Security consultant configuring Qualys VMDR for a client
Qualys consultancy

Qualys Consultancy Services

You already own Qualys. We help you make it useful — fixing VMDR configuration, scanner coverage, asset tagging, reporting and patch management so your team gets reliable data and a clear list of work.

Authentication coverage
95%+
Duplicate asset records
-80%
Report noise reduction
-70%
Illustrative figures
The challenge

Why an existing Qualys subscription often fails to deliver.

Most organisations that contact us already have a Qualys licence. They also have a lot of data, a long list of critical findings, and a team that has stopped trusting any of it. The platform is not the problem — the configuration, ownership and workflow around it usually are.

The first thing we see is authentication gaps. An unauthenticated scan infers patch levels from network banners, so it misses real vulnerabilities and reports issues that were fixed months ago. We regularly find that thirty to fifty per cent of the estate has no working credentials, which makes every dashboard and trend report unreliable.

Asset tagging is the next issue. Tags were often set up during the initial deployment and never maintained. Servers move site, change function or get decommissioned, but the tags do not. The result is scan jobs targeting the wrong groups, patch jobs running against test boxes, and reports that mix production and lab data.

Reporting then becomes the reason people disengage. A CSV with fifteen thousand rows, four thousand of them marked critical, is not a work queue — it is a resignation letter for whoever has to read it. Without grouping by fix, prioritisation by actual risk, and a management trend view, the report is ignored and the programme stalls.

Patch Management is frequently bought but not configured. The operating system patching is usually handled elsewhere, and the third-party applications that actually carry most of the exposure — browsers, PDF tools, Java runtimes, remote access clients — are left unmanaged. The patching dashboard shows green while the vulnerability report stays red.

Underneath all of this is an ownership gap. Security bought the tool, IT runs the infrastructure, and neither team has written down who configures it, who triages the output, who owns remediation, and who checks that fixes actually worked. Findings age not because people are lazy, but because the work has no home.

  • Large parts of the estate scanning without credentials
  • Asset tags that no longer match the real environment
  • Reports that produce noise instead of a work queue
  • Patch Management bought but not covering third-party software
  • No written ownership between security and IT operations
Our approach

How we fix it without taking over the programme.

We start with a health check. We look at your Qualys subscription, the modules you have licensed, how scanners and agents are deployed, what authentication records exist, how asset tags are structured, and what reports are currently produced. The output is a short, prioritised fix list ranked by what will most improve the quality of your data.

Authentication is usually the first fix. We build and test credentialed scanning for Windows, Linux, network devices and databases, and we treat authentication failures as a work queue rather than a footnote. Until the scan is seeing the real patch state, everything downstream is guesswork.

Next we rebuild the tagging strategy. That means agreeing what dimensions matter — site, function, criticality, owner, environment — cleaning up duplicates and stale records, and writing a short runbook so new assets get tagged correctly as they are provisioned. Tags are boring until they are wrong, and then they break everything.

We then tune the scanning. Option profiles are matched to asset type and fragility, scan windows respect your change control, and cloud connectors are configured so ephemeral instances do not keep appearing as ghosts after they have been destroyed. We also set up a reconciliation between Qualys and your CMDB or AD so coverage gaps surface quickly.

Reporting is redesigned around two audiences. Operations get a short, prioritised queue grouped by fix, with owners and due dates. Management get a trend view: exposure over time, mean time to remediate, SLA performance and exceptions. Both are built in Qualys so they refresh automatically.

If Patch Management is licensed, we configure it properly. That means covering third-party applications, setting up pilot rings, scheduling in local time for global estates, and validating that a patch job actually closed the finding rather than just reporting success. We also integrate with Intune or Windows Update where that is how the operating system is already patched.

Throughout the engagement we work alongside your team and document what we change. The goal is to leave you with a clean, maintainable Qualys environment and the knowledge to keep it that way, not a dependency on us.

  • Health check to find the highest-impact fixes first
  • Credentialed scanning built and tested across the estate
  • Tagging strategy rebuilt with a maintainable runbook
  • Scanning tuned for accuracy and change-control windows
  • Reporting split into operational queue and management trend
  • Patch Management configured for third-party coverage and validation
What's included

Everything in the engagement, set out up front.

A focused consultancy engagement to make your existing Qualys investment useful.

VMDR implementation review

We review how VMDR is configured today — agents, scanners, authentication, option profiles and connectors — and fix the parts producing bad data.

Scanner deployment and tuning

Physical, virtual and cloud scanner placement, scan windows, asset group scope and option profiles matched to the systems being scanned.

Tagging strategy and cleanup

A tagging model that fits your estate, cleanup of stale and duplicate records, and a runbook to keep tags accurate as assets change.

Reporting optimisation

Operational queues for IT and trend dashboards for management, built inside Qualys and refreshed automatically from live data.

Patch Management configuration

Third-party patch coverage, pilot rings, local-time scheduling, rollback planning and validation that fixes actually closed the findings.

Technical troubleshooting

Health checks, authentication failures, scan errors, duplicate records, connector issues and any other configuration problem we find.

Deliverables

What you receive.

  • Qualys health-check report with prioritised fix list
  • Reconciled asset inventory with clean tagging
  • Verified credentialed scan coverage across the estate
  • Tuned option profiles and scan schedules
  • Operational remediation queue for the IT team
  • Management trend dashboard with SLA tracking
  • Patch Management configuration and runbook
  • Knowledge-transfer session and documentation pack
Who it suits

Built for organisations that need the work done properly.

Organisations that bought Qualys but never got value

You have the licence, the data is flowing, but nobody trusts the findings or acts on them. We fix the setup so the platform starts earning its cost.

Internal security teams that need extra hands

Your team knows what needs doing but does not have capacity to unpick months of configuration drift while keeping everything else running.

IT teams inheriting a Qualys deployment

The person who set it up has left, documentation is thin, and the current team needs someone to explain what was configured and why.

Regulated firms preparing for assessment

You need clean evidence for Cyber Essentials, ISO 27001, PCI DSS or insurer reviews and want the scanner configured to produce it automatically.

Outcomes & benefits

What changes once the work is done.

What changes once the configuration, data and reporting are fixed.

Reliable scan data

Credentialed coverage and clean asset tags mean the findings you see are real, current and attached to the right owner.

A queue people will actually work

Reports are short, prioritised by risk and grouped by fix, so the IT team gets a list of actions rather than a spreadsheet of noise.

Faster, provable remediation

Patch Management covers the applications that were previously missed, and validation re-scanning proves the fix stuck.

Clearer compliance evidence

Scan schedules, patching records and exception registers are already in the format assessors, insurers and auditors expect.

Less friction between security and IT

Written SLAs, pilot rings and exception routes give both teams a shared process so remediation stops getting stuck in handovers.

A platform your team can operate

Documentation and knowledge transfer mean the improvements last after we leave, instead of drifting back within a quarter.

Why Qualys programmes fail — and the technology we work with.

The pattern is consistent. An organisation buys Qualys VMDR, runs a scan, gets a huge report, and assumes the tool will drive the remediation. It does not, because scanning is only the first step. Risk falls when someone acts on the findings, and that requires ownership, prioritisation and a workflow that the scanner cannot create for you.

Poor asset visibility is the quiet killer. You cannot remediate what you have not mapped, and you cannot report a trend if the denominator keeps changing. We reconcile Qualys against CMDB, Active Directory, Intune and cloud provider inventories so the estate being scanned matches the estate you think you have.

Security and IT Operations often disagree on priorities. Security is measured on closing findings; Operations is measured on uptime and change success. Both are reasonable. Where there is no agreed SLA, no pilot ring and no exception route, the same critical finding gets discussed every week and fixed never. We write that handover down so both sides know the rules.

We work primarily with Qualys VMDR and Qualys Patch Management, but we also integrate with Microsoft Defender Vulnerability Management, Microsoft Intune, Windows Server Update Services and the standard cloud connectors. The right answer usually involves using each tool for what it is good at, rather than forcing Qualys to do everything.

  • Scanning alone does not reduce risk — workflow and ownership do
  • Asset data from Qualys must be reconciled with CMDB, AD and cloud inventories
  • Security and IT Operations need a written handover, not a shared inbox
  • Qualys VMDR, Patch Management, Defender and Intune used for their strengths
Frequently asked questions

Questions we are asked most often.

Do we have to hand over the whole vulnerability management programme?

No. This is consultancy, not a takeover. Most clients keep their internal team running the day-to-day work. We come in to fix the configuration, build the processes and leave you self-sufficient. If you later want us to run the programme for you, that is a separate managed service, but it is not what this page is selling.

We already have Qualys VMDR. What is usually wrong with it?

The most common problems are authentication records that do not cover the estate, asset tags that were set up once and never maintained, scan option profiles that are too aggressive or too light, and reporting that shows every finding without any prioritisation. The result is a lot of data and very little action. We unpick those issues in order of impact.

Can you help us deploy scanners or agents for the first time?

Yes. We design the scanner placement — physical, virtual or cloud — against your network topology and segmentation, configure option profiles that match the asset type, and roll out agents through your existing deployment mechanism. We also test authentication records for each platform before any production scanning starts.

Why does asset tagging matter so much?

Tags are the foundation of everything else in Qualys: scan jobs, patch jobs, dashboards, user permissions and reports. Poor tagging means the same server gets scanned three different ways, patch jobs hit the wrong machines, and a board report cannot separate production from test. We build a tagging strategy around site, function, criticality and owner, and we document how to keep it current.

How do you fix Qualys reporting so people actually read it?

We stop trying to report every finding. Instead we build two views: an operational queue for the team doing the fixing, and a management trend view showing exposure direction, mean time to remediate and SLA performance. We also group findings by fix, so one patch that closes two hundred entries is shown as one action, not a wall of noise.

Can you configure Qualys Patch Management for third-party software?

Yes, and that is often where the biggest gap is. Operating system patching is usually handled by Windows Update or Intune, but browsers, PDF tools, Java runtimes and remote access clients are frequently unmanaged. We configure Qualys Patch Management to cover those applications, set up pilot rings and schedule jobs in local time for global estates.

What does a typical engagement look like?

It starts with a health check: we review your existing Qualys setup, identify the top three things breaking your data, and agree a fix plan. We then work through configuration, tagging, scanning, reporting and patch management over a defined period, with regular checkpoints and knowledge transfer. Most engagements run from four to twelve weeks depending on estate size.

Will this help with Cyber Essentials or ISO 27001?

Yes. A well-configured Qualys environment is one of the easiest ways to produce evidence for Cyber Essentials patching requirements and ISO 27001 technical vulnerability management controls. We align the tagging, scan schedules and reports to the framework you are being assessed against, so the evidence is already in the right format.

Do you support estates with multiple sites or cloud providers?

Yes. We have worked with single-site SMEs and multi-region organisations with hybrid infrastructure. The tagging and scanner strategy has to account for split domains, cloud connectors, regional maintenance windows and different teams owning different parts of the estate. We design the setup so it stays accurate as the environment changes.

What happens after the consultancy ends?

You get documented configuration, runbooks and a clean Qualys environment your team can operate. We also leave a short list of ongoing hygiene tasks — tag reviews, authentication checks, option profile tuning — so the setup does not drift back to where it was. Ongoing ad-hoc support is available if you need it.

Get more value from the Qualys licence you already own.

Book a Qualys health check and we will identify the highest-impact fixes in your current setup, with a clear plan to make the platform useful to your team.

Book a Qualys health check