What is our primary use case?
I have been using Wiz for around six months. My main use case for Wiz is cloud security visibility and risk management, as I use it to identify misconfigurations, vulnerabilities, and potentially security risks across a cloud environment. Having this information in one place makes it easier for the security team to prioritize issues and focus on the risks that need attention first.
An example of how my team uses Wiz for risk management or visibility is identifying a cloud resource with a security misconfiguration and prioritizing it based on the associated risk. Instead of manually checking every resource, the team can quickly see the issue, understand its potential impact, and route it to the right team for remediation, making the review process much more efficient.
I also use Wiz as a central point for getting an overall view of the cloud security posture. It helps us bring different security findings together, prioritize the important risks, and give us a clear picture of where attention is needed. The centralized visibility is probably the biggest benefit for all of us.
Wiz is primarily used in our public cloud environment, having integrated with a cloud account so the team can get centralized visibility into configurations, vulnerabilities, and security risks across the environment without managing separate tools for each account.
Wiz has helped us consolidate some of our cloud security workflows into a single platform, making it easier to prioritize critical risks because we can see the related findings and context together instead of switching between multiple tools. It reduces the noise and helps the team focus on issues that have the greatest potential impact.
The runtime sensor has improved our visibility into active threats by providing more context around what is happening in the environment, making it easier to distinguish active threats from lower findings and focus the team's attention on threats that require immediate investigation compared to previous solutions.
What is most valuable?
The best features Wiz offers include centralized cloud visibility, risk prioritization, and the identification of misconfigurations and vulnerabilities. I also appreciate how Wiz connects different findings and provides context around the potential impact, making it easier to focus on the issues that actually matter instead of treating every alert the same way.
The feature that has made the biggest difference for our team is centralized cloud visibility, as it gives us a much clearer view of our overall security posture and helps us quickly identify which sources have the highest priority risks. This saves time compared to manually referring to different cloud environments and security findings separately.
I appreciate that the features work together rather than operating as completely separate tools, as the combination of visibility, risk context, and prioritization makes it easier for the team to understand what needs attention first. It keeps the security workflow relatively simple while still providing a good level of detail.
Overall, Wiz has a positive impact on our organization by improving our visibility into the cloud environment and making it easier to identify and prioritize security risks. The centralized view has also helped the team spend less time manually viewing findings and focus more on addressing the issues that have the greatest potential impact.
What needs improvement?
Wiz is already quite strong, but the platform could be made even easier for new users with more guided workflows and simpler explanations of some of the more advanced findings. I would also like to see further improvements in reporting and customization so the team can tailor dashboards and reports more closely to their specific needs.
One area I would like to see improved is the user experience around complex findings, as having more contextual guidance on why an issue is important and the recommended remediation steps would make it easier for newer team members to act on findings. More flexible reporting and dashboard options would also be useful.
What do I think about the stability of the solution?
Overall, I have found Wiz to be stable and reliable in day-to-day use, consistently providing visibility across our cloud environment without experiencing major stability issues. The platform has been dependable for monitoring security posture and keeping track of risks over time.
What do I think about the scalability of the solution?
I rate Wiz's scalability quite positively, as it works well as the cloud environment grows and makes it possible to maintain visibility across multiple accounts and resources from a centralized platform, making it easier for the security team to scale monitoring and risk management without significantly increasing the manual effort.
How are customer service and support?
Overall, I have had a positive experience with Wiz customer support, as the team has been responsive when I needed help with configuration or understanding specific findings. Their guidance has helped me resolve questions faster, although the response time on more complex issues could sometimes be improved.
Which solution did I use previously and why did I switch?
I previously used CrowdStrike as a cloud security solution, but I was not finding it working according to my needs, so I needed to switch. I chose Wiz, which has been more efficient and has been working very well.
How was the initial setup?
My experience with pricing, setup cost, and licensing for Wiz has been fairly straightforward, as the setup was relatively smooth once the cloud environment and integrations were configured. The licensing model was easy for me to understand, with the overall cost feeling reasonable considering the visibility and security coverage Wiz provides across the cloud environments.
What was our ROI?
While I have not calculated a formal ROI with specific financial figures, the overall impact of Wiz has been positive, as it saves time by bringing cloud security findings and context into one place and reduces manual investigation and prioritization. It also helps the existing team work more efficiently without needing additional resources just to manage cloud security visibility.
Which other solutions did I evaluate?
I evaluated a few other cloud security platforms before choosing Wiz, mainly comparing them on cloud visibility, risk prioritization, ease of deployment, integrations, and overall usability. Wiz stood out because it provided a more centralized view of our cloud environment and made it easier to understand and prioritize the risks I was seeing.
What other advice do I have?
While I have not formally measured the impact with specific numbers, the time savings from using Wiz are noticeable, as it reduces the amount of manual effort needed to view cloud resources and prioritize findings. The team can get context around the risks much faster, helping us respond to important issues most efficiently.
Wiz has reduced alert fatigue for the team, mainly by providing better context and helping prioritize the findings that matter most. While I have not formally measured the reduction over a specific period, the team spends noticeably less time sorting through low findings and can focus more quickly on critical risks.
I use Wiz post-sale support services when needed, which have been helpful for resolving configuration questions and getting guidance on more complex security findings. Having that support available helps our team troubleshoot issues faster, using the time I could otherwise spend figuring out certain problems on my own.
Wiz has helped us reduce and prioritize critical issues, although we have not consistently reached zero criticals in the issue queue. Its prioritization and contextual information make it easier to identify the most important issues and get them assigned for remediation, which has improved our overall response process.
I recommend Wiz to organizations looking for better visibility and centralized management for cloud security risks, advising that they clearly define their cloud accounts and security priorities before deploying it. The platform can surface a lot of information, so taking time to understand its prioritization features will help the team get the most value from it. I rate this product nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner