Cloud Platform
Contact us
Asset Management
Vulnerability & Configuration Management
Risk Remediation
Threat Detection & Response
  • Overview
  • Platform Apps

  • Qualys Endpoint Security

    Advanced endpoint threat protection, improved threat context, and alert prioritization

  • Context XDR

    Extend detection and response beyond the endpoint to the enterprise

Cloud Security

Qualys Launches VMDR 2.0 with TruRisk™ Scores and Automated Remediation Workflows

New capabilities give security, cloud operations and IT teams unprecedented insights into their risk posture along with easy to use drag and drop orchestration to prioritize and quickly respond to the most critical threats

FOSTER CITY, Calif. June 6, 2022 - Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of disruptive cloud-based IT, security and compliance solutions, today unveiled Qualys Vulnerability Management, Detection and Response (VMDR) 2.0. The new cloud-based solution gives unprecedented insights into an organization’s unique risk posture along with the ability to use drag and drop workflows to orchestrate responses.

The doubling of disclosed vulnerabilities over the last five years, the speed at which vulnerabilities are weaponized, and the cyber talent shortage, have left teams struggling to wade through a mountain of vulnerabilities with no way to fix them all. Security and IT teams need a new systematic approach to cut through the noise and prioritize fixing the most critical vulnerabilities that will reduce risk in their environment.

Qualys VMDR 2.0 provides insight security and IT teams need to focus on the vulnerabilities that genuinely reduce risk. Qualys beta customers with the TruRisk capability enabled prioritized on average 28% fewer critical vulnerabilities across a sample size of 2.6 million assets and 74 million detections. Simultaneously, they were able to reduce risk on average by 23% and in some cases as high as 50%.

“Cyber risk is becoming part of the business risk equation. Even the most advanced organizations can’t patch all the threats they uncover, which increasingly includes poorly misconfigured services,” said Michelle Abraham, research director at IDC. “Organizations must prioritize efforts that result in the maximum reduction of risk. Qualys’s approach to cyber risk management considers multiple factors like vulnerabilities and misconfigured systems, so organizations can focus on fixes that reduce their overall risk.”

Qualys VMDR with TruRisk offers risk-based vulnerability management for unprecedented insights into an organization’s unique risk posture to prioritize its most critical vulnerabilities across hybrid environments. The solution helps security and IT teams increase efficiency and save time by providing shared context and the ability to create drag and drop workflows to automate time-consuming vulnerability management operational processes including vulnerability assessment of ephemeral cloud assets, alerting, and prioritization.

Customer Testimonials
“Qualys VMDR with TruRisk has helped us improve our program by providing additional context to threat and risk, better identifying high risk vulnerabilities, some of which the common vulnerability scoring system (CVSS) had previously rated as low or medium severity. It was eye opening to see that some of the identified assets posing the highest organizational risk were not always being immediately detected. The transparency of the rating algorithm also made it easy to justify prioritization and get all relevant security and IT stakeholders aligned and move quickly to remediate the risk,” noted Brian Penn, manager, Security Posture with Aflac.

“The sheer number of attempted infiltrations encountered by our security teams on a weekly basis is daunting, and the task of prioritizing the most critical ones is a constant battle,” said Elie Abouzeid, vice president of Information Security for DentaQuest. “Qualys TruRisk helps us focus on the vulnerabilities that pose the highest risk and provides actionable insights to remediate those first. In addition to the risk scores, integration with ServiceNow ITSM enables our teams to assign tickets, track status and perform remediation all under a single coordinated view from investigation to resolution.”

Qualys VMDR 2.0 with TruRisk
Qualys VMDR 2.0 with TruRisk

Qualys VMDR with TruRisk allows Security and IT teams to:

Reduce Risk with Holistic Scoring – Quantify risk across the entire attack surface including vulnerabilities, misconfigurations and digital certificates, correlate with business criticality and exploit intelligence from hundreds of sources, including Shodan’s attack surface exposure data. Qualys VMDR with TruRisk automatically de-prioritizes vulnerabilities if compensating controls are in force, tracks risk reduction trends over time, and helps organizations measure and report on the effectiveness of their cybersecurity program across hybrid environments.

Quickly Remediate at Scale – Leverage rule-based integrations between VMDR and ITSM tools such as ServiceNow and JIRA, along with dynamic vulnerability tagging, to automatically assign remediation tickets to prioritize vulnerabilities and bridge the gap between security and IT teams. Orchestrate remediation directly from the ITSM tool to help close vulnerabilities faster and reduce the mean time to remediation.

Receive Preemptive Attack Alerts – External threat intelligence, from more than 180,000 vulnerabilities and 25 plus threat and exploit intelligence sources, is natively correlated with vulnerabilities and misconfigurations to proactively alert teams on vulnerabilities exploited by malware or those used in an active malicious campaign known to target your industry.

Automate Operational Workflows – Teams save valuable time and resources with Qualys Qflow technology. They can develop drag and drop visual workflows to automate time-consuming and complex vulnerability management tasks, such as vulnerability assessments for ephemeral cloud assets, alerting for high-profile threats or quarantining high-risk assets.

“In this era of increasing attacks and board-level attention on cyber resiliency, efficiently managing cyber risk is more important than ever,” said Sumedh Thakar, president and CEO of Qualys. “With VMDR 1.0, we innovated by bringing the four core elements of vulnerability management into a seamless workflow to help organizations efficiently respond to threats. We’re changing the game again with VMDR 2.0 allowing organizations to kickoff remediation workflows for vulnerability management tasks, prioritize remediation on the critical issues that reduce risk, and streamline responses and integrations with ITSM solutions like ServiceNow.”

VMDR Live Event
Please join us on Tuesday, June 7 at 10 am PT for our hybrid launch event. Register at

Qualys VMDR with TruRisk will be available in late June. To request a free trial, visit Learn more by reading our blog, Introducing Qualys VMDR 2.0.

Additional Resources
• Learn about VMDR 2.0 with TruRisk
• Read the Introducing VMDR 2.0 blog
• Details on the Qualys Cloud Platform
• Follow Qualys on LinkedIn and Twitter

About Qualys
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit

Qualys, Qualys VMDR® and the Qualys logo are proprietary trademarks of Qualys, Inc. All other products or names may be trademarks of their respective companies.

Media Contact:
Tami Casey