Comprehensive cloud security has unified AI posture, code protection and runtime defense
What is our primary use case?
I mostly work with a lot of AI use cases and some data governance use cases where we are focusing on the data because data can reside anywhere in the cloud. It is not limited to some storage. We do have a variety of services where data can reside and it is very crucial to identify those sensitive data and label them. When data is exfiltrated from one resource to another resource, we have to make sure that the DLP policies are fulfilled or enforced.
I have found that Wiz covers all the stages of the software development life cycle. It covers application or code security, DevOps security, and runtime security. It is a full-fledged CNAPP solution. All the areas within the development and the deployment side are covered.
How has it helped my organization?
The impact of consolidation on my ability to prioritize critical risks in the cloud environment is all about the correlation and how the technology works at the back end. It picks the data from different sources and correlates and identifies the high-priority risk. It provides visibility, meaning the risk score about the resource where we need to focus on.
Wiz does reduce alert fatigue for our customers, but alert fatigue is the main concern for every organization. If you don't have the proper workflow for each incident, it also depends upon the implementation and the workflow that you have decided. Sometimes it is a very big concern and a big headache for the customer because it finds a lot of findings that could be false positives. We have to fine-tune those alerts as per the infrastructure design. Sometimes some findings could be false positives, so we have to assess all these findings and we have to make sure that all policies are relevant for the environment.
The second point is basically the remediation steps. Sometimes it creates a burden or headache for the customer because the remediation of those kinds of findings are difficult. It may need a dedicated team who can get involved and fix them. Ownership and accountability is the main concern. We have to collaborate with different teams and make them understand the impact of that finding. The workflow also depends upon whether automation should be there. Automation is not for all findings, but for where we can do some kind of alerts where we can do the automation. For example, with IAM, those guys having the extra privilege, we can decide the workflow and we can remediate. But somewhere the service is running, we cannot immediately remediate those findings because it involves a lot of impact. First, we have to analyze each alert and what kind of impact it could be, then based on that, we have to plan whether it will be manual or through automation.
What is most valuable?
Wiz is currently allowing us to consolidate everything, the findings, the visibility of your environment, and everything is there.
Wiz Code is also covering your secrets and your vulnerabilities inside the IAC. It also provides us the SCA, Software Composition Analysis, and also provides an SBOM report that helps developers to look at the security standpoint while creating or writing any code. There are a lot of other things it is providing, but these are the major things.
Regarding Wiz Defend, the runtime protection, we do have the agent or sensor on the endpoint where it can defend in real time. There are two approaches. Detection is the one capability and protection is the second capability. At some stage, it only provides us the visibility, and at some stage, it also defends the attack.
I find AI security posture management very important in cloud security strategy. Nowadays, every organization is using different kinds of models or enhancing their applications. While they are using the models or they are calling through APIs, maybe sometimes they are using models inside their environment, sometimes they are just buying the APIs for any third-party model. While we are buying any APIs for their application or to integrate the LLM model into their application, it is crucial that we should have the visibility. Whoever kind of prompts the end user is triggering and what kind of data in or out is happening. Such kind of sensitive information may be traversing inside our network. The visibility of these things should be there so that preventive control can be implemented.
What needs improvement?
I believe Wiz could be improved or enhanced by acknowledging that nowadays a lot of technology is coming. Every solution is now doing the integration at the backend. They are trying to cover more areas in terms of cybersecurity. Definitely, every solution is growing as per the market demand. We can see a couple of more things coming soon, and every technology or technology owner is working behind the scenes. The purpose is basically the baseline foundation. If you talk about the CIA triad, that should be covered properly and everyone is doing the same thing.
I would like Wiz to push backend integration more, but not that much because license and procurement happen through a different team.
For how long have I used the solution?
I have been working with Wiz for the last three months, during which I deployed this Wiz solution for one of the clients.
What do I think about the stability of the solution?
The stability and reliability of Wiz are good. I don't feel any issues. It is good because whenever they are planning any activity, they generally inform us prior to implementation.
What do I think about the scalability of the solution?
Regarding the scalability of Wiz, it is good. I don't see or feel any kind of issue on the scalability or the performance. Every solution is running behind most probably on the Kubernetes services, they are using multiple containers and the pods behind those services. In terms of scalability, I don't feel any issues. It totally depends upon the license, how much license you procured. Based on that you can onboard or you can consume those licenses. Even if you go beyond that, you don't see any kind of challenges. It is pretty much good, not limited to Wiz but for all solutions I'm talking about. They are providing 99.99 kind of SLA. I don't see and feel such kind of issues in the past.
How are customer service and support?
I communicate with the technical support at some times when we feel that the technology is not working as expected. The outcome that we suppose is not getting as expected, so we generally raise a ticket with the provider. They assist as they regularly do.
What other advice do I have?
I have found that Wiz covers all the stages of the software development life cycle. It covers your application or code security, also covers DevOps security, and also finally covers the runtime security. It is a full-fledged CNAPP solution. All the areas within the development and the deployment side are covered.
My impression of Wiz Runtime Sensor is quite good. Runtime, as I already mentioned, in the runtime sensor, we are basically deploying the sensor on the endpoint. It could be your EC2 instance, the virtual machine, container, and the Lambda function as well. It detects and blocks in real time and blocks the attack in real time. It is really convenient. Sometimes zero-day vulnerability is not possible in agentless scanning. When I say agentless scanning, we don't have a sensor on the device. But while we are putting the sensor, we have these kinds of visibility and it protects or helps us with zero-day attacks as well. That is really helpful for the organization.
On the ability side of Wiz regarding its ability to achieve zero criticals in its issue queues, there is no doubt. But it also depends upon the use case as well. We have a limited use case for the recent deployment, it is all about the deployment. But as a part of product maturity, we can leverage or we can explore more things.
While deploying any controls, there are a lot of prerequisites and readiness for that. We have to collaborate with different teams. It could be the network team, generally the network team, the cloud team, and the infrastructure team, where we have to explain the use case of that particular control, why we are putting it, and what is the requirement. Once we have a good understanding about the infrastructure and about the technologies, we generally deploy the solution phase-wise. In phase one, we just target one or two test environments where we can provide some ROI against those accounts and resources. Down the line, we are covering in phases, more accounts and resources. That is how the approach we are currently following, and generally every organization is doing the same thing.
Most of the customers prefer a hybrid environment, not limited to the on-prem or cloud. Everyone is using a hybrid environment nowadays. It could be Azure, AWS, and sometimes on-prem. But the capability that the solution is providing is very limited to the on-prem environment. They more focus on the cloud environment first and are limited to the endpoint protection if I talk about the runtime monitoring. The rest of the things cover the cloud environment only, the identity and the access part.
To get the full potential of Wiz, it is good and good for the cloud environment and the hybrid cloud environment. Some part of it is covering the on-prem as well.
I would rate this product a 9 out of 10 based on its comprehensive coverage and capabilities.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Security scanning has consolidated cloud vulnerabilities and provides clear remediation paths
What is our primary use case?
As a customer, I use Wiz myself, but because I work for the Commonwealth Bank, it could be a partner with Wiz. I don't have insight into this tool as it is a very large organization and was already in place before I joined, with other people having set it up, so I don't have that background.
So far, I am scanning for vulnerabilities in packages and dependencies. I use Wiz Code a bit.
What is most valuable?
What I like most about Wiz is that it is similar to other tools. Wiz has integrated with industry standards, such as security protocols and policies like Open OWASP and several others, based on my security standards for scanning packages, finding vulnerabilities, and providing fix versions based on its search and information retrieval.
I think it is at a good price and gives analysis while working well with other testing or pen testing tools that other security teams use to scan software to ensure it aligns with security requirements. Wiz helps because other tools, based on what they detect, usually reflect those fixes or remediations in other tools as well. Wiz gives a very good insight into how secure your software and code are.
Wiz is quite good at consolidating the scanning results.
What needs improvement?
Wiz is agentless, which is a plus, but the runtime and real-time detection could be limited, as it is not its strength. I could not give details on how limited it is. Its price could be high compared to others, and I feel it is expensive.
For how long have I used the solution?
I have been using Wiz for one and a half years.
What do I think about the stability of the solution?
I would give stability a nine because I did not see significant instability.
What do I think about the scalability of the solution?
I feel scalability is good, and I can give it a nine. We have many pipelines running Wiz scanning, and I have not seen Wiz pending or taking too long, which is a good thing.
How are customer service and support?
I rate support from Wiz an eight.
How was the initial setup?
Regarding installation, I just joined and used it, which might not be my area to comment on whether it is easy or difficult.
What was our ROI?
I see possible ROI with Wiz, but as I mentioned, I am not at that level of use. I just researched Wiz prices, and I got a feeling about it.
Which other solutions did I evaluate?
I do not have in-depth knowledge to give a detailed pros and cons analysis of Wiz compared to products such as OWASP, SonarQube, or Snyk. However, when comparing Wiz to Dynatrace or Snyk, I see they focus on different areas. Dynatrace focuses on code quality scanning, and Snyk may have more focus on security. Wiz scans artifacts or dependency packages, which is a bit different from SonarQube, as SonarQube scans code. However, Wiz is able to scan code and also manage the artifactory, dependencies, and their versions. This is quite similar to JFrog X-ray scanning.
What other advice do I have?
Wiz Code impacts the development workflow similar to SonarQube. Wiz Code can detect coding quality issues or coding conventions and those kinds of problems. Nowadays, we leverage AI tools for development. As a developer, I probably use AI for initial code, and in most cases, I just review and integrate, with the AI generating code programming. Wiz Code or SonarQube scans those codes and then gives a report. If we instruct the AI or do proper prompting, they usually give very good code that can pass the scanning.
AI security is definitely very important for our security strategy.
AI security posture management is important because if you use an AI tool, you need to protect your data. As a commercial company or even a government organization, you do not want to leak sensitive data such as PII or other organization-related data to the AI, especially in uncontrolled environments. When we use AI tools at the Commonwealth Bank itself, we are only allowed to use internal AI, which means it has many regulations in place, including guardrails, and the deployment environment looks at both input and output, ensuring that data does not go to the internet. This protects organization-level data and filters unnecessary inputs and outputs.
For Wiz Runtime Sensor, I am not quite familiar with it, but I know that this tool is meant to find dynamic analysis at runtime. I probably have little practice with another tool called OWASP ZAP.
I think the alert fatigue from Wiz is quite similar at the same level as the other scanning tools. If it detects any critical or high vulnerabilities, it alerts you. You can set up alerts based on your standards or rules to send alerts. With alerts based on findings, it allows you to set alerts on multiple domains such as vulnerabilities. For example, you might have critical CVEs on an EC2 instance and send an alert. It could also be scanning identity risks and possibly security exposures such as secrets exposure. Wiz covers a lot, including data exposure and attack paths. In alerting, it gives very clear information such as severity, affected resources, risks, and possibly an attack path description explaining how an attacker might use that vulnerability. Wiz includes such information based on severity, affected resources, attack paths, risk descriptions, and possibly remediation guidance.
If I summarize everything about Wiz, it deserves an eight in general.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Automation has transformed cloud and container security posture and reduced manual effort
What is our primary use case?
My main use case for Wiz is that it identifies misconfigurations within the cloud services and misconfiguration within the Kubernetes platform. We also detect vulnerabilities within the runtime from the containers. Once we have those findings in place, we run a cron job within the GitLab pipeline wherein it pulls all vulnerabilities and misconfigurations and then creates tickets to the respective teams through Jira or through ServiceNow. Everything is totally automated. A Python function has been created which pulls all the vulnerabilities, performs data enrichment to identify the ownership, and then assigns the SLA and the SLA breach timeline, based on which it is then posted to the respective groups.
What is most valuable?
The best features Wiz offers in my experience are the collective findings that you get to see for each resource, which is called something as issues. It combines all findings, whether it is exposed to the internet, whether it has misconfigurations, whether there is encryption in place, or whether there is an IAM issue in place. You get to see all findings for a particular resource in one view, which Prisma or some other tool was not offering at this moment. Wiz is also offering ASPM at a service management level, KSPM, and AI security.
Wiz has positively impacted my organization because with the consequence model, as and when the consequence model triggers, every team goes ahead and mitigates the findings to ensure that it is not escalated to the CEO level. The automation is helping us to drive our platform to be more secure.
What needs improvement?
I choose eight out of ten because there is always room for improvement. Possibly I am not able to identify it, but definitely there would be some room for improvement. Nothing is perfect in terms of security.
We are in the process of getting to zero-day vulnerabilities.
For how long have I used the solution?
I have been using Wiz for the past two years, enabling CSPM and CWP mainly, but as of now we have also started with KSPM, which is Kubernetes security posture management and data security posture management as well in my current company.
What do I think about the stability of the solution?
Wiz is stable in my experience.
What do I think about the scalability of the solution?
Wiz's scalability is good as of now because the attributes we need in terms of identifying vulnerabilities is pretty good compared to Prisma.
How are customer service and support?
Customer support is good. They are really helpful, but it is only the management who gets to interact with the sales team.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We did evaluate CrowdStrike, Tenable One, and Prisma Cortex.
How was the initial setup?
We create dashboards with the automation, so all the findings being pulled from Wiz are enriched first, and then we store all those findings with the SLA metrics into a Grafana dashboard.
What was our ROI?
I have seen a return on investment with Wiz, specifically in that we need fewer employees.
What other advice do I have?
I would advise others looking into using Wiz to definitely compare it with all the other tools that are in the market. Wiz is one of the finest tools that I have used so far, and it gives visibility to all the services based resources, which other tools do not give. It also helps to create custom policies based on Rego, which is one of the easiest solutions that anyone can develop. I give this product a rating of eight out of ten and would definitely recommend Wiz.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Wiz Brings Clarity and Prioritization to Cloud Security
What do you like best about the product?
The UI is amazing, and it's only the tip of the iceberg: the graph-query engine underneath is super powerful. There's a bit of a learning curve here, but the AI tool is a big help with this part.
Plus, the documentation is excellent and the team are very customer focused.
What do you dislike about the product?
The colors of the new logo 😁
The PoV was a stressful process, it's a rather unique approach to buying a software solution IME.
What problems is the product solving and how is that benefiting you?
Wiz gives structure and prioritization to our cloud security efforts. No more worrying about every CVE, we can focus on the few that really matter !
Comprehensive Cloud and Code Security with Excellent Visibility and Fast Deployment
What do you like best about the product?
Very easy to deploy and quick to start delivering value. It provides excellent visibility across a wide range of security risks and surfaces vulnerabilities that might otherwise go unnoticed. The remediation guidance, particularly the GenAI step-by-step explanations, is genuinely useful for helping teams understand and fix issues rather than just identifying them.
What do you dislike about the product?
Some capabilities are consumption-based, so it is important to understand how certain features could affect cost. That said, it is straightforward to control or limit additional spend if needed.
What problems is the product solving and how is that benefiting you?
Wiz provides us with a consolidated view of security risks across our cloud estate and code base. It has improved our visibility, helped us uncover issues we hadn’t previously detected, and made it easier for teams to prioritise and remediate vulnerabilities. Overall, it’s having a positive impact on our security posture.
Easy, Agentless Deployment, Useful and pertinent security alert.
What do you like best about the product?
First of all, the deployment was very easy: there was no agent to install and no complicated onboarding. It was up and running in less than half a day. For the smaller details, our TAM was available very quickly and knows the product almost perfectly. The issue tab is really useful to pinpoint exactly what you need to address quickly by providing a good context, and help to cut the alert fatigue drastically. That's a tool we're using daily and that is completely integrated into our alerting process.
The pertinence of issues are also very good, having a platform that we can trust about the severity of issues is a game changer.
What do you dislike about the product?
As today, unfortunately we didn't find a downside of WIZ compared to other product.
What problems is the product solving and how is that benefiting you?
Our first problem was the alert fatigue, we come from a regular CSPM, without any context. WIZ was able to cut the alert fatigue instantly, the user adoption of the tool was greatly improved by that.
Instant Cloud Visibility and Clear, Actionable Risk Insights
What do you like best about the product?
Wiz provides full visibility into our cloud resources. It was easy to set up; within minutes, I was able to connect Wiz to my entire environment. It then performs a full inventory of my environment and clearly presents the outstanding vulnerabilities and misconfigurations, and most importantly, the toxic combinations that should be addressed immediately. Also, Wiz support is excellent
What do you dislike about the product?
I honestly do not think there's anything I dislike about Wiz.
What problems is the product solving and how is that benefiting you?
Wiz is helping us solve issues around resource visibility and inventory. In a cloud environment, where resources can be spun up very easily, Wiz captures those changes quickly and highlights possible misconfigurations or other concerns that should be addressed. It also doesn’t just present findings; it correlates toxic combinations and indicates what specifically requires urgent attention. I find Wiz threat intel really good, especially because it correlates that intel with my resources and lets me know whether any of them are affected.
Wiz AI security is also great. As an organization that is rapidly embracing AI for our processes and workflows, Wiz provides full visibility into our usage of AI services across our cloud providers, including possible misconfigurations, Shadow AI, the use of sensitive data for AI model training, and publicly exposed MCPs within my environment.
Wiz Delivers Comprehensive, Low-Noise Security with High-Value Findings
What do you like best about the product?
Ever since we adopted Wiz, it has delivered to us in every sense ranging from code security all the way to infrastructure security, providing a comprehensive all in one platform which has helped us to consolidate our security tooling enormously. Wiz does well in showing us which findings require our attention and which ones perhaps do not, this is very different to other platforms that are out there which we have found to be overwhelming due to the amount of noise generated. On top of this, Wiz has helped us detect findings that all other providers missed which to us showcased the value of using Wiz as a security platform.
What do you dislike about the product?
There isn't really anything that I have disliked about Wiz, other than perhaps the cost which can be slightly higher than competitors however I think this ends up balancing out due to the value provided by Wiz.
What problems is the product solving and how is that benefiting you?
As with many businesses, security and more so visibility into issues within our platform has always been a pain point due to the amount of disconnected tools that we had to implement. Whereas with Wiz, it has helped us consolidate all of them into a singular comprehensive and connected platform.
Helpful Dashboards and Clear Resource Categorization for Faster Troubleshooting
What do you like best about the product?
Dashboards and how resources are being categorized for easy troubleshooting.
What do you dislike about the product?
The MITTR dashboard needs more work to be comprehensive especially on the Executive overview.
What problems is the product solving and how is that benefiting you?
It gives us the overview of our environment and every resources. Easy to track issues down to the source and providing a remediation steps which can be automated.
Fully Integrated, Fast-Evolving Platform That Listens to Customer Feedback - highly recommended!
What do you like best about the product?
Wiz is a fully integrated system, and whenever there are areas where it isn’t, the team at Wiz closes the gap quickly. They use customer feedback to develop the service at a fast pace, staying aligned with what the market wants and needs.
What do you dislike about the product?
I think Wiz should do more to improve its built-in agents, because the integrated knowledge the service collects, along with the TI information streamed through the product, could be used by an agentic system to deliver much faster responses across any framework.
What problems is the product solving and how is that benefiting you?
Wiz is solving cloud security posture management, as well as CDR and holistic view on identities across our cloud