by Qualys. With Qualys, there are no servers to provision, software to install, or databases to maintain. You always have the latest Qualys features available through your browser, without setting up special client software or VPN connections.

Scalable and extensible

Scale up globally, on demand. Integrate with other systems via extensible XML-based APIs. You can use Qualys with a broad range of security and compliance systems, such as GRC, ticketing systems, SIEM, ERM, and IDS.

See for yourself. Try Qualys VMDR for free.

Start your free trial today. No software to download or install. Email us or call us at 1 (800) 745-4355.