Qualys launches TotalCloud with FlexScan for cloudnative VMDR

November 2, 2022

Based on the industry’s most accurate vulnerability detection platform, new solution enables flexible, cloudnative scanning with and without agents

FOSTER CITY, California – Munich, Germany – November 02, 2022 – Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of cloud-based IT, security and compliance solutions, today introduced TotalCloud with FlexScan, a new solution that delivers cloudnative VMDR of the highest precision (Six Sigma). Agent and agentless scans in this solution enable comprehensive, cloudnative management of security posture and protection of workloads in multi-cloud and hybrid environments.

As business applications and on-premises infrastructure increasingly move to the cloud, it is becoming more difficult for security teams to stay on top of cyber risks across all cloud workloads, services, resources, users and applications. In addition, teams are dealing with a multitude of specialised stand-alone solutions that provide no context and only a fragmented view of the risks. This approach makes security more expensive and complex, and cloud applications vulnerable to attack.

“Qualys is expanding its popular platform to provide a comprehensive solution that delivers visibility, context, speed, automation and orchestration to help organisations scale their security and compliance programmes for modern software development,” said Melinda Marks, Senior Analyst, ESG. “Qualys TotalCloud already integrates security into developers’ workflows, empowering them to deliver secure and reliable code. In turn, security teams gain the control and visibility they need to reduce vulnerability to attack, respond quickly to threats and thus manage risk.”

“As a finance company, we need continuous visibility into the security and compliance status of our cloud applications and clear insight into the risks,” said Prabhuram Rajarathinam, CISO at Cholamandalam Investment and Finance Company. “Qualys TotalCloud with FlexScan will help our cloud security and DevOps teams with multiple assessments to further strengthen the security of our cloud applications.”

Qualys has already secured more than 31 million workloads, and Qualys TotalCloud further enhances VMDR’s industry-leading accuracy with cloudnative FlexScan assessments to combine cloud posture management and cloud workload security into a single view that provides visibility into existing risks. TotalCloud automates inventory, assessment, prioritisation and risk remediation with an easy-to-use drag-and-drop workflow engine. This ensures end-to-end zero-touch security, from code to the production cloud application.

Qualys FlexScan

Qualys TotalCloud also introduces FlexScan, a comprehensive cloudnative assessment solution that allows organisations to combine multiple cloud scanning options. This gives them the most accurate security assessment possible for their cloud environment.

Security teams have multiple hybrid assessment capabilities at their disposal to secure the entire cloud attack surface:

Agentless zero-touch scanning driven by cloud provider APIs for rapid analytics.
Virtual appliance scanning to check unknown workloads over the network for open ports and detect vulnerabilities that are remotely exploitable.
Snapshot assessment, where the workload snapshot is made available for regular offline scanning, including vulnerability and OSS scanning.
Qualys Cloud Agents in the workload for comprehensive vulnerability, configuration and security analysis in real time.
Qualys TotalCloud provides the following benefits to security teams:

Instant status visibility of multi-cloud environments – The unified cloud status dashboard provides visibility into the inventory, security and compliance status of multi-cloud environments within minutes. Teams can easily identify and prioritise the highest risk misconfigurations and gain additional context on workload vulnerability and security status.

Holistic security visibility to prioritise cloud risks with TruRisk – The console provides a holistic view of cloud security that includes all cloud workloads, services and resources. In addition, Qualys TruRisk quantifies security risk based on workload criticality and detected vulnerabilities, and correlates risk with threat intelligence on ransomware, malware and exploitation. This allows risks to be prioritised, tracked and reduced.

Fast problem resolution with no-code drag & drop workflows – Integrating QFlow technology with TotalCloud saves security and DevOps teams valuable time and resources. Automation features and no-code drag-and-drop workflows simplify the time-consuming operational tasks of assessing vulnerabilities of short-lived cloud assets, alerting on serious threats, remediating misconfigurations and quarantining high-risk assets.

Shift-Left Security for Early Problem Detection – TotalCloud provides shift-left security capabilities integrated with developers’ existing CI/CD tools to continuously audit cloud workloads, containers and Infrastructure-as-Code (IaC) artefacts. This allows for quick identification of security vulnerabilities and corresponding remediation actions in the development, build and pre-deployment phases. Major cloud providers such as AWS, Azure and Google Cloud are supported.

“Cloud security is becoming highly fragmented with too many standalone solutions, and that adds complexity,” said Sumedh Thakar, president and CEO of Qualys. “Our customers want a seamless, comprehensive view of cyber risk that spans all their assets, whether in or out of the cloud. With our innovative TotalCloud solution, we provide a flexible, high-value, cloudnative risk assessment for our customers who want to move further into the cloud with Qualys.”

Qualys Total Cloud Live Event

Learn more about the new solution at our hybrid launch event on Wednesday, November 9, at 1:45 p.m. PT. To register, visit www.qualys.com/totalcloud-live.

Related Articles

Opinion piece: These ideas won’t work without money

Once again, a major coup is set to take place: with the NOOTS state treaty, Germany finally wants to push ahead with the digitisation of its administration. ‘A real boost,’ says Bitkom President Dr Ralf Wintergerst. In future, government agencies will be able to...

Share This