I have been using Wiz for approximately three years in my career. Our first use case is Cloud Security Posture Management. We needed that because we are a multi-cloud company. We have most of our infrastructure in AWS, but we also have some in Azure and some in GCP. So we needed a CSPM to cover all three environments.
E VP And Chief Information Security Officer at Rate
Cloud security has unified multi-cloud visibility and simplifies vulnerability management
Pros and Cons
- "One of the things that Wiz has done well is that there are no agents for the CSPM, at least from what we are doing, and it is very easy to roll out, easy to configure, maintain, and generally it does what it says it does with few issues."
- "We have an integration with ServiceNow, but Wiz's ServiceNow integration is not the best."
What is our primary use case?
What is most valuable?
The feature I appreciate most about Wiz as a CSPM is the vulnerability detection and misconfiguration identification. It helps us to ensure that we know if there are misconfigured cloud workloads and what those are, as well as if there are vulnerabilities. That is one of the key value adds for us.
What we have done is create a tool that is not just a security tool but is actually used by other teams. We have created dashboards for other teams, for product teams who are developing code. They can see their assets, or our cloud team or other teams that own different assets can view their own team's vulnerabilities and misconfigurations through per-team dashboards.
For us, the value add when considering Wiz is that I would rather consolidate under fewer tools to get to a platform. This allows for alerts, administration, and dashboards to all be under one platform, simplifying the environment. It makes operations easier and ultimately enhances our ability to use the platform more effectively.
What needs improvement?
Wiz allows us to consolidate tools, particularly in vulnerability management. We used to use a technology called Tenable to do our vulnerability scans, not just on-prem but in the cloud, and we replaced Tenable with Wiz's capabilities as well as the capabilities of an endpoint protection technology we use called CrowdStrike.
Regarding scalability, we have connected to all our cloud accounts and have never had any capacity or performance issues, so scalability really has not been a topic of conversation for us because we have never had any issues.
I have contacted customer support for Wiz. They are aware of our discussions about it. We have talked about it during our quarterly business reviews.
What do I think about the stability of the solution?
I have never seen any instability with Wiz, such as lagging, crashing, or downtime.
Buyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We have connected to all our cloud accounts and have never had any capacity or performance issues, so scalability really has not been a topic of conversation for us because we have never had any issues.
How are customer service and support?
I have contacted customer support for Wiz. They are aware of our discussions about it. We have talked about it during our quarterly business reviews.
I am a few steps removed from the details about the support quality and speed, but my impression through the team and talking with the account team directly is that when we raise issues, they are addressed thoughtfully, professionally, and quickly. I do not think there have been any lingering support issues we have had. We have also surfaced feature requests or changes, and they have implemented those and rolled those out within a few weeks. Wiz does a good job of listening to the feedback of their customers and using that to help shape the platform.
Which solution did I use previously and why did I switch?
I have not used any alternatives to Wiz. Wiz was our choice; although we evaluated different technologies when we were looking for a CSPM, we went with Wiz, so we went from nothing to Wiz.
How was the initial setup?
The initial deployment of Wiz was easy from my point of view. Essentially, once we connected Wiz to our AWS account, all the data starts to flow in and telemetry on our cloud assets, any vulnerabilities, and misconfigurations. So the dashboards light up with red, yellow, and green indicators. After deciding to go with Wiz, our proof of concept ended up becoming our production implementation, and we just expanded Wiz to more accounts, then to Azure and GCP. So it was very easy.
What about the implementation team?
I do not know exactly how long it took to fully deploy to a working condition because it has been so long ago, but I will say that getting the visibility was in a matter of weeks to connect the accounts, probably within a week. Then it was a few months to build some of the dashboards and operationalize what we were seeing.
What other advice do I have?
Feature-wise, I cannot tell you that it is a bit expensive compared to its peers, but I do think the premium is worth it. One of the things that Wiz has done well is that there are no agents for the CSPM, at least from what we are doing. It is very easy to roll out, easy to configure, maintain, and generally it does what it says it does with few issues. We had more overhead and more issues with other competing CSPM platforms.
From the team standpoint, I do not think Wiz requires much maintenance on our end because it is all cloud-based and Wiz does a great job of providing almost weekly updates. The ongoing maintenance itself of Wiz is low. We do have integrations which require some care and feeding. We have an integration with ServiceNow, but Wiz's ServiceNow integration is not the best. I have been told there have been issues getting the data out of Wiz and plugged into ServiceNow effectively, so that has taken a little bit more attention.
We are working on achieving zero criticals in our issue queues with Wiz. It has helped us gain visibility into our critical issues, but we still have a few dozen left to work through. A lot of that actually has to do with some older infrastructure and workloads that applications use. So we have some application migrations in the works, but we have not quite got to the zero critical status.
I would rate this review as a 9 overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jan 28, 2026
Flag as inappropriateSenior Cloud Infrastructure Engineer at Self-Employed
Centralized cloud security monitoring has improved compliance reporting and cross-team visibility
Pros and Cons
- "Wiz significantly helped with our compliance requirements."
- "From a technical perspective, Wiz is excellent, but the pricing is too expensive."
What is our primary use case?
The product was implemented for AWS monitoring and cloud infrastructure monitoring. Our goal was to conduct security monitoring of cloud infrastructure. Wiz was the first product we selected, and we were not using any other product, so this was not a consolidation effort.
What is most valuable?
The installation and configuration process was straightforward, and the onboarding was smooth. The user interface of Wiz, including the graphics, dashboards, and overall design, is user-friendly. The customization capabilities are excellent, allowing us to tailor the tool based on our requirements.
When someone worked from another country and connected with an unusual IP address, the system provided us with a notification, which was valuable.
Wiz significantly helped with our compliance requirements. The tool makes it easy to generate compliance reports by selecting a specific compliance framework, and it creates the report automatically.
The product provides an overview of our entire company through dashboards, and access was not limited to our security team. We provided access to other departments and software developers, allowing them to monitor the dashboards as well. This broader accessibility made Wiz a valuable tool for our organization.
What needs improvement?
During the initial setup, obtaining support was not easy initially. When assistance was needed, response times were longer than desired. However, the documentation was comprehensive, so there were no major blocking challenges.
After purchasing the product, support quality improved significantly. As a paying customer with a license fee, we found that support was responsive and easy to reach.
From a technical perspective, Wiz is excellent, but the pricing is too expensive.
We experienced pressure to monitor license costs constantly because they increased automatically. There was no way to limit these increases, which was a significant stress point.
What do I think about the stability of the solution?
Wiz is very reliable. The services were stable, and we did not experience any downtime. During monitoring operations, we did not encounter any issues that required attention or fixes. From the first day of implementation, the product worked well and remained stable.
What do I think about the scalability of the solution?
Wiz scales easily. The platform automatically scales itself, though this automatic scaling also increased our license costs, which required monitoring. The scalability happens in the background without requiring manual intervention.
How are customer service and support?
After purchasing the product, support was satisfactory. As a paying customer with a license fee, we received good support and found it easy to reach out to the team. Overall, the support experience was satisfactory.
Which solution did I use previously and why did I switch?
I used this product at my previous company but am no longer a customer.
How was the initial setup?
The installation and configuration process was straightforward, and the onboarding was smooth.
During the initial setup, obtaining support was not easy initially. When assistance was needed, response times were longer than desired. However, the documentation was comprehensive, so there were no major blocking challenges. Overall, we did not experience any significant blocker challenges with Wiz.
Which other solutions did I evaluate?
We did not experience any security threats, but the monitoring of our infrastructure was valuable. We did not use any other solution, though it was reassuring to know that Wiz was operational and running.
We conducted proof-of-concept evaluations with different tools. Wiz was easy to onboard to our infrastructure. We did not want to spend excessive time on integrations and configurations during the initial phase. The process was straightforward, which was a key factor in our decision. Additionally, because we were using AWS infrastructure, Wiz could be purchased directly through the AWS Marketplace, which was another reason we selected it.
What other advice do I have?
The setup process takes approximately fifteen to twenty minutes. If you are not using artificial intelligence, you may not need this capability. However, if you are using artificial intelligence in your portfolio, it is important.
Control is essential when using artificial intelligence because there are instances where you feel out of control. You do not know what is happening in the background, and artificial intelligence agents are working and performing tasks. When you have a security tool controlling everything, it is truly useful.
We used filters that Wiz provides while configuring alerts. You can avoid false positives, excessive noise, or alert spam by using these rules and alert configurations.
The company was a startup in its initial phase, and I was involved in choosing the technology tools stack from the beginning.
We did use the features available. Our goal was not to avoid using the product's capabilities. I would rate this review nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 30, 2026
Flag as inappropriateBuyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.
Senior Engineering Manager, Data & AI at Omnissa
Has consolidated multiple tools while improving issue detection and inventory tracking
Pros and Cons
- "Wiz has helped me consolidate some tools, as it is not just doing the job of the security tool alone, and we do not need to invest in multiple tools because all aspects such as infrastructure, application, vulnerabilities, and the regular security scoring patterns are in-built into Wiz along with the inventory manager."
- "More or less, Wiz is doing well, but the false alerts at random times would be another area for improvement."
What is our primary use case?
My use case for Wiz is basically for overall security, focusing on vulnerability management, infrastructure security, and application security, all of that combined. I have my AWS accounts where I run multiple services, so that's where I'm utilizing Wiz to the core optimum, utilizing all of its capabilities. Even as an inventory management tool, I think it has been really helpful because it keeps a record of every change, making it very functional.
How has it helped my organization?
Wiz has helped me consolidate some tools, as it is not just doing the job of the security tool alone. It has good inventory management, good vulnerability management, and we do not need to invest in multiple tools. All aspects such as infrastructure, application, vulnerabilities, and the regular security scoring patterns are in-built into Wiz along with the inventory manager, which has helped us reduce one or two tools here and there.Wiz has reduced alert fatigue in my organization, as it is very accurate in terms of reporting the issues, which has definitely improved, and I don't see a concern.
What is most valuable?
The best features of Wiz that I appreciate the most include trends of security, such as how we have been getting issues reported and how frequently we are closing them, along with the capabilities to notify a user and a channel on Slack, which have all been really helpful beyond just doing its main job as a security framework.The extent to which the Wiz runtime sensor has helped identify active threats more effectively compared to other solutions I've used is significant, as it refreshes based on a schedule in terms of the latest findings. It has been pretty effective for our use case, as I keep checking for anything new reported there. We also have a ticketing mechanism attached to it, so as soon as a security issue is figured out, it creates a ticket on Jira, allowing us to keep track of issues, and it is pretty responsive in terms of catching the latest issues.Wiz has helped me achieve zero criticals in issue queues, as it detects a range of issues whether it is the end of life of a product or an actual security issue, such as an exposed port or a compromised service.
What needs improvement?
In Wiz, the areas that have room for improvement would include some autonomous capabilities, such as having an agent declare where, since we are in the era of AI, it can auto-solve some low or medium alerts. High and critical issues would still need manual handling, but some level of alerts being handled autonomously would be good. More or less, Wiz is doing well, but the false alerts at random times would be another area for improvement. I would also appreciate seeing it go deeper on the security aspect, expanding beyond just infrastructure and application to include potential issues stemming from APIs, as currently it focuses more on the infrastructure pieces. Having more visibility in API endpoints, microservices, and application code running on the infrastructure would be beneficial.
For how long have I used the solution?
I have been using Wiz for the past 18 months.
What do I think about the stability of the solution?
The stability of Wiz has been good, with no downtime, bugs, or glitches. Just today I was not able to load it, but I wouldn't blame it that much as I have always been able to access the application when reaching out. I would rate the stability out of 10 as about nine or 10.
What do I think about the scalability of the solution?
Wiz is scaling well for our use case, so I would rate scalability a 10 out of 10.
How are customer service and support?
I would rate technical support as about nine, as we had a couple of cases where the responses were delayed quite a bit, but apart from that, they have been spot on.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I cannot name the vendor I used previously, but the reason for switching to Wiz was the added features that we were getting, which offered more control on cloud security.
How was the initial setup?
The deployment process of Wiz was easy and not complex. It was fairly straightforward, honestly. The internal configurations took time due to the different applications we have, but I don't think there was any delay from the Wiz side.It took about three to four weeks to deploy Wiz, as the time taken was more about how we wanted to structure the projects and boxes inside Wiz from our perspective. We were operational from the first week and integrated with SSO projects by the third or fourth week.
What about the implementation team?
The integration capabilities of Wiz were generally seamless, although we had some complications with Oracle accounts. Integration with AWS was pretty straightforward, but with Azure and Oracle, Oracle had some limitations regarding what it could report to Wiz. However, I think there was some more fine-tuning and adjustments done by the Wiz team to ensure Oracle could also be onboarded correctly, so that worked out.
What was our ROI?
The purchase of Wiz was a direct purchase rather than through the AWS marketplace or a partner purchase.
What's my experience with pricing, setup cost, and licensing?
My thoughts on the pricing of Wiz is that for our use case, it has been moderate, as I was using a different tool earlier, so it's not been a very large jump. I would say it resides in that moderate zone, and it's not something that raises eyebrows, so I think we're good.
Which other solutions did I evaluate?
I would say Wiz is in the top tier, and it might just be the leading product as well. While there are a couple more products out there, I think Wiz is definitely leading the course at this point.
What other advice do I have?
I have created some custom dashboards, charts, and counters, and I have created some custom reports that are sent out, including a lot of widgets for my reporting of all the accounts that I have. I have almost seven to eight accounts where very large workloads are running, and in total, there are almost 20 accounts, so it gives a very good view to summarize all of the accounts in one place.My business is a medium enterprise with about 5,000 employees.The maintenance of Wiz is fairly easy, with a few people looking into it, but it's not as though their whole time is dedicated to Wiz, which is a good part.I absolutely recommend Wiz to other users because of its ease, features, and user-friendliness, allowing anyone to come in, configure all the things they want out of Wiz, and start using it. There is no doubt about that. I would rate this review an 8 out of 10 overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Specialist at Zensar Technologies
Comprehensive cloud security has unified AI posture, code protection and runtime defense
Pros and Cons
- "I have found that Wiz covers all the stages of the software development life cycle; it covers application or code security, DevOps security, and runtime security, and it is a full-fledged CNAPP solution where all the areas within the development and the deployment side are covered."
- "Sometimes it is a very big concern and a big headache for the customer because it finds a lot of findings that could be false positives."
What is our primary use case?
I mostly work with a lot of AI use cases and some data governance use cases where we are focusing on the data because data can reside anywhere in the cloud. It is not limited to some storage. We do have a variety of services where data can reside and it is very crucial to identify those sensitive data and label them. When data is exfiltrated from one resource to another resource, we have to make sure that the DLP policies are fulfilled or enforced.
I have found that Wiz covers all the stages of the software development life cycle. It covers application or code security, DevOps security, and runtime security. It is a full-fledged CNAPP solution. All the areas within the development and the deployment side are covered.
How has it helped my organization?
The impact of consolidation on my ability to prioritize critical risks in the cloud environment is all about the correlation and how the technology works at the back end. It picks the data from different sources and correlates and identifies the high-priority risk. It provides visibility, meaning the risk score about the resource where we need to focus on.
Wiz does reduce alert fatigue for our customers, but alert fatigue is the main concern for every organization. If you don't have the proper workflow for each incident, it also depends upon the implementation and the workflow that you have decided. Sometimes it is a very big concern and a big headache for the customer because it finds a lot of findings that could be false positives. We have to fine-tune those alerts as per the infrastructure design. Sometimes some findings could be false positives, so we have to assess all these findings and we have to make sure that all policies are relevant for the environment.
The second point is basically the remediation steps. Sometimes it creates a burden or headache for the customer because the remediation of those kinds of findings are difficult. It may need a dedicated team who can get involved and fix them. Ownership and accountability is the main concern. We have to collaborate with different teams and make them understand the impact of that finding. The workflow also depends upon whether automation should be there. Automation is not for all findings, but for where we can do some kind of alerts where we can do the automation. For example, with IAM, those guys having the extra privilege, we can decide the workflow and we can remediate. But somewhere the service is running, we cannot immediately remediate those findings because it involves a lot of impact. First, we have to analyze each alert and what kind of impact it could be, then based on that, we have to plan whether it will be manual or through automation.
What is most valuable?
Wiz is currently allowing us to consolidate everything, the findings, the visibility of your environment, and everything is there.
Wiz Code is also covering your secrets and your vulnerabilities inside the IAC. It also provides us the SCA, Software Composition Analysis, and also provides an SBOM report that helps developers to look at the security standpoint while creating or writing any code. There are a lot of other things it is providing, but these are the major things.
Regarding Wiz Defend, the runtime protection, we do have the agent or sensor on the endpoint where it can defend in real time. There are two approaches. Detection is the one capability and protection is the second capability. At some stage, it only provides us the visibility, and at some stage, it also defends the attack.
I find AI security posture management very important in cloud security strategy. Nowadays, every organization is using different kinds of models or enhancing their applications. While they are using the models or they are calling through APIs, maybe sometimes they are using models inside their environment, sometimes they are just buying the APIs for any third-party model. While we are buying any APIs for their application or to integrate the LLM model into their application, it is crucial that we should have the visibility. Whoever kind of prompts the end user is triggering and what kind of data in or out is happening. Such kind of sensitive information may be traversing inside our network. The visibility of these things should be there so that preventive control can be implemented.
What needs improvement?
I believe Wiz could be improved or enhanced by acknowledging that nowadays a lot of technology is coming. Every solution is now doing the integration at the backend. They are trying to cover more areas in terms of cybersecurity. Definitely, every solution is growing as per the market demand. We can see a couple of more things coming soon, and every technology or technology owner is working behind the scenes. The purpose is basically the baseline foundation. If you talk about the CIA triad, that should be covered properly and everyone is doing the same thing.
I would like Wiz to push backend integration more, but not that much because license and procurement happen through a different team.
For how long have I used the solution?
I have been working with Wiz for the last three months, during which I deployed this Wiz solution for one of the clients.
What do I think about the stability of the solution?
The stability and reliability of Wiz are good. I don't feel any issues. It is good because whenever they are planning any activity, they generally inform us prior to implementation.
What do I think about the scalability of the solution?
Regarding the scalability of Wiz, it is good. I don't see or feel any kind of issue on the scalability or the performance. Every solution is running behind most probably on the Kubernetes services, they are using multiple containers and the pods behind those services. In terms of scalability, I don't feel any issues. It totally depends upon the license, how much license you procured. Based on that you can onboard or you can consume those licenses. Even if you go beyond that, you don't see any kind of challenges. It is pretty much good, not limited to Wiz but for all solutions I'm talking about. They are providing 99.99 kind of SLA. I don't see and feel such kind of issues in the past.
How are customer service and support?
I communicate with the technical support at some times when we feel that the technology is not working as expected. The outcome that we suppose is not getting as expected, so we generally raise a ticket with the provider. They assist as they regularly do.
What other advice do I have?
I have found that Wiz covers all the stages of the software development life cycle. It covers your application or code security, also covers DevOps security, and also finally covers the runtime security. It is a full-fledged CNAPP solution. All the areas within the development and the deployment side are covered.
My impression of Wiz Runtime Sensor is quite good. Runtime, as I already mentioned, in the runtime sensor, we are basically deploying the sensor on the endpoint. It could be your EC2 instance, the virtual machine, container, and the Lambda function as well. It detects and blocks in real time and blocks the attack in real time. It is really convenient. Sometimes zero-day vulnerability is not possible in agentless scanning. When I say agentless scanning, we don't have a sensor on the device. But while we are putting the sensor, we have these kinds of visibility and it protects or helps us with zero-day attacks as well. That is really helpful for the organization.
On the ability side of Wiz regarding its ability to achieve zero criticals in its issue queues, there is no doubt. But it also depends upon the use case as well. We have a limited use case for the recent deployment, it is all about the deployment. But as a part of product maturity, we can leverage or we can explore more things.
While deploying any controls, there are a lot of prerequisites and readiness for that. We have to collaborate with different teams. It could be the network team, generally the network team, the cloud team, and the infrastructure team, where we have to explain the use case of that particular control, why we are putting it, and what is the requirement. Once we have a good understanding about the infrastructure and about the technologies, we generally deploy the solution phase-wise. In phase one, we just target one or two test environments where we can provide some ROI against those accounts and resources. Down the line, we are covering in phases, more accounts and resources. That is how the approach we are currently following, and generally every organization is doing the same thing.
Most of the customers prefer a hybrid environment, not limited to the on-prem or cloud. Everyone is using a hybrid environment nowadays. It could be Azure, AWS, and sometimes on-prem. But the capability that the solution is providing is very limited to the on-prem environment. They more focus on the cloud environment first and are limited to the endpoint protection if I talk about the runtime monitoring. The rest of the things cover the cloud environment only, the identity and the access part.
To get the full potential of Wiz, it is good and good for the cloud environment and the hybrid cloud environment. Some part of it is covering the on-prem as well.
I would rate this product a 9 out of 10 based on its comprehensive coverage and capabilities.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Mar 28, 2026
Flag as inappropriatePlatform Lead Commercial Integration Systems at a wholesaler/distributor with 5,001-10,000 employees
Security platform has provided unified visibility and actionable insights across all projects
Pros and Cons
- "What I appreciate most about Wiz is that it has access to all project scopes."
- "I found the initial setup of Wiz not entirely straightforward; there is a learning curve involved."
What is our primary use case?
I am a customer of Wiz, and we use Wiz for container scans, image scans, and code and build scans, with most of my use cases involving container and code and build scans.
What is most valuable?
What I appreciate most about Wiz is that it has access to all project scopes. For example, in an organization where I am part of a particular workstream, if I compare Wiz with other tools such as Snyk, I could only access my part of the organization, but in Wiz, the project scope lists all the areas of the projects. If I'm interested to know what's happening across data, finance, and warehouse, I can click and understand and review their vulnerabilities and trigger points. That's quite valuable.
The other thing I find useful is the information about policies. It has graph control which lists issues based on severity, risk, external attack surface, unprotected data, and remedies, and in some cases it highlights these. Recently, they added Mika AI, which is a cool feature. I can ask anything related to my work, and it responds based on certain trends, which is quite useful.
AI security is important to me because it helps. I have found one of their AI agents which is quite effective. It scans and provides trends of anomalies or vulnerabilities across various projects while supporting remedies as part of that. It is very important for me to assess what the AI suggests based on the scan it reviews across other projects. We review this before we hook our pipeline to see if we have vulnerabilities or anomalies in a particular area. We also try to prevent these rather than cure them, so we use the stats provided by AI to prevent anomalies or vulnerabilities from being detected and our security team having to chase us to fix them.
What needs improvement?
I'm not certain if Wiz allows me to consolidate tools because we link our integrations. When I say consolidate, I mean integrating with other third-party providers. We integrate with our integrations which are run via our build scan, so my experience is limited to our domain. I am not from security; I am a user of Wiz, and I try to use Wiz to ensure that the vulnerabilities it finds and scans can be actioned by our engineers. With respect to consolidation, I'm aware of what it does in my area. We only integrate our container and build scans with Wiz, and that works pretty well for us.
I think Wiz could be improved by identifying vulnerabilities occurring in a repeated pattern in the same estate. The AI capability should scan these and warn us based on historic data before moving or running a container scan. It should suggest somewhere on the dashboard that based on the last year, I've identified these vulnerabilities in a repeated fashion, so perhaps it's time to improve.
For how long have I used the solution?
I have been using Wiz for the last two years, probably around close to a year, but then I moved out from that engagement. I still have access to Wiz, and my account is still active with Wiz. The last time that I had hands-on experience with Wiz was three months ago.
What do I think about the stability of the solution?
I find Wiz to be pretty stable, and I have not heard of it going down.
What do I think about the scalability of the solution?
In terms of scalability, it is straightforward. During our busiest period, Black Friday, I have not heard of issues with Wiz struggling to cope with the volumes we handle.
How are customer service and support?
I would rate the technical support of Wiz a seven, as it is fairly decent. I can't think of anything I am not happy about with the technical support since I have not been directly involved; it is our security team. I haven't heard them complaining much, and they were responsive to our queries when we started the engagement.
Which solution did I use previously and why did I switch?
Before Wiz, I used Snyk for the same use cases. The decision to stop using Snyk and switch to Wiz was a central security decision, not mine. From what I understand, it may be related to Snyk becoming overly particular about the pricing models.
How was the initial setup?
I participated in the initial setup of Wiz during a pilot conducted by our security team, where my team was chosen to run scans on some of our repos. This was around two years back. I found the initial setup of Wiz not entirely straightforward; there is a learning curve involved. I believe the Wiz team was pretty supportive during our adoption journey.
What other advice do I have?
I am not certain if I utilized Wiz Defend in my security strategy as I haven't heard of it. There is a separate security team which adds the policies and the setup, and we are asked to run the respective pipeline so that all the container scans and build scans adhere to our security guidelines. It may be done as part of our security offering by the security team, which I am not aware of.
I am not certain what Wiz Runtime Sensor is or if it is part of the offering. I think it is available as part of the explorer, but I can't remember.
I can confirm that zero criticals in our issue queues is not possible; you will get critical vulnerabilities. What we have to assess is the level of security threat based on the score that is assigned. We do have critical vulnerabilities, but what Wiz does is help identify them, and wherever possible, provide a remedy or solution for them. We try to assess and review that periodically and try to reduce the severity of the vulnerability. In some cases, Wiz suggests certain actions which could probably downgrade the critical severity to medium or high.
Wiz has reduced alert fatigue in our area to some extent. It will identify a vulnerability, send an alert, and if there is a possible fix, if I give that command, then Wiz will try to do that by itself. I can't comment on the organization as a whole, but in the project that I have access to, I can see that for the last six months, Wiz has helped reduce alert fatigue by about twenty percent over a given time period.
Regarding the pricing of Wiz, that's a question for our security team; I don't know what tenant or at what level they have been using it. From what I understand, they are quite competitive and fairly price their offering. In an area where Wiz is helping us is in endpoint management, where their RED agent provides endpoints whenever incidents are raised. I believe they are pretty flexible on the pricing since they want to enhance their footprint globally.
I rate this review eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 5, 2026
Flag as inappropriateCyber Security Engineer at a consultancy with 10,001+ employees
Cloud risk posture has improved and custom dashboards and graph views provide deeper insights
Pros and Cons
- "One feature I particularly appreciate about Wiz is that, similar to other cloud-native security tools like Microsoft's Defender for Cloud, it allows you to define policies as code and deploy them through a version control system with a continuous deployment pipeline."
- "Wiz does encounter some glitches similar to other tools in the market; I remember facing certain challenges, such as problems scanning encrypted disks or discrepancies in the findings from already remediated vulnerabilities not reflecting accurately in the tool."
What is our primary use case?
My experience with Wiz varies on a case-by-case basis because I don't work on it daily; I engage with it when we need to research something that isn't fully implemented in the organization. Some elements are implemented, but they were done on a POC basis. I have hands-on experience where I've explored the environment extensively, checked vulnerabilities, and shared different findings with team members. So while I've worked with all that, I wouldn't classify it as part of my everyday BAU work, but I've been introduced to it in the last one or two years, max.
We have multiple subscriptions linked to Wiz, and we monitor various aspects including cloud security posture management findings. Compliance is another area we've focused on, where we've created our own compliance framework within Wiz. One feature I particularly appreciate about Wiz is that, similar to other cloud-native security tools like Microsoft's Defender for Cloud, it allows you to define policies as code and deploy them through a version control system with a continuous deployment pipeline. This functionality is also present in Wiz, where their Terraform provider enables complete documentation on controlling aspects directly in the Wiz environment. The major things we've worked on include deploying policies based on CSPM findings detected in Wiz, setting up our own framework and rules within those categories, and we've also worked with inventory management, as Wiz provides an AI-driven inventory that gives visibility into all cloud deployments. Wiz also helps manage vulnerabilities in various environments, such as Kubernetes clusters or Azure container apps.
In different organizational contexts, whether product-based or service-based, the customization of dashboards is highly beneficial. For instance, if I'm a startup or a large company using Wiz for multiple applications, custom dashboards allow me to categorize data from various feeds. Dashboarding becomes effective after managing categorization; I can define a project and add relevant resources or subscriptions under that project. Moving forward in the dashboarding section, I can set up custom widgets to view high-severity CSPM findings or risks, thus visualizing data based on specific filters and categories.
What is most valuable?
One feature I appreciate about Wiz is the graph controls, which allow for the correlation of multiple findings. For example, if a virtual machine has a critical CVE and is exposed to the internet, this links multiple vulnerabilities such as initial access types. Wiz attempts to categorize these different types of findings, such as CWPP and CSPM, and offers customization through graph controls where we can create our own contextual risk assessments in the cloud environment. Additionally, Wiz allows you to deploy aspects in the tool similarly to the GitHub model, which I appreciate. Its UI is also very smooth and categorized, making it easy to navigate and search through resources efficiently. You can create custom reports and dashboards in your own way, which are some of the major aspects I value in Wiz.
What needs improvement?
There is definitely room for improvement with Wiz. Given the scope of CNAP technology, which covers the entire SDLC from deployment to monitoring and APIs, it would be beneficial to enhance data integration capabilities. Wiz could partner with leaders in the market, such as Checkmarx, for example; while it currently supports Checkmarx in preview, there still needs to be significant enhancement in contextually mapping risks from pre-deployment scans, such as SAS, SCA, and DAST scanning results. Including these results would elevate contextual risk assessments to a higher level.
Wiz does encounter some glitches similar to other tools in the market. I remember facing certain challenges, such as problems scanning encrypted disks or discrepancies in the findings from already remediated vulnerabilities not reflecting accurately in the tool. These issues are not indicative of an overarching systemic failure but are worth noting as areas that could be improved upon.
Currently, Wiz doesn't consolidate tools effectively. Though it is starting to move in that direction with Checkmarx integration in preview, it lacks the maturity to fully replace other mature open-source tools. Wiz does offer some capability in SCA via CLI, but it falls short compared to its market counterparts and would benefit from further development in tool consolidation and correlation.
For how long have I used the solution?
I started using Wiz around two years ago.
What do I think about the stability of the solution?
During the POC, there were indeed a lot of alerts generated by Wiz. It's important to note that alerts vary in type; there are different classifications for vulnerability alerts, CSPM alerts, and contextual risk alerts. Each category has its own significance, meaning that while there may be a high volume of alerts, they can be beneficial and informative based on the context.
Wiz does encounter some glitches similar to other tools in the market. I remember facing certain challenges, such as problems scanning encrypted disks or discrepancies in the findings from already remediated vulnerabilities not reflecting accurately in the tool. These issues are not indicative of an overarching systemic failure but are worth noting as areas that could be improved upon.
What do I think about the scalability of the solution?
I rate Wiz's scalability a perfect 10 out of 10. During our POC, we successfully linked many subscriptions and could manage them effectively without encountering any scalability issues.
How are customer service and support?
I would rate the vendor's technical support as a nine out of ten. They respond swiftly and provide support when needed; for instance, when we experienced some initial trouble figuring out how to configure CCRs and validate results, the vendor was readily available to assist us over calls, clarifying both technical aspects and theoretical insights.
How would you rate customer service and support?
Positive
How was the initial setup?
I didn't handle the initial installation of Wiz directly; that task fell to the operations team responsible for deploying security tools. However, from what I gather, integrating Wiz into the environment is not complex. It primarily requires the creation of a service account with sufficient permissions for Wiz to access necessary resources, making the overall integration process straightforward. Challenges might arise from organizational dynamics when persuading stakeholders, but technically, the setup doesn't appear to be cumbersome.
What about the implementation team?
Many people participated in the POC phase with Wiz, involving different teams such as the operational team for deployment and others handling various security dimensions. Many teams contributed during the POC phase., focusing primarily on the security specialists without including end users.
What was our ROI?
I would have appreciated providing a more specific return on investment metric for Wiz, but since my experience with it is based on a POC without full implementation, I cannot precisely track its impact on time or resource savings. It hasn't been operationalized fully yet in our organization.
What other advice do I have?
My understanding of Wiz's pricing suggests it's not cheap. While I may not have direct involvement in pricing discussions due to different teams managing purchasing decisions, feedback indicates that Wiz is among the most expensive tools available. Though there's likely room for adjustment in pricing, it should be noted that, compared to tools such as Microsoft Defender for Cloud, which scales according to subscriptions, Wiz's pricing can be significantly higher when supporting multiple products within larger organizations.
Wiz was implemented as a POC, and while there were many subscriptions linked, I can share examples of its usage. For instance, when Log4j vulnerabilities emerged several years ago, we managed to quickly create a report through the Wiz dashboard, enabling us to identify all workloads impacted by a critical CVE. With resource tagging for ownership, this helped us reach out to the relevant individuals responsible. Although Wiz offers an option for service integrations such as Jira for issue creation if implemented fully, our approach was manual report generation, where we exported findings and alerted personnel to maintain a zero-issues status.
I would rate this review a 9 out of 10 overall.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Engineer II | Senior BI Developer | Data & Analytics Engineer at a manufacturing company with 5,001-10,000 employees
Centralized risk insights have improved cloud visibility and prioritize critical vulnerabilities
Pros and Cons
- "Overall, it helps strengthen our cloud security posture and manage risks more proactively."
- "Wiz can be improved by providing clearer remediation guidance, more actionable remediation recommendations, and better integration with existing security and ticketing tools."
What is our primary use case?
Wiz is primarily used for cloud security monitoring and risk assessment. I use it to identify security vulnerabilities and misconfigurations and potential risks across cloud environments and to prioritize critical issues and improve overall security visibility.
In my day-to-day work, I use Wiz to review cloud security findings and identify misconfigurations and vulnerabilities and prioritize high-risk issues. For example, when a resource has excessive permissions or an exposed configuration, I review the finding and assess its potential impact and coordinate with the responsible team to address it. This helps improve cloud security and visibility and reduce risk.
Wiz also helps improve visibility across cloud environments by bringing security findings into one place.
How has it helped my organization?
Wiz has impacted our organization positively because it improves cloud security visibility by helping teams identify vulnerabilities and detect misconfigurations and prioritize critical risks. It supports more efficient security reviews, better collaboration between teams, and faster remediation of important issues. Overall, it helps strengthen our cloud security posture and manage risks more proactively.
Wiz has helped our team identify and prioritize security issues more effectively and efficiently, reducing manual effort in reviewing cloud risk. It improves visibility into vulnerabilities and misconfigurations, helping teams focus on critical findings and respond more effectively. I have not tracked specific metrics for time saved or incident reduction, but the main benefit has been more proactive risk management and improved security visibility.
Wiz helped consolidate cloud security findings into a centralized view, making it easier to identify and prioritize critical risks. This improved visibility across the cloud environment and helped teams focus on high-impact vulnerabilities and misconfigurations instead of reviewing findings across multiple tools separately.
Wiz has helped make security alerts more manageable by centralizing findings and prioritizing critical risks. However, I have not measured the exact reduction in alert fatigue over a specific period, so I cannot provide a reliable percentage. The main benefit is that teams can focus more effectively on high-priority issues.
What is most valuable?
The most valuable features of Wiz are its centralized cloud security visibility, risk prioritization, vulnerability detection, and misconfiguration identification. I find the ability to understand potential risks and prioritize critical issues especially useful as it helps teams focus on the most important security concerns and improve their overall cloud security posture.
Risk prioritization is a feature I rely on most because it helps identify critical vulnerabilities and misconfigurations that need immediate attention. It allows teams to focus on the highest impact issues first and improve the overall cloud security posture.
Wiz runtime sensor can provide additional visibility into active threats and activity.
What needs improvement?
Wiz can be improved by providing clearer remediation guidance, more actionable remediation recommendations, and better integration with existing security and ticketing tools. Simplifying dashboards and reducing false positives would help teams prioritize genuine threats more efficiently. Improved reporting and customization options would also make it easier to track security improvements over time.
Better prioritization of security alerts, more accurate risk scoring, and clearer step-by-step remediation guidance would make Wiz even more effective. Enhanced automation for routine security tasks and more flexible reporting would also help teams save time and manage cloud security risk more efficiently.
Wiz could further improve its automated remediation capabilities, provide more customizable security reports, and offer clearer explanations of risk scores. Better integration with existing workflows and fewer false-positive alerts would help teams resolve genuine security issues faster and manage cloud risks more efficiently.
For how long have I used the solution?
I have been using Wiz for two years.
What do I think about the stability of the solution?
Wiz has maintained stability in my usage.
How are customer service and support?
Post-sales support services can help resolve technical issues, clarify security findings, and improve troubleshooting efficiency. I have not directly measured its impact on my team's productivity, so I cannot quantify the improvement. However, the support provided has been good and adequate.
Which solution did I use previously and why did I switch?
We did not use a previous different solution before Wiz.
What was our ROI?
Wiz has provided value by improving cloud security visibility, helping teams prioritize critical risks, and streamlining security reviews. These benefits can improve operational efficiency and support better risk management. However, I have not quantified the specific financial returns or cost savings, so I cannot provide verified return on investment metrics. That said, Wiz is useful and worth the return on investment.
What's my experience with pricing, setup cost, and licensing?
Licensing is an important consideration for our organization, especially when securing multiple cloud environments. Setup requires configuring integrations, access permissions, and security monitoring. Clearer pricing options and simpler licensing would make budgeting the cost and management easier.
Which other solutions did I evaluate?
Before choosing Wiz, we evaluated other cloud security platforms such as Microsoft Defender for Cloud or Prisma Cloud. Key considerations included risk prioritization, cloud visibility, integration capabilities, and ease of use.
What other advice do I have?
I rated Wiz better overall because it provides strong cloud security visibility, effective vulnerability detection, and useful risk prioritization. It helps teams identify misconfigurations, focus on critical security issues, and improve remediation workflows. Overall, it is a valuable platform for proactive cloud risk management and strengthening security posture.
Wiz's governance and security are valuable for maintaining a secure cloud environment. Strong access control, data protection, transparency, and responsible handling of AI-generated insights are important for protecting sensitive information. Overall, I value security-focused controls that help organizations use AI capabilities safely and confidently.
Regarding the accuracy and reliability of Wiz's output, the AI's capabilities can help improve the efficiency of security analysis by summarizing findings and providing remediation recommendations. The accuracy and reliability depend on the quality of the available data and context. Important findings should still be validated before taking action. Greater transparency and consistent context-aware recommendations would further strengthen trust in AI-generated outputs.
I can recommend Wiz for organizations looking to improve their cloud security and visibility and prioritize critical risks. Evaluate its integrations, pricing, and compatibilities with your cloud environment before adopting it. Ensure your team has a clear process for investigating and remediating security findings. I have rated this product a 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Oct 9, 2026
Flag as inappropriateSenior Iam Engineer at a tech vendor with 10,001+ employees
Unified cloud views have simplified finding infrastructure vulnerabilities and identity risks
Pros and Cons
- "The UI is what I appreciate most about Wiz; the interface is really easy and not clunky."
- "Wiz is not agnostic compared to other competitors in the market. If you want to add a new integration to another platform, it does not have an easy plug-and-play option for whatever platform."
What is our primary use case?
I have been working with Wiz for about two years. I use Wiz for vulnerability management, specifically finding infrastructure-related security bugs, particularly with Windows. I have also used it for a couple of months for identity-related purposes.
What is most valuable?
The UI is what I appreciate most about Wiz; the interface is really easy and not clunky. You can create many dashboards and a personal page for all the vulnerabilities you are trying to find. When it comes to your systems, users, and applications, having all of those attachments to your different platforms and being able to have the scans go throughout the platforms while pulling those vulnerabilities is really helpful with a nice user interface.
Wiz brings great integration into GCP resources, which is crucial for my previous organizations that were very heavily GCP-based. Wiz has seamless integration into GCP, AWS, Azure, Okta, and other large cloud platforms and SaaS platforms.
Wiz allows you to consolidate tools, but not all tools. It does not handle the nuanced type of tools, but the major tools it does allow you to consolidate from my experience.
The main advantage of Wiz is its user interface. A good interface makes it easy for engineers to not get fatigued from working with so much data and ensures it is not clunky-looking, as it is hard to identify issues. You want something that is visually appealing to identify risk, and having a good UI presents a huge benefit.
What needs improvement?
I would want to see Wiz improve by connecting to other major platforms agnostically, with the ability to connect to other platforms without needing to do too much integration. It requires a lot of alignment with different platforms for it to function properly.
I am not sure if Wiz has reduced alert fatigue in my organization, as I have not really looked into that aspect.
Wiz is not agnostic compared to other competitors in the market. If you want to add a new integration to another platform, it does not have an easy plug-and-play option for whatever platform. It requires integration to the proper tooling, and that is only from my experience with it.
For how long have I used the solution?
My experience with Wiz began six months ago.
What do I think about the stability of the solution?
I have not had any crashes, downtimes, or performance issues with Wiz.
What do I think about the scalability of the solution?
I find Wiz scalable and have tried to scale it up and out.
How are customer service and support?
I evaluate the customer service and technical support of Wiz as pretty useful. At my last company, we were able to have weekly calls with Wiz to talk about new updates and remediate any issues that we had. I would rate the technical support an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
I have used Exonius, but that is not a cloud posture platform; it is more of a logging platform or monitoring platform. I probably have used others, but I do not remember their names.
How was the initial setup?
Onboarding with Wiz is straightforward. I find it easy to teach myself how to use it, and I was able to figure it out within a week or two of just exploring it inside of Wiz.
What about the implementation team?
I was not involved in the setup deployment of Wiz.
What other advice do I have?
I have not utilized Wiz Defend. I do not use Wiz Code in my operations. I have not used the AI Posture Management in Wiz, but I have used Posture Management, though I only used it for a few weeks in the beginning.
I find Wiz Posture Management pretty beneficial in my overall cloud security strategy, as everything is in the cloud. Many companies use cloud resources, so I think it is pretty beneficial.
I have not utilized Wiz Runtime Sensor, as I am more infrastructure, networking, and compute-related, so I have not been involved in application risk and have not really used the runtime features for Wiz.
Wiz has not helped my organization achieve zero criticals in its issue queues. There are many critical issues that come up regularly, and having to tackle them means sometimes those critical issues cannot be resolved because of architectural issues. If you resolve it, there will be an issue within the architecture, so I do not think I have ever seen the critical issues get down to zero.
Regarding the cloud security democratization aspect of Wiz, I have only used it here and there for infrastructure-related items and touched some other cloud-related items, but from my scope, I do not think I have seen the actual impact it has on our entire team or organization. When I used it, I was a level one engineer, so I did not get to see the entire scope of its impact.
I have not used Wiz recently, but from my memory of using it, I did appreciate the identity platform and think that they should expand more into the identity area and make it more seamless for items such as RBAC or non-human identities.
I am not entirely sure how my latest company purchased Wiz, but my first company that I used it with bought it through Google's Marketplace.
I was not using Wiz post-sales support services.
My overall rating for Wiz is an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jun 23, 2026
Flag as inappropriateCyber Security Engineer at Tata Consultancy
Streamlines cloud risk prioritization and accelerates resolution of critical vulnerabilities and IAM issues
Pros and Cons
- "Wiz stands out for its strengths, particularly in agentless scanning and graph-based risk prioritization, in addition to its comprehensive CNAPP capabilities and multi-cloud coverage."
- "There is also alert noise in larger environments that generates duplicate alerts for the same issues under different categories."
What is our primary use case?
I have used Wiz for security findings, which includes dashboards with the main purpose of Cloud Security Posture Management. Wiz scans all cloud accounts to detect misconfigurations, open ports, publicly exposed resources, and weak IAM permissions. I also utilize it for vulnerability management, such as VMs, containers, serverless functions, and any IAM risky visibilities. I use Wiz for all these things as I work on these areas most of the time. Essentially, it is a cloud risk tool that prioritizes the most critical issues, allowing me to address high-yield issues quickly with the help of Wiz's architecture.
Achieving zero critical issues in Wiz means eliminating all critical severity securities across the cloud platform, which is a significant goal for our cloud security teams. I utilize the Risk Graph to identify real critical issues, prioritizing the resolution of public exposures and patching high and critical CVEs. I track OS-level and package vulnerabilities that need fixing, and sometimes when our OS isn't updated, it flags the errors. My processes involve patching libraries, upgrading AMIs, and removing secrets found in workloads, such as rotating keys for public IPs or un-updated software and databases. It is critical to implement least privilege measures for IAM risks, ensuring admin access is minimized. Moreover, I encrypt all storage and use tags to separate non-production issues according to different environments such as dev, stage, or prod. Utilizing Wiz projects, I segment teams such as network, platform, application, or DevOps so that each team handles their assigned issues, boosting closure speed. I also automate workflows through Jira to create tickets for critical exposures or IAM risks. Thus, achieving zero criticals in Wiz reflects my commitment to eradicating public exposures, patching critical vulnerabilities, and addressing IAM risks, ensuring I adhere to cloud best practices.
What is most valuable?
I love this interface because it is very clean, neat, and easy to understand. It includes the CNAPP and CSPM security features and extensively uses detection for vulnerabilities and misconfigurations. Everything is present on the dashboard. My personal interest lies in agentless scanning, which I consider the most powerful feature. The unique capability I can highlight is Attack Path Analysis, which identifies the exact path an attacker can exploit by correlating network exposure and any misconfigurations. Additionally, the unified Risk Graph is a very strong feature that helps teams find the most critical issues. I appreciate the accurate prioritization, which saves a great deal of time. Overall, Wiz provides a full CNAPP platform, encompassing CSPM, vulnerability management, IaC scanning, and more. I really appreciate these elements, and the dashboard is also very good.
What needs improvement?
I do not identify many areas for improvement, but I believe dashboard customization is somewhat limited. While the dashboards are quite good, the variety of widget types is restricted; I cannot fully customize colors or create complex multi-level dashboards. There is also alert noise in larger environments that generates duplicate alerts for the same issues under different categories. Furthermore, remediation automation is limited; Wiz suggests fixes but lacks auto-remediation for many issues. Compared to Prisma, the auto-resolve options are fewer. Although I have heard about deeper container and K8s scanning capabilities, I do not have a clear understanding of what that entails. I perceive that real-time cluster events are also somewhat limited. Regarding the reports, I face limitations in fully customizing PDF reports.
For how long have I used the solution?
I have been using Wiz for more than eight months.
How was the initial setup?
The setup for Wiz is a one-time configuration, similar to setups in ServiceNow or Ultimatics. This one-time setup ensures proper cloud integration, assessing the type of cloud account, the API permissions in place, and avoiding mistakes during the initial configuration. It highlights any missing requirements, such as IAM roles or permissions, and shows failed connections to allow for quick fixes. Agentless scanning is feasible, so this setup ensures proper configurations are in place. Additionally, it aids the administration in understanding what has been completed versus what remains pending. In summary, it guides onboarding tools to configure cloud accounts, permissions, and integrations accurately and prevents security visibility gaps while reducing onboarding errors.
The deployment time is not measured in days, weeks, or months; rather, it typically takes between five to ten minutes at most. IAM configurations and similar setups may take about two to three minutes.
Which other solutions did I evaluate?
When comparing Wiz with other solutions on the market, I note that my initial experience was with Prisma Cloud. Wiz stands out for its strengths, particularly in agentless scanning and graph-based risk prioritization, in addition to its comprehensive CNAPP capabilities and multi-cloud coverage. However, I recognize that certain areas, such as runtime threat detection and response, might be handled better by other vendors; while Wiz excels in posture and risk analysis, its runtime protection may not be as advanced as specialized tools designed for workload protection. Other tools might offer better capabilities for behavioral or anomaly detection, as Wiz may not capture the most subtle runtime issues. For instance, scanning public and private buckets requires waiting for scheduled scans or conducting manual scans, which can take significant time to yield updated records. While other vendors might possess better flexibility, the overall effectiveness depends heavily on data size and volume. I observe that legacy security vendor solutions offer mature enterprise support, while newer CNAPP solutions such as Wiz move rapidly but face trade-offs in large regulated enterprises. Overall, Wiz receives high ratings for its innovation and speed, which are great qualities despite some areas requiring improvement. So, in summary, I consider Wiz one of the strongest CNAPP platforms due to its agentless scanning architecture, making it lighter to deploy than competitors such as Prisma Cloud or Lacework. Nonetheless, organizations needing deep runtime protection or specialized identity entitlement management might want to explore other platforms, but I can definitely recommend Wiz for various needs.
What other advice do I have?
For the dashboard itself, it is a very simple and clear function. I generally go to the dashboards to create and add widgets for vulnerability by severity, public exposure, or misconfigurations. I also include widgets such as graphs or tables based on my requirements. I utilize saved views for custom data, which filters the exact information I have in the dashboard, for example, all AWS EC2 instances with critical CVEs or public-facing VMs with secret keys. Multiple sections include critical compliance and posture scores, and I apply filters at the dashboard level too. Essentially, I have almost everything available in terms of customization. I simply need to understand how to use Wiz dashboard in conjunction with my project requirements. Although Wiz is a relatively new tool and I have only worked on a portion of its capabilities, I can refer to the documentation to successfully carry out the needed customizations.
I find the pricing to be cost-effective, as Wiz includes features that many other vendors lack. It seems reasonable when compared to alternatives. Overall, pricing can vary significantly based on Wiz's licensing of workloads, which depends on the number of VMs, containers, and functions I deploy. However, I can request volume-based discounts for larger deployments, especially if managing numerous workloads. Hence, I classify Wiz as cost-effective.
I notice that redeployment is generally very easy compared to other CNAPP tools because it is agentless. The agentless architecture permits multiple operations without the need for redeployment. I only need to connect to the cloud, set up scans, and ensure workload visibility, making the entire process straightforward.
The results from using Wiz have been quite positive; it effectively reduces alert fatigue within my organization. It is clearly a time-efficient solution, which enhances operational efficiency.
I indeed consolidate tools when using Wiz, effectively streamlining processes to enhance focus on critical risks. I would rate this solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineering Lead at Persistent Systems
Cloud risks have become transparent and vulnerability management is now streamlined
Pros and Cons
- "Wiz helps to identify active threats more effectively as it does active scanning on workloads, keeps looking into logs and images of virtual machines, and upon detecting threats, it checks possible connections through events and logs, giving visibility into where the issue started and exactly where it is."
- "An area of improvement is that there is a lot of data inside Wiz and the naming is confusing, as similar categories for vulnerabilities and issues sometimes duplicate issues across resources, which can be hectic."
What is our primary use case?
I basically use it for vulnerability management, so from an admin's perspective, I am using it as an actual user of Wiz. It is for vulnerability management majorly, and to apply or review the compliances of the cloud environment.
How has it helped my organization?
Wiz helps to consolidate our tools. Wiz helps to identify active threats more effectively as it does active scanning on workloads, keeps looking into logs and images of virtual machines, and upon detecting threats, it checks possible connections through events and logs, giving visibility into where the issue started and exactly where it is.
Wiz helps to achieve zero criticals in its issue queues. Wiz reduces alert fatigue overall, but there is a learning curve; out of the box, it may increase noise if there isn't a proper architecture in place.
Wiz makes cloud security visibility clear for stakeholders, allowing them to understand risk posture, and does that really well. It creates a sense of ownership, as risk factors are presented, enabling anyone, including non-security and non-engineering teams, to use the tool if they are interested.
What is most valuable?
The biggest advantages of Wiz are that we can monitor multiple environments, as it has the capability to monitor multi-cloud models or architectures, providing visibility on a single page or tool. It also has AI integrations, so if you are finding a zero-day issue, you can calculate the risk score of that particular product and utilize that score to prioritize that particular CVE. If you are unsure about the resolution, Wiz also provides solutions and can craft custom PowerShell scripts to resolve a particular issue, all within the same tool, so you do not have to look elsewhere for solutions.
Wiz only provides visibility; if you want to take any actions, Wiz requires your consent to do it, so it does not automatically fix issues until you provide feedback.
We do have Wiz Code, but it is only for visibility, and we have not integrated it into our CI/CD pipelines yet, as it just gives us the library views and reports on DevOps content.
What needs improvement?
An area of improvement is that there is a lot of data inside Wiz and the naming is confusing, as similar categories for vulnerabilities and issues sometimes duplicate issues across resources, which can be hectic. While it doesn't cost much in terms of workloads, larger environments may incur higher costs based on architecture, and Wiz does not provide pre-configured reports but rather a dashboard requiring access to the tool.
For how long have I used the solution?
I am using Wiz for the last three years.
What do I think about the stability of the solution?
Wiz is stable; aside from the mentioned cons, there are no other issues from the tool's perspective, so it is about 99% stable.
What do I think about the scalability of the solution?
There is no issue with scalability; depending on architecture, you can scale Wiz anytime, as it has ready-to-deploy workloads utilizing cloud capabilities.
How are customer service and support?
Technical support is quite good; they help with configuration, cyber advisory, and provide support for any major changes needed.
Which solution did I use previously and why did I switch?
I have worked with Prisma, which is Palo Alto's CSPM, and Azure Cloud Security tools.
How was the initial setup?
Deployment for Wiz is not complex; various deployment types exist depending on the desired approach, primarily requiring keys and registrations to connect to environments, though installing workloads can be complicated.
What about the implementation team?
We are not using post-sales support, just the regular support for major configuration-related issues.
What was our ROI?
Wiz is worth the investment, and if everything is properly configured, it definitely offers value for money. I would say around 80% in ROI benefits. That is in terms of money and time; doing everything manually would take a lot of work and effort, and Wiz reduces both the workload and the need for manual thinking and human feedback.
What's my experience with pricing, setup cost, and licensing?
Wiz is fairly priced compared to competitors and fits well within a low budget. Wiz is less expensive than Microsoft and Palo Alto.
Which other solutions did I evaluate?
This particular integration of AI Security Posture Management is kind of new, introduced in one or two years, and for customers who have integrated their own LLMs or opted for special Azure or AWS Bedrock services, it is useful as it lets you know about security-related risks and provides visibility around AI-specific resources in the cloud, grouping risk factors, which helps present details in meetings.
The current AI integration makes Wiz good for those not using on-premises or other environments, but proprietary cloud tools like Azure or AWS excel in features and ease of deployment.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 27, 2026
Flag as inappropriateBuyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Cloud-Native Application Protection Platforms (CNAPP) Vulnerability Management Container Security Cloud Workload Protection Platforms (CWPP) Cloud Security Posture Management (CSPM) Data Security Posture Management (DSPM) Compliance Management Risk-Based Vulnerability Management Cloud Security Remediation Application Security Posture Management (ASPM) Cloud Detection and Response (CDR) Continuous Threat Exposure Management (CTEM) AI SecurityPopular Comparisons
Cloudflare
Datadog
Snyk
Qualys TotalCloud
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Darktrace
Checkmarx One
Prisma Cloud by Palo Alto Networks
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Varonis Platform
Veracode
Qualys Exposure Management
Tanium
TrendAI Vision One – Cloud Security
Buyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How would you compare Wiz vs Lacework?
- AWS Cloud Security Posture tool - has anyone used either Wiz or Ermetic cloud security products and can compare them to AWS Security Hub?
- Which tool is best for CNAPP: Wiz or Orca?
- How to minimize false positives for PII and PCI around different data systems across the globe?
- When evaluating Cloud-Native Application Protection Platforms (CNAPP), what aspect do you think is the most important to look for?
- Why is a CNAPP (Cloud-Native Application Protection Platform) important?
- What CNAPP solution do you recommend for a hybrid cloud?
- Why are Cloud-Native Application Protection Platforms (CNAPP) tools important for companies?
- When evaluating Cloud-Native Application Protection Platforms (CNAPP) solutions, what aspect do you think is the most important to look for?
- Why is Cloud-Native Application Protection Platforms (CNAPP) important for companies?





















