No more typing reviews! Try our Samantha, our new voice AI agent.
Navaneet Upadhyay - PeerSpot reviewer
Principal Solution Architect at ACPL Systems Pvt Ltd
Reseller
Top 10
Jan 28, 2026
Automates security workflows and improves visibility across hybrid environments
Pros and Cons
  • "Wiz is very effective and very advanced compared to other solutions."
  • "When integrating multiple clouds like hybrid cloud with Wiz, these processes need to be more user-friendly because more scripting is required in this scenario."

What is our primary use case?

I use Wiz to secure code to cloud posture. We are using Wiz and also positioning Wiz to my customers, especially to protect their code environment, runtime environment like DevOps environment, and other code-related vulnerabilities in an automated way. Automating security processes is particularly helpful. We also provide CSPM and CNAPP ability to the customers.

I have created custom dashboards with Wiz for code-to-cloud scenarios, different scenarios, and for our whole infrastructure which is monitored through Wiz.

Wiz is very helpful to achieve a zero critical scenario. Wherever possible, it gives good insights and there is an ability to automate with AI scenarios. Their powerful AI engines also recommend best solutions to apply to identified vulnerabilities and identified gaps related to coding scenarios especially. It also suggests the best way to patch vulnerabilities and other related issues. This is really helpful.

What is most valuable?

Wiz is very effective and very advanced compared to other solutions. It is helpful to use and user-friendly from the customer's view. It is easy to use, easy to handle, and easy to customize for our scenarios especially.

Pricing in comparison to other solutions is good, but a little bit of discounting and flexibility if Wiz can offer to customers would be helpful. Training, vouchers, and certifications would help position this solution in the market. If Wiz integrates their certifications free with their solution positioning in the market for customers especially, it would be helpful. In comparison to the Microsoft product, it is not as costly, but for other products in comparison to other available players, it is a little bit on the high side.

What needs improvement?

Wiz may try to ease the connector positions. When integrating multiple clouds like hybrid cloud with Wiz, these processes need to be more user-friendly because more scripting is required in this scenario. Without a coder or without a deep administrator managing things, it is not possible to integrate clouds with Wiz dashboards. Some easy steps are required so that users who are not highly technical can do these things.

For how long have I used the solution?

I have been using Wiz in my career for approximately one year.

Buyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.

What do I think about the stability of the solution?

I have not observed stability issues in my scenario, and my customers also have not reported any major crises.

What do I think about the scalability of the solution?

Wiz is very much scalable. It totally depends on the workloads which are working on cloud scenarios, either GCP or Azure or any cloud scenario. It totally depends on your workloads. In cloud scenarios, workloads are always scalable, so Wiz is also scalable and adopts these things easily. There is no challenge.

Which solution did I use previously and why did I switch?

I have used Microsoft CNAPP and CSPM functionality very frequently, and also used Palo Alto Prisma CNAPP and CWP functionality. I can compare them with these two OEMs.

Which other solutions did I evaluate?

Wiz is OEM agnostic. It is able to integrate any cloud, either GCP, Azure, or AWS. Similarly, like Palo Alto, Wiz is OEM agnostic. Microsoft is more specific to Azure where it is easy to integrate with Azure and it is a native platform. For other platforms, there may be some complications, like AWS with other GCP and other suites like Oracle OCI cloud. However, Wiz is OEM agnostic, so it is helpful to integrate and manage hybrid cloud scenarios efficiently.

Pricing in comparison to other solutions is good, but a little bit of discounting and flexibility if Wiz can offer to customers would be helpful. Training, vouchers, and certifications would help position this solution in the market. If Wiz integrates their certifications free with their solution positioning in the market for customers especially, it would be helpful. In comparison to the Microsoft product, it is not as costly, but for other products in comparison to other available players, it is a little bit on the high side.

What other advice do I have?

Maintenance is required from time to time, as patching is required. If there are any latest updates available, then we need to just patch those updates. Integrations need to be monitored to ensure there are no gaps in the integration part. If we monitor multiple hybrid clouds, we need to be there and monitor these things also.

We deployed Wiz, but not for our internal use. We are just demoing and practicing scenarios.

I would rate this review a 9 overall.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jan 28, 2026
Flag as inappropriate
PeerSpot user
Vivekkumar Jaiswal - PeerSpot reviewer
Senior Specialist at a tech vendor with 10,001+ employees
Real User
Top 5
Jun 30, 2026
Contextual risk insights have strengthened cloud threat detection and reduced incident response time
Pros and Cons
  • "Wiz has improved the overall security posture of our previous organization, National Australia Bank, by providing wide-cross visibility in terms of risk identification, alert creation, misconfiguration identification, vulnerability remediations, patching of security holes, and exposing details."
  • "There are various ways to improve Wiz, particularly focusing on posture prioritization and enhancing runtime detections while comparing to solutions like CrowdStrike or Defender which have more mature runtime capabilities and can work on stronger behavior-based detections."

What is our primary use case?

I used Wiz for more than 2.5 years while working for NAB, National Australia Bank, where they were using Wiz cloud security platform to enhance their detections for cloud-related threats.

We are using Wiz to enhance our security detections for automated risk detection and threat detection across the cloud network infrastructure while also utilizing it for automated risk remediations, the exposure of the attack, and the lifecycle path analysis.

We mainly use Wiz for cloud security identifications, cloud-related vulnerability platform, patching of the vulnerabilities, and new alerts and detections, which also provides visibility across multiple cloud environments.

What is most valuable?

The very best feature is Wiz's contextual graph relationships in terms of the security graphs, as it's basically the core engine.

It integrates with cloud-native platforms and cloud security, giving us insights into current vulnerabilities, misconfigurations, identity permissions, and network exposure while also providing a real-time attack path, isolating alerts quickly, and reducing exploitable risk.

There are a lot of features that I found personally very good, such as CSPM, which stands for Cloud Security Posture Management, identifying misconfigurations like open ports, public storage, and continuously monitoring those configurations.

Wiz has improved the overall security posture of our previous organization, National Australia Bank, by providing wide-cross visibility in terms of risk identification, alert creation, misconfiguration identification, vulnerability remediations, patching of security holes, and exposing details.

What needs improvement?

There are various ways to improve Wiz, particularly focusing on posture prioritization and enhancing runtime detections while comparing to solutions like CrowdStrike or Defender which have more mature runtime capabilities and can work on stronger behavior-based detections.

I noticed an initial spike in alert noise, with many alerts triggered, so there should be work on the fine-tuning of those alerts, potentially using AI for better alert separation to improve overall performance.

Wiz currently covers all AI workloads, but there are opportunities for improvement, particularly regarding LLM issues and data leakage.

For how long have I used the solution?

I have been working in cybersecurity for a total of nine years.

What do I think about the stability of the solution?

Wiz is stable.

What do I think about the scalability of the solution?

Wiz is highly scalable according to our requirements and can be deployed across the cloud infrastructure.

How are customer service and support?

The customer service is excellent and very supportive.

Which solution did I use previously and why did I switch?

We previously used Orca Security, which was good but lacked integration capabilities with cloud environments and globally deployed threats, which is why we switched to Wiz.

How was the initial setup?

We purchased Wiz through the AWS Marketplace.

What was our ROI?

The ROI is 80%. I believe the total efforts and time needed have been reduced by 80%.

Which other solutions did I evaluate?

We evaluated CrowdStrike Falcon as another option.

What other advice do I have?

I would rate Wiz a 10 because the platform has quickly grown in the market and offers great alerting features as it captures the needs of different enterprises effectively.

Most of the big companies are utilizing Wiz's security platform due to its design, which effectively identifies risks, alerts users to threats or vulnerabilities, and provides actionable insights.

Wiz has positively affected our team's efficiency.

It has affected our operations to a great extent, as Wiz quickly identifies true positive incidents, active threats, and ongoing threats, allowing the security team to act swiftly.

Wiz effectively helps in identifying critical issues within a timeframe, facilitating the detection of those issues.

It has positively impacted the overall security posture by allowing comprehensive data reliability, identification, and alert configuration in a single view.

Wiz is very important because it uses an AI security platform that provides end-to-end security management.

We initially did not see employee reductions, but after fine-tuning, there was a significant decrease in total staff required and time spent on vulnerabilities.

Organizations should opt for this newly launched solution for threat identification in cloud infrastructure. I have given this product an overall rating of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 30, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.
Sonaansha Aneja - PeerSpot reviewer
Cybersecurity Executive at Gigabit Technologies Pvt Ltd
Real User
Top 5Leaderboard
Sep 11, 2026
Centralized cloud risk visibility has transformed how our team prioritizes and remediates issues
Pros and Cons
  • "Overall, Wiz has a positive impact on our organization by improving our visibility into the cloud environment and making it easier to identify and prioritize security risks."
  • "One area I would like to see improved is the user experience around complex findings, as having more contextual guidance on why an issue is important and the recommended remediation steps would make it easier for newer team members to act on findings."

What is our primary use case?

I have been using Wiz for around six months. My main use case for Wiz is cloud security visibility and risk management, as I use it to identify misconfigurations, vulnerabilities, and potentially security risks across a cloud environment. Having this information in one place makes it easier for the security team to prioritize issues and focus on the risks that need attention first.

An example of how my team uses Wiz for risk management or visibility is identifying a cloud resource with a security misconfiguration and prioritizing it based on the associated risk. Instead of manually checking every resource, the team can quickly see the issue, understand its potential impact, and route it to the right team for remediation, making the review process much more efficient.

I also use Wiz as a central point for getting an overall view of the cloud security posture. It helps us bring different security findings together, prioritize the important risks, and give us a clear picture of where attention is needed. The centralized visibility is probably the biggest benefit for all of us.

Wiz is primarily used in our public cloud environment, having integrated with a cloud account so the team can get centralized visibility into configurations, vulnerabilities, and security risks across the environment without managing separate tools for each account.

Wiz has helped us consolidate some of our cloud security workflows into a single platform, making it easier to prioritize critical risks because we can see the related findings and context together instead of switching between multiple tools. It reduces the noise and helps the team focus on issues that have the greatest potential impact.

The runtime sensor has improved our visibility into active threats by providing more context around what is happening in the environment, making it easier to distinguish active threats from lower findings and focus the team's attention on threats that require immediate investigation compared to previous solutions.

What is most valuable?

The best features Wiz offers include centralized cloud visibility, risk prioritization, and the identification of misconfigurations and vulnerabilities. I also appreciate how Wiz connects different findings and provides context around the potential impact, making it easier to focus on the issues that actually matter instead of treating every alert the same way.

The feature that has made the biggest difference for our team is centralized cloud visibility, as it gives us a much clearer view of our overall security posture and helps us quickly identify which sources have the highest priority risks. This saves time compared to manually referring to different cloud environments and security findings separately.

I appreciate that the features work together rather than operating as completely separate tools, as the combination of visibility, risk context, and prioritization makes it easier for the team to understand what needs attention first. It keeps the security workflow relatively simple while still providing a good level of detail.

Overall, Wiz has a positive impact on our organization by improving our visibility into the cloud environment and making it easier to identify and prioritize security risks. The centralized view has also helped the team spend less time manually viewing findings and focus more on addressing the issues that have the greatest potential impact.

What needs improvement?

Wiz is already quite strong, but the platform could be made even easier for new users with more guided workflows and simpler explanations of some of the more advanced findings. I would also like to see further improvements in reporting and customization so the team can tailor dashboards and reports more closely to their specific needs.

One area I would like to see improved is the user experience around complex findings, as having more contextual guidance on why an issue is important and the recommended remediation steps would make it easier for newer team members to act on findings. More flexible reporting and dashboard options would also be useful.

What do I think about the stability of the solution?

Overall, I have found Wiz to be stable and reliable in day-to-day use, consistently providing visibility across our cloud environment without experiencing major stability issues. The platform has been dependable for monitoring security posture and keeping track of risks over time.

What do I think about the scalability of the solution?

I rate Wiz's scalability quite positively, as it works well as the cloud environment grows and makes it possible to maintain visibility across multiple accounts and resources from a centralized platform, making it easier for the security team to scale monitoring and risk management without significantly increasing the manual effort.

How are customer service and support?

Overall, I have had a positive experience with Wiz customer support, as the team has been responsive when I needed help with configuration or understanding specific findings. Their guidance has helped me resolve questions faster, although the response time on more complex issues could sometimes be improved.

Which solution did I use previously and why did I switch?

I previously used CrowdStrike as a cloud security solution, but I was not finding it working according to my needs, so I needed to switch. I chose Wiz, which has been more efficient and has been working very well.

How was the initial setup?

My experience with pricing, setup cost, and licensing for Wiz has been fairly straightforward, as the setup was relatively smooth once the cloud environment and integrations were configured. The licensing model was easy for me to understand, with the overall cost feeling reasonable considering the visibility and security coverage Wiz provides across the cloud environments.

What was our ROI?

While I have not calculated a formal ROI with specific financial figures, the overall impact of Wiz has been positive, as it saves time by bringing cloud security findings and context into one place and reduces manual investigation and prioritization. It also helps the existing team work more efficiently without needing additional resources just to manage cloud security visibility.

Which other solutions did I evaluate?

I evaluated a few other cloud security platforms before choosing Wiz, mainly comparing them on cloud visibility, risk prioritization, ease of deployment, integrations, and overall usability. Wiz stood out because it provided a more centralized view of our cloud environment and made it easier to understand and prioritize the risks I was seeing.

What other advice do I have?

While I have not formally measured the impact with specific numbers, the time savings from using Wiz are noticeable, as it reduces the amount of manual effort needed to view cloud resources and prioritize findings. The team can get context around the risks much faster, helping us respond to important issues most efficiently.

Wiz has reduced alert fatigue for the team, mainly by providing better context and helping prioritize the findings that matter most. While I have not formally measured the reduction over a specific period, the team spends noticeably less time sorting through low findings and can focus more quickly on critical risks.

I use Wiz post-sale support services when needed, which have been helpful for resolving configuration questions and getting guidance on more complex security findings. Having that support available helps our team troubleshoot issues faster, using the time I could otherwise spend figuring out certain problems on my own.

Wiz has helped us reduce and prioritize critical issues, although we have not consistently reached zero criticals in the issue queue. Its prioritization and contextual information make it easier to identify the most important issues and get them assigned for remediation, which has improved our overall response process.

I recommend Wiz to organizations looking for better visibility and centralized management for cloud security risks, advising that they clearly define their cloud accounts and security priorities before deploying it. The platform can surface a lot of information, so taking time to understand its prioritization features will help the team get the most value from it. I rate this product nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 11, 2026
Flag as inappropriate
PeerSpot user
Vikram Chakravarthy - PeerSpot reviewer
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
Real User
Top 5Leaderboard
May 26, 2026
Contextual risk insights have transformed how our teams prioritize and remediate cloud exposures
Pros and Cons
  • "The biggest impact Wiz has had on our organization is improved visibility and better prioritization, as previously mentioned."
  • "One important area for improvement in Wiz could be customization and reporting flexibility."

What is our primary use case?

Wiz is primarily used to identify risks, assert exposed workloads, identify publicly exposed resources, and prioritize vulnerabilities in our cloud environment. The main use case for Wiz revolves around cloud security posture visibility, risk prioritization, vulnerability exposure management, misconfiguration detection, and identifying toxic combinations of risks in our cloud environments.

Our main use case for Wiz is contextual prioritization. In many environments, there are thousands or millions of vulnerabilities, but not all are equally important. Wiz helps reduce noise by enabling security teams to focus on exploitable and high-impact risks first.

What is most valuable?

One of the best features of Wiz, in my opinion, is risk prioritization and the context for visibility. Another major strength is its cloud posture visibility across environments, supporting multiple cloud environments. The attack path visualization and ability to correlate vulnerabilities, exposure, identities, and permissions into a single risk view are very helpful for our security teams.

In our day-to-day work, the contextual prioritization feature reduces our investigation effort because analysts do not need to perform manual correlations related to vulnerabilities, exposure, or cloud asset permissions. Instead of reviewing thousands of alerts individually, the team can focus on high-priority risks where exposure and business impact are clearer. Another useful aspect is visibility across multi-cloud environments and the centralized posture management, which helps our team understand risk in one place instead of depending on fragmented visibility.

Wiz helps us by identifying a publicly exposed cloud asset with critical vulnerabilities and permission-related risks. Instead of reviewing findings separately, Wiz provides contextual visibility that shows which issues were internet exposed, whether they had vulnerabilities, and the high risks from a business perspective, which accelerates our prioritization remediation instead of treating every vulnerability equally.

Wiz improves efficiency because remediation teams receive more context about why something matters. Instead of only seeing a vulnerability, teams can understand the exposure, permissions, affected assets, and the business relevance. The biggest impact Wiz has had on our organization is improved visibility and better prioritization, as previously mentioned. The security teams in our environment are able to focus on meaningful cloud risks faster rather than spending too much time manually reviewing low-priority findings.

Wiz allows us to consolidate tools, meaning we can use a single tool for vulnerability management, risk analysis, and threat management, which the SOC team utilizes. It is a flexible tool, enabling every team to use Wiz to detect and defend their organizational posture. On the consolidation aspect, Wiz integrates multiple tools; for example, we have integrated Microsoft Teams and ServiceNow, allowing us to create tickets directly using a single tool and send notifications via Teams or Slack.

Wiz's runtime sensor provides visibility across multiple cloud environments, including AWS, Azure, GCP, and Oracle. It helps us prioritize vulnerabilities by discovering newly identified assets or vulnerabilities and has different signatures and policies compared to other CSPM tools, which proves to be very helpful.

What needs improvement?

One important area for improvement in Wiz could be customization and reporting flexibility. Sometimes organizations want deeper tailoring based on their internal workflows and governance requirements. If we can have customization for reports and dashboards, it will be helpful.

Reporting and dashboard customization can improve further, especially for leadership reporting that can be highly customized to meet specific workflows.

For how long have I used the solution?

I have been working in cybersecurity, particularly on vulnerability management-related tasks for around six years.

What do I think about the stability of the solution?

Wiz has been stable for cloud visibility and posture monitoring activities.

What do I think about the scalability of the solution?

Wiz scales well for our enterprise cloud environment and growing workloads because visibility requirements increase significantly in a cloud-first environment.

How are customer service and support?

The customer support experience typically depends on the complexity of the issues. When we raise a ticket with the support team, the deployment is handled well, and the support is generally good.

Which solution did I use previously and why did I switch?

We have used McAfee MVISION in the past. As we expanded our cloud, we switched to Wiz because it offers more visibility for our fragmented security approach.

What was our ROI?

We see a return on investment primarily from improved prioritization and reduced investigation effort. Instead of spending time on thousands of findings, teams can focus on the highest risk exposures, which improves remediation efficiency.

Which other solutions did I evaluate?

We compared Wiz with other CNAPP and CSPM solutions based on visibility, prioritization, cloud integration, and operational simplicity.

What other advice do I have?

My advice for others looking to use Wiz is to first understand their cloud visibility gaps. If an organization struggles with prioritization, cloud posture visibility, or encounters too many findings with little context, Wiz can provide strong value in addressing those issues. I rate this product 9 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 26, 2026
Flag as inappropriate
PeerSpot user
Senior Cloud Architect at Commonwealth Bank of Australia
Real User
Top 20
Mar 30, 2026
Security scanning has consolidated cloud vulnerabilities and provides clear remediation paths
Pros and Cons
  • "Wiz gives a very good insight into how secure your software and code are and is quite good at consolidating the scanning results."
  • "Wiz is agentless, which is a plus, but the runtime and real-time detection could be limited, as it is not its strength."

What is our primary use case?

As a customer, I use Wiz myself, but because I work for the Commonwealth Bank, it could be a partner with Wiz. I don't have insight into this tool as it is a very large organization and was already in place before I joined, with other people having set it up, so I don't have that background.

So far, I am scanning for vulnerabilities in packages and dependencies. I use Wiz Code a bit.

What is most valuable?

What I like most about Wiz is that it is similar to other tools. Wiz has integrated with industry standards, such as security protocols and policies like Open OWASP and several others, based on my security standards for scanning packages, finding vulnerabilities, and providing fix versions based on its search and information retrieval.

I think it is at a good price and gives analysis while working well with other testing or pen testing tools that other security teams use to scan software to ensure it aligns with security requirements. Wiz helps because other tools, based on what they detect, usually reflect those fixes or remediations in other tools as well. Wiz gives a very good insight into how secure your software and code are.

Wiz is quite good at consolidating the scanning results.

What needs improvement?

Wiz is agentless, which is a plus, but the runtime and real-time detection could be limited, as it is not its strength. I could not give details on how limited it is. Its price could be high compared to others, and I feel it is expensive.

For how long have I used the solution?

I have been using Wiz for one and a half years.

What do I think about the stability of the solution?

I would give stability a nine because I did not see significant instability.

What do I think about the scalability of the solution?

I feel scalability is good, and I can give it a nine. We have many pipelines running Wiz scanning, and I have not seen Wiz pending or taking too long, which is a good thing.

How are customer service and support?

I rate support from Wiz an eight.

How was the initial setup?

Regarding installation, I just joined and used it, which might not be my area to comment on whether it is easy or difficult.

What was our ROI?

I see possible ROI with Wiz, but as I mentioned, I am not at that level of use. I just researched Wiz prices, and I got a feeling about it.

Which other solutions did I evaluate?

I do not have in-depth knowledge to give a detailed pros and cons analysis of Wiz compared to products such as OWASP, SonarQube, or Snyk. However, when comparing Wiz to Dynatrace or Snyk, I see they focus on different areas. Dynatrace focuses on code quality scanning, and Snyk may have more focus on security. Wiz scans artifacts or dependency packages, which is a bit different from SonarQube, as SonarQube scans code. However, Wiz is able to scan code and also manage the artifactory, dependencies, and their versions. This is quite similar to JFrog X-ray scanning.

What other advice do I have?

Wiz Code impacts the development workflow similar to SonarQube. Wiz Code can detect coding quality issues or coding conventions and those kinds of problems. Nowadays, we leverage AI tools for development. As a developer, I probably use AI for initial code, and in most cases, I just review and integrate, with the AI generating code programming. Wiz Code or SonarQube scans those codes and then gives a report. If we instruct the AI or do proper prompting, they usually give very good code that can pass the scanning.

AI security is definitely very important for our security strategy.

AI security posture management is important because if you use an AI tool, you need to protect your data. As a commercial company or even a government organization, you do not want to leak sensitive data such as PII or other organization-related data to the AI, especially in uncontrolled environments. When we use AI tools at the Commonwealth Bank itself, we are only allowed to use internal AI, which means it has many regulations in place, including guardrails, and the deployment environment looks at both input and output, ensuring that data does not go to the internet. This protects organization-level data and filters unnecessary inputs and outputs.

For Wiz Runtime Sensor, I am not quite familiar with it, but I know that this tool is meant to find dynamic analysis at runtime. I probably have little practice with another tool called OWASP ZAP.

I think the alert fatigue from Wiz is quite similar at the same level as the other scanning tools. If it detects any critical or high vulnerabilities, it alerts you. You can set up alerts based on your standards or rules to send alerts. With alerts based on findings, it allows you to set alerts on multiple domains such as vulnerabilities. For example, you might have critical CVEs on an EC2 instance and send an alert. It could also be scanning identity risks and possibly security exposures such as secrets exposure. Wiz covers a lot, including data exposure and attack paths. In alerting, it gives very clear information such as severity, affected resources, risks, and possibly an attack path description explaining how an attacker might use that vulnerability. Wiz includes such information based on severity, affected resources, attack paths, risk descriptions, and possibly remediation guidance.

If I summarize everything about Wiz, it deserves an eight in general.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 30, 2026
Flag as inappropriate
PeerSpot user
reviewer2860287 - PeerSpot reviewer
Senior Cloud Security Engineer at a wholesaler/distributor with 201-500 employees
Real User
Top 20
Jun 22, 2026
Comprehensive cloud security has improved visibility and enabled precise threat response
Pros and Cons
  • "Wiz has positively impacted my organization by stopping security incidents, giving us full visibility in our cloud environments, and providing us with the confidence that we can use the tool not just for security but also for operations tooling, DevOps, code scanning, and all of the above."
  • "Wiz's pricing model is very poor."

What is our primary use case?

My main use case for Wiz is cloud security, infrastructure as code, threat detection and response, and application security.

For example, if we have a cloud resource that has an Amazon GuardDuty alert, we will use Wiz to ingest the log, and we review it for security reasons and use that information in our alerting pipeline. Wiz is where we ingest all the information and logs.

My main use case is to scan cloud infrastructure for misconfigurations, issues, security threat intelligence, and more.

What is most valuable?

The best features Wiz offers include the scanning, the ability to map vulnerabilities to specific resources, the ability for GraphQL API integration, and their security graph when it comes to querying information, finding specific detections, and responding to them, and much more.

For example, we use many other automation tools that need to integrate with Wiz, and through the graph API or GraphQL API, we are able to call Wiz in a very specific way where if we want to automate anything, it is possible via their API.

There is a variety of features per team, such as cloud security, AI security, security operations center, and more.

Wiz has positively impacted my organization by stopping security incidents, giving us full visibility in our cloud environments, and providing us with the confidence that we can use the tool not just for security but also for operations tooling, DevOps, code scanning, and all of the above.

We have seen specific outcomes and information improve as a result, and we have definitely narrowed down more incidents that we might need to take care of with the tooling, which has given us wider visibility compared to when we did not have it.

Wiz allowed us to consolidate tools, and on the issues it gives us from the top level down—critical to informational—we are able to fully prioritize the things that are most important due to that capability.

What needs improvement?

Wiz's pricing model is very poor.

The pricing is out of control, but when it comes to the actual functionality of the tool, the tool is great.

On a scale of one to ten, I would rate Wiz an eight. I rate it an eight because internally, they have specific people who want to bulldoze you when it comes to signing agreements that are much higher priced than the value that you get. Wiz is great. Some people are great and some are not, so they are a little bit less willing to work with customers on their specific needs regarding things such as pricing versus other tools.

For how long have I used the solution?

I have been using Wiz for over four years.

What do I think about the stability of the solution?

Wiz is stable.

What do I think about the scalability of the solution?

Wiz's scalability is very good, and I have not had any issues yet.

How are customer service and support?

The customer support is fair; they are not great, nor bad.

Which solution did I use previously and why did I switch?

We started to use Wiz since their inception.

How was the initial setup?

Everything is very well set up; the UI is easy to use, and their API is great.

What about the implementation team?

We are just a customer without a business relationship with this vendor other than that.

What was our ROI?

I have definitely saved time, but money saved is still up in the air; there have been things that make us feel that is not the case. We also need fewer employees, partially.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing has been very poor.

Which other solutions did I evaluate?

Before choosing Wiz, I evaluated other options such as Orca and Upwind.

What other advice do I have?

The extent to which the Wiz runtime sensor has helped in identifying active threats more effectively compared to previous solutions is pretty minimal.

My impression of the cloud security democratization aspect of the product is that it is one of the best sources of truth we have. It is extremely impactful on the organization, so it is definitely a tool we are going to use if the pricing is right.

We have gone through three technical account managers and have decided not to renew.

My advice to others looking into using Wiz is to make sure that you are working with the right account team, set up all of your integrations correctly, and take your time during your proof of value.

Wiz is a great tool, and we will continue to use it over time. I rate Wiz an eight out of ten overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 22, 2026
Flag as inappropriate
PeerSpot user
Pratik Vandariya - PeerSpot reviewer
Sr. Technical Lead Support Executive at Jekson Vision
Real User
Top 20
Nov 7, 2025
Has increased inventory visibility and significantly reduced operational mistakes through improved threat identification
Pros and Cons
  • "The best features of Wiz are its security capabilities, providing the best security for pharmaceutical products and industries, along with the required dashboard containing customer details and inventory management features."
  • "There is room for improvement in Wiz, particularly in operator management, as general operators may lack the necessary knowledge, requiring an easier-to-understand tool."

What is our primary use case?

I'm working with Jackson Vision, the track and trace provider, and we have been using Wiz for six years. We use Wiz as a portal similar to an ERP tool, managing customer inventory for security purposes and vulnerability management.

What is most valuable?

The best features of Wiz are its security capabilities, providing the best security for pharmaceutical products and industries, along with the required dashboard containing customer details and inventory management features.

The runtime sensor in Wiz helps identify threats effectively as it integrates with machines and operates on a hierarchy-based system with different rights for operators and supervisors.

The benefits of using Wiz are significant as we provide a solution based on 21 CFR standards for security and audit purposes, making it the best tool for these needs.

With Wiz, we achieve almost zero downtime and zero fault management in its issue queues.

Using Wiz saves us a significant amount of time and resources, with an almost thirty to forty percent return on investment.

Wiz has significantly reduced alert fatigue in our organization, addressing operator-level mistakes that used to be common in manual processes before we adopted automation.

Wiz has been the best tool for consolidating our solutions.

What needs improvement?

There is room for improvement in Wiz, particularly in operator management, as general operators may lack the necessary knowledge, requiring an easier-to-understand tool. We also need all tasks and dashboards to show completed activities and next steps along with SOPs for missed steps.

For how long have I used the solution?

I'm working with Jackson Vision, the track and trace provider, and we have been using Wiz for six years.

What do I think about the stability of the solution?

I rate the stability of Wiz as almost eight out of ten, indicating good performance with limited downtime, bugs, or glitches.

What do I think about the scalability of the solution?

Wiz is a very scalable product, as we operate in sixty-five countries and serve the pharmaceutical industry well, rating it eight out of ten for scalability.

How are customer service and support?

I rate the technical support of Wiz as eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We are not currently comparing Wiz with other solutions as we have our research team looking for the best solutions available.

How was the initial setup?

The deployment of Wiz is easy.

What about the implementation team?

Deployment takes almost three to four hours, and our IT teams facilitate this process. We have around two hundred fifty to two hundred eighty customers who work with Wiz, and our team and IT teams are knowledgeable about it.

What was our ROI?

Using Wiz saves us a significant amount of time and resources, with an almost thirty to forty percent return on investment.

What's my experience with pricing, setup cost, and licensing?

The pricing of Wiz is cost efficient.

Which other solutions did I evaluate?

I find Wiz to be better compared to other software, and we are currently progressing, rating it seven out of ten against any master product or company.

What other advice do I have?

I have experience with Wiz and can provide a review. We are manufacturers of pharmaceutical machines and provide integrated solutions for track and trace, but we are not partners or resellers.

Wiz requires maintenance including patching and updates; if we encounter issues on-site, we update accordingly.

We purchased Wiz from the AWS marketplace, and many of our customers are utilizing the cloud-based solution we provide them, along with the portal that includes all necessary details for them.

We recommend Wiz to other users, such as Life Pharma in Dubai. I rate this product a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
DevOps / Cloud R&D Team at Sri Cloud Solutions
Real User
Top 20
May 29, 2026
Automated cloud scans have improved threat detection and streamline forensic investigations
Pros and Cons
  • "Using Wiz Code has been a worthy investment, as manually checking all 100 AWS accounts for issues would take an immense amount of time, but Wiz Code allows us to scan all accounts within minutes and continuously monitors our cloud environment every 24 hours, displaying any changes in the Wiz Code UI under the issues and threats section."
  • "Wiz Code has many features, and I think they could continue to enhance customization according to our requirements."

What is our primary use case?

My main use case for Wiz Code is to detect vulnerabilities, findings, and issues in our cloud environment. It detects our AWS account, Azure, and GCP as well, scanning all our cloud accounts and detecting misconfigurations. Based on severity—high, low, medium—we find those issues and solve them accordingly, identifying the root cause of those things.

In our cloud environment, we have detected issues with ECS services, where our main part is to develop code and policies. One thing we noticed in the ECS service was that a role had high permissions, meaning it had more than necessary access. We solved that issue by remediating it and sharing our information with the cloud team.

As part of these past six months, I have concentrated on my contribution to the team, focusing on Wiz Code policies and concurrently working on the forensics feature in Wiz Code. For the forensics feature, we create a cross-account IAM role. If we have 100 AWS accounts, there are many issues found at the snapshot level and in EC2 instances. Wiz Code has a feature called Wiz forensics, which copies the EC2 volumes from the source account to the forensic account, allowing us to investigate all the findings. To do this, we need to create a cross-account IAM role and think about following the least privilege policy. Recently, I worked on the Wiz Code forensics feature.

What is most valuable?

Wiz Code offers many benefits. It is a cloud security tool that is essential nowadays, helping significantly in my day-to-day activities. It detects misconfigurations and shows them in the Wiz Code UI, and it also provides features such as dashboards and widgets, allowing us to create customized dashboards for our requirements and set alerts as needed.

I have customized the dashboards. Recently, I'm doing some research and development on Wiz Code dashboards and reviewing videos on creating them.

Wiz Code has made things easier because whenever we write any cloud configuration rule, it detects issues across all AWS accounts. For example, if an employee creates an S3 bucket in public mode when it should be private, Wiz Code has a feature called Cloud Matcher in a cloud configuration rule that catches this misconfiguration. It provides details such as the account name, the S3 bucket name, when the issue was issued, and the IAM user involved, all of which are shown in the Wiz Code UI under the issues section.

Using Wiz Code has led to significant measurable improvements for our organization. For example, the graph controls feature allows us to create a security query that detects misconfigurations and indicates the stage at which issues occur. This feature shows everything end-to-end in a security graph, identifying what is affected and the root cause of the issue.

What needs improvement?

Wiz Code has many features, and I think they could continue to enhance customization according to our requirements.

For how long have I used the solution?

I have been using Wiz Code for the past six to eight months.

What do I think about the stability of the solution?

Wiz Code is stable, and we can customize it according to our requirements.

What do I think about the scalability of the solution?

For scalability, we can adapt Wiz Code based on our specific needs.

How are customer service and support?

The customer support is good. Whenever we encounter any blockers or require information or permission issues in Wiz Code, they promptly address our tickets.

Which solution did I use previously and why did I switch?

I did not use any other solution before Wiz Code. Previously, I was involved in another project that was a DevOps project.

How was the initial setup?

I have used the AWS cloud provider with cloud connectors to connect our cloud with Wiz Code. Specific roles and permissions are needed to deploy the Wiz Code scanner role, and these roles are created in both our environment and the Wiz Code AWS account for integration.

What about the implementation team?

There is a business relationship with the vendor, as there is a bond from our organization according to information I heard from my teammates.

What was our ROI?

Using Wiz Code has been a worthy investment. Manually checking all 100 AWS accounts for issues would take an immense amount of time, but Wiz Code allows us to scan all accounts within minutes and continuously monitors our cloud environment every 24 hours, displaying any changes in the Wiz Code UI under the issues and threats section.

What's my experience with pricing, setup cost, and licensing?

I don't have any idea about the licensing and pricing specifics as I believe that is handled in the backend, but I suspect that acquiring a Wiz Code tenant subscription involves significant cost.

Which other solutions did I evaluate?

I did not evaluate other options before choosing Wiz Code, as I was switching to another project that used Wiz Code. I wanted to explore learning new skills in this field.

What other advice do I have?

There is a business relationship with the vendor, as there is a bond from our organization according to information I heard from my teammates.

Wiz Code significantly aids in my day-to-day activities. I would rate this product eight out of ten, and I don't have any further additional thoughts on this session.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 29, 2026
Flag as inappropriate
PeerSpot user
reviewer2618736 - PeerSpot reviewer
Security Manager at a consultancy with 10,001+ employees
Real User
Top 20
Jan 4, 2026
Continuous code security has reduced vulnerabilities and provides real-time risk visibility
Pros and Cons
  • "The best features with Wiz Code give you a reasonable picture when it comes to vulnerabilities, which means you see the usual severity levels, you also get to see references on how to remediate vulnerabilities, and the fact that it has a visual dashboard helps all stakeholders, especially folks who need to remediate, to get that picture correctly and then take action."
  • "I have a big improvement in mind for Wiz Code, not a small improvement."

What is our primary use case?

Folks deploying infrastructure with Terraform code need to verify that those deployments do not have vulnerability concerns, and if they do, they need to be remediated, which is the main use case for Wiz Code.

What is most valuable?

The best features with Wiz Code give you a reasonable picture when it comes to vulnerabilities, which means you see the usual severity levels. You also get to see references on how to remediate vulnerabilities. The fact that it has a visual dashboard helps all stakeholders, especially folks who need to remediate, to get that picture correctly and then take action. You know exactly how to track SLAs, which is another great feature. Those features make the tool useful for most people.

It has been quite easy to get visibility into the vulnerabilities and what steps need to be taken. The fact that you get something in real-time means you can plan to either remediate in real-time or put that as an action to remediate. Overall, Wiz Code improves your workflow efficiency to more than average.

What needs improvement?

I have a big improvement in mind for Wiz Code, not a small improvement. When I look at tools such as vulnerability detection tools, I focus on how the reporting could help fast-track risk mitigations. I don't want folks to just look at the severity rating, whether it's critical, high, or medium. I would love to see how that presents a risk. Meaning that if a particular vulnerability is compromised, it could be a low severity, but if it's compromised, what business impact does it have? With capabilities we have in AI and other technologies, I think we could do much more than just sharing vulnerability ratings or severity ratings for folks to act on. That approach is outdated. Something that communicates the value would make sense and could help drive or change habits. That's what I'm thinking, and that's why I say it's a big one, not just something small.

For how long have I used the solution?

I have used Wiz Code for about three years now.

What do I think about the stability of the solution?

Wiz Code is reasonably cool in terms of stability overall.

What do I think about the scalability of the solution?

Wiz Code is scalable.

How are customer service and support?

The support from Wiz Code is incredible. I don't give anyone a 10 in the first place, frankly, but I think a nine will look good. Wiz has done incredibly well. They've set up regular connects with the team, they share new updates, and they want to get feedback in terms of what we think could be done differently. Those sessions actually help. If you need them to jump on a call to resolve an issue, they are always available. That's why I give them a nine.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I did use other solutions before choosing Wiz Code for this, specifically InsightVM. InsightVM has some capabilities I've used in the past as well. However, I wouldn't say I've used InsightVM the way I currently use Wiz Code. I can't really judge or compare the difference between the two. I'm sure InsightVM or Rapid7 has improved on its offerings since when I used it.

Which other solutions did I evaluate?

The metric regarding automated code reviews is something I have not captured, but it's a good metric.

What other advice do I have?

I do use Wiz Code's real-time code tracking.

From my perspective, I think it's positive, but for folks who need to remediate and have old habits when it comes to software development, it might be a big concern. Ultimately, it helps everyone because you have that visibility and you can take action within a sprint because of that visibility. If you can act right away, you can capture that as part of your sprint planning and remediate promptly. It's a good feature. However, I speak from a security perspective. For a product team, it could be a lot to handle. With creating the right habits over time, it becomes an advantage for everyone.

I have never had to think about Wiz Code's error detection feature for improving code quality.

I do not use the analytics tools within Wiz Code. I may know this tool by a different term, but I need clarification on what the analytics tool encompasses.

I have no idea of the pricing for Wiz Code. I have no knowledge of current pricing.

To rate Wiz Code, I need to think of some baseline, but I don't really have any baseline. When I consider the support they offer, which is fantastic, and how reliable the tool is, I could give them a rating of eight.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cybersecurity Analyst at Digitaltrack
Real User
Top 5
Jul 28, 2026
Cloud security has improved as I manage multi-cloud risks and streamline compliance audits
Pros and Cons
  • "Wiz has impacted our organization very positively because it includes various advanced features such as compliance audits, continuous security monitoring, and vulnerability management, along with cloud assistance and DevSecOps integration."
  • "I feel there is a bit of noise in the initial setup and quality cleaning that may take time in larger environments."

What is our primary use case?

I have been using Wiz for approximately three to four weeks, and I find that Wiz is an amazing cloud security platform that helps the organization identify, prioritize, and remediate security issues across cloud environments such as AWS, Azure, and various types of clouds, Kubernetes, and containers.

My main use cases for Wiz include cloud security posture management, or CSPM, because admins continuously monitor the cloud environment for misconfigurations and if any misconfiguration is found, Wiz will correct them. Additionally, there is the Vulnerability Management feature because it prioritizes vulnerabilities based on real-world risks and exploitability, also identifying vulnerabilities that could impact real-world risk within organizations. The Identity security feature also detects excessive permissions and identifies related risk, along with Kubernetes security which scans the Kubernetes clusters and workloads. These are my use cases of Wiz in my role.

We use Wiz in a cloud risk assessment because we scan client cloud environments to identify exposed resources and misconfigurations, generate security assessment reports, and perform vulnerability management and compliance audits which validate adherence to industry frameworks and produce audit-related reports for customers. This eases their workload, and it is also used for incident response to investigate attack paths, identify compromised resources, and reduce investigation time with centralized visibility. These are my use cases in my work.

What is most valuable?

The best feature of Wiz is its multi-cloud support which encompasses AWS, Microsoft Azure, Google Cloud Platform, and Kubernetes. This multi-cloud support is one of the main features that stands out, along with path analysis that matches how attackers could navigate through the environment.

Wiz has impacted our organization very positively because it includes various advanced features such as compliance audits, continuous security monitoring, and vulnerability management, along with cloud assistance and DevSecOps integration. All these features empower Wiz, significantly aiding our organization's growth.

I have seen major changes since implementing Wiz because it greatly enhances visibility into our cloud infrastructure; the onboarding became simpler and the dashboard provides clear insights into vulnerabilities, misconfigurations, and attack paths, contributing positively to our organization's security and growth.

Wiz provides governance as it implements all necessary policies correctly, validating compliance with industry frameworks rather than just standard frameworks. It adheres to frameworks created by the CB or RBAC which gets validated here, providing Audit Ready Reports for customers; this is an excellent point for both customers and co-owners.

The accuracy and reliability of Wiz are impressive; all the inputs fit perfectly with no extra adjustments needed. Reliability exists in various features, especially when creating policies, allowing us to execute incident response tasks effectively; hence, accuracy and reliability are strong components of Wiz.

Wiz's Runtime Sensor integrates seamlessly with DevSecOps, providing CI/CD pipelines and integrating with various tools and use cases, helping to effectively identify actively running threats, making it a strong solution compared to previous ones.

Wiz has great scalability; I find it one of its strong features, helping organizations grow due to its capabilities.

What needs improvement?

I believe a little more documentation could help users follow step by step. That is the extent of the improvements needed.

I feel there is a bit of noise in the initial setup and quality cleaning that may take time in larger environments. Additionally, advanced features might require security expertise; hence, improvements in documentation would be beneficial. Otherwise, all aspects are very good and easy to use.

For how long have I used the solution?

I have been using Wiz for approximately three to four weeks.

How are customer service and support?

Customer support is good; whenever we need assistance, the business support team is readily available to help us. It is reassuring to know we can rely on good customer support.

What other advice do I have?

All of the ways I use Wiz are amazing, as it can be used anywhere it is suitable, and it is especially great for large organizations.

I find myself relying most on multi-cloud support because it is very useful, especially since we do not have a single cloud but rather use different clouds such as AWS, Azure, and Google Cloud Platform along with Kubernetes. Wiz allows us to coordinate efficiently across these different teams and groups, which is why our organization relies heavily on this feature.

Wiz does not allow for tool consolidation in our environment; even though it has features for that, there is not a need to consolidate different tools because it functions very well with existing tools in our organization.

We have reduced alert fatigue in our organization due to Wiz's accuracy in managing alerts. I can approximate a reduction of approximately three to four hours in alert handling since Wiz provides alerts with minimal latency between the alerts and real-time notifications.

I advise others to choose Wiz because it stands out as an awesome tool that offers various benefits to organizations, and trying Wiz will undoubtedly benefit you. I have given this product a review rating of 9.5 out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 28, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros sharing their opinions.