Posted inCloudSecurity

Qualys enhances posture management and workload security across hybrid cloud

Qualys TotalCloud extends the accuracy of VMDR with cloud-native FlexScan assessments to unify Cloud Posture Management and Cloud Workload Security in a single view with risk insights.

Cloud security
The project will leverage hardware to bolster cloud security.

Qualys has announced TotalCloud with FlexScan delivering cloud-native VMDR with Six Sigma Accuracy via agent and agent-less scanning for comprehensive coverage of cloud-native posture management and workload security across multi-cloud and hybrid environments.

With more than 31 million workloads already secured by Qualys, Qualys TotalCloud extends the accuracy of VMDR with cloud-native FlexScan assessments to unify Cloud Posture Management and Cloud Workload Security in a single view with risk insights. TotalCloud automates inventory, assessment, prioritisation and risk remediation via an easy-to-use drag-and-drop workflow engine for continuous and zero-touch security from code to production cloud applications.

Qualys FlexScan

Qualys TotalCloud introduces FlexScan a comprehensive cloud-native assessment solution that allows organisations to combine multiple cloud scanning options for the most accurate security assessment of their cloud environment.

Security teams will have multiple hybrid assessment capabilities to secure the entire cloud attack surface including:

  • Zero-touch, agent-less, cloud service provider API-based scanning for fast analysis.
  • Virtual appliance-based scanning to assess unknown workloads over the network for open ports and remotely exploitable vulnerability detection.
  • Snapshot assessment that mounts the workload snapshot for periodic offline scanning including vulnerabilities and OSS scanning.
  • Qualys Cloud Agents in the workload for comprehensive, real-time vulnerability, configuration and security assessment.

Qualys TotalCloud provides security teams with:
Immediate multi-cloud posture insights — The unified cloud posture dashboard provides inventory, security and compliance posture insights across multi-cloud environments in minutes. Teams can easily identify and prioritise the misconfigurations that cause the highest risk with additional context on workload vulnerability and security posture.

Unified security view to prioritise cloud risk with TruRisk — A single view of cloud security insights across cloud workloads, services and resources is provided via the console. Additionally, Qualys TruRisk quantifies security risk by workload criticality and vulnerability detections and correlates it with ransomware, malware and exploitation threat intelligence to prioritise, trace and reduce risk.

Fast remediation with no code, drag-and-drop workflows — The integration of QFlow technology into TotalCloud saves security and DevOps teams valuable time and resources. Automation and no-code, drag-and-drop workflows help simplify the time-consuming operational tasks of assessing vulnerabilities on ephemeral cloud assets, alerting on high-profile threats, remediating misconfigurations, and quarantining high-risk assets.

Shift-left security to catch issues early — TotalCloud provides shift-left security integrated into developers existing CI/CD tools to continuously assess cloud workloads, containers and Infrastructure as Code (IaC) artifacts. This allows for the rapid identification of security exposures and remediation steps during the development, build and pre-deployment stages while providing support for the major cloud providers including AWS, Azure and Google Cloud.

Qualys TotalCloud is currently in preview. It will be generally available by the end of the year.