


Checkmarx One and Wiz are prominent players in the security tools category. Checkmarx One has an upper hand in code analysis, while Wiz excels in cloud-native application protection.
Features: Checkmarx One supports SAST, SCA, and IAC, greatly assisting in code security. Its integration with numerous SCM solutions and CICD tools makes it a go-to option for developers. Fast scanning and broad language support improve security by identifying precise vulnerabilities. Wiz provides advanced cloud-native protection, known for its security graph and risk prioritization. Comprehensive scanning across environments and efficient false positive management streamline security processes.
Room for Improvement: Checkmarx One could benefit from reducing false positives and enhancing CI/CD pipeline integration. Users also request dynamic testing support and cost adjustments. Wiz should enhance reporting and customization features, integrate with various ecosystems, and improve real-time threat detection and alert management. Improved support for complex findings and advanced reporting capabilities is also needed.
Ease of Deployment and Customer Service: Checkmarx One provides flexible deployment options, including on-premises and hybrid cloud. However, its customer service needs improvement in responsiveness and support proactivity. Wiz excels in cloud deployments, enabling smooth integration and fast time-to-value, yet there is room for better support responsiveness and reporting improvements. The ease of use in cloud environments gives Wiz a deployment advantage.
Pricing and ROI: Checkmarx One is seen as a premium product, with pricing considered justified for its capabilities but challenging for smaller teams. Its modular licensing can scale with module usage. Wiz is similarly viewed as expensive but delivers significant value through visibility and potential cost savings via tool consolidation, aiding returns through enhanced security and faster resolution time.
The solution provides a good ROI, especially for regular customers, offering discounts for three-year licenses.
I don't think the tool in itself is very capable of doing that, but we have XSOAR and other tool integrations done on the platform, so this can be accomplished.
Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
Based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year.
doing everything manually would take a lot of work and effort, and Wiz reduces both the workload and the need for manual thinking and human feedback.
Wiz Code allows us to scan all accounts within minutes.
I think we're reaching the point where we'll see a return on investment, and we'll be there by the end of the year.
If I make it a high priority, they have resolved one query within 20 minutes.
If local Indian support cannot resolve an issue, global tech support aligns promptly within the agreed SLA.
Fast response times and knowledgeable staff who understand the intricacies of the system.
If you raise a support case with Checkmarx, it is handled smoothly.
The customer support team is amazing and they provide on-phone call, email support, and on-website support.
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive.
On a scale from 1 to 10, I would give Wiz's support a 10.
The vendor was readily available to assist us over calls, clarifying both technical aspects and theoretical insights.
If I were to put Wiz support on a scale from one to ten, I would give them a ten.
For stability, scalability, mean time to response, and potential incident investigation improvements, I would give it a nine or probably even a ten.
Onboarding endpoints and assets on Cortex Cloud by Palo Alto Networks is very easy.
The platform is able to auto-shut certain resources that are not in use through the agentless scan feature.
Approximately four billion lines of code are being scanned monthly.
Since it is cloud-based, the infrastructure and PaaS, IaaS, and SaaS are taken care of by the cloud marketplace.
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
Our environment quadrupled in size. We didn’t have to make any adjustments or configuration changes; it just accommodated the growth.
In terms of scalability, I don't feel any issues.
In terms of cloud environment scalability, this is where Wiz Code generally excels, being built to handle thousands of AWS accounts, multi-cloud environments, and millions of cloud resources.
My impression of Cloud Runtime Security in stopping attacks in real-time is that I have never had an issue where it has let something through, causing an outage or concerns to the customer.
However, now in Cortex Cloud, I have not seen any lag or buffer.
My evaluation of how stable and reliable Cortex Cloud by Palo Alto Networks is very positive.
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
Checkmarx One is often down when the cloud provider experiences issues.
The stability of Wiz has been good, with no downtime, bugs, or glitches.
The best part is that their entire solution is built on APIs, allowing for easy integration without a codeless approach.
The services were stable, and we did not experience any downtime.
Regarding the generative AI security tool, I know for sure it's Agentic.
The solution is quite premium in cost compared to alternatives such as Wiz.
There is not a clear MSP model compared to other vendors such as CrowdStrike.
Integration into the IDE being used would be beneficial so that code does not need to be uploaded to the website and an IDE-friendly report could be generated.
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
If you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great.
One significant area for improvement would be increasing automation. While they excel at identifying issues, we need assistance in minimizing the human hours required for tasks.
Adding AI-driven features could significantly assist developers in addressing vulnerabilities more efficiently, thereby improving deployment times and adherence to deadlines.
Governance is the area where Wiz Code actually shines; for large enterprises, governance is not just finding vulnerabilities; it includes ownership, accountability, exceptions, policies, risk acceptance, and auditability.
The solution is costly, with high-end capabilities suitable for enterprises.
Today, it is smart and easy to calculate the licenses.
For a small team under 50 developers, normal expenses come under 30 to 60K.
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable.
The pricing should be reasonable, matching what we are paying for.
I don’t think there’s anyone else out there offering the same level, scale, or efficiency.
If you are a small scale enterprise organization, you probably would not pay such a hefty amount of money to protect your organization.
Wiz is less expensive than Microsoft and Palo Alto.
AI/ML aids in anticipating remediation for misconfigurations and vulnerabilities, and automatic remediation can be easily configured.
Cortex Cloud by Palo Alto Networks has reduced the time spent on incident investigations, and if I had to estimate, I would say it has cut our investigation time in half.
This simplifies the management of shared responsibility among different people and entities, allowing you to use one single tool instead of having dozens of different tools to orchestrate and integrate.
Since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days.
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages.
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle.
The ability to scan every layer without agents is a huge selling point because we're multi-agent.
My favourite is the EASM/External Exposure view and overall package - full risk visibility. It allows us to prioritize, and I mean truly prioritize, what should be addressed first.
The granularity of visibility that the platform provides is the most valuable aspect.


| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 1 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 32 |
| Midsize Enterprise | 9 |
| Large Enterprise | 46 |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 12 |
| Large Enterprise | 48 |
Cortex Cloud by Palo Alto Networks enhances cloud security with features like AI/ML threat detection and automated remediation, ensuring real-time protection and efficient management across cloud environments.
Cortex Cloud by Palo Alto Networks offers comprehensive cloud security posture management and runtime protection. It reduces manual tasks and accelerates incident investigation through advanced threat detection and AI-driven anomaly detection. With integration to the MITRE ATT&CK framework, it boosts threat response while reducing incident resolution time. Although users find the UI complex and pricing high, its capabilities in securing AWS, Azure, and other environments, as well as its potential integration with CyberArk, emphasize its enterprise-ready design for cloud transformation across diverse industry sectors.
What are the key features of Cortex Cloud by Palo Alto Networks?Cortex Cloud by Palo Alto Networks is deployed across industries like telecom, BFSI, and manufacturing for robust cloud security. It's leveraged for detecting misconfigurations and vulnerabilities, aiding cloud transformation and compliance with standards such as GDPR and NIST. The integration across cloud infrastructures, including AWS and Azure, supports policy creation and threat management strategies for diverse enterprises.
Checkmarx One delivers robust security through seamless integration with SCM and CI/CD tools, ensuring reliable SAST and SCA. Primarily used by organizations for vulnerability detection, it supports cloud and on-premises deployment to enhance secure coding practices.
Checkmarx One provides organizations with comprehensive tools for secure software development, integrating effectively with CI/CD pipelines to scan thousands of applications. Its capabilities extend to identifying vulnerabilities in both code bases and third-party software. Enhancing workflow by supporting SCM solutions, it assists in maintaining secure coding standards and compliance. While excelling in various areas, it requires improvements in scan speed, reduction of false positives, and broader platform integration, particularly for COBOL and Swift. Its pricing model is noted as high, and demand exists for better tutorials and documentation.
What are the key features of Checkmarx One?Industries implement Checkmarx One for secure coding compliance and vulnerability management across varying environments, choosing between cloud and on-premises deployment based on requirements. Its extensive language support and integration with DevSecOps practices make it a popular choice for organizations aiming to enhance software security.
Wiz enhances cloud security with features like CSPM, risk prioritization, and centralized visibility. Users benefit from agentless scanning and integration with CI/CD tools, improving threat detection and compliance management.
Wiz offers a comprehensive security solution for cloud environments by providing functionalities like threat intelligence, detailed risk analysis, and automated compliance mapping. It supports vulnerability management and risk analysis, utilizing agentless deployment for seamless integration across multi-cloud settings. The platform's ability to streamline workflows and reduce false positives enables users to improve remediation speed and bolster security posture. Despite impressive capabilities, there is a need for improvement in reporting, security functionality for Kubernetes, handling false positives, and integration with APIs. Enhanced dashboards and more flexibility in automation processes are also required.
What are the key features of Wiz?Industries integrate Wiz for cloud security posture management, ensuring compliance and managing vulnerabilities in multi-cloud environments. Users leverage its agentless capabilities to protect cloud-native applications, integrating with CI/CD pipelines to enhance security operations and automate remediation. This comprehensive approach offers robust cloud security solutions.
We monitor all AI Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.