No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2860563 - PeerSpot reviewer
Lead, Applications Cloud And Platform Security at a manufacturing company with 10,001+ employees
Real User
Top 20
Jun 23, 2026
Improved code security posture and visibility but still needs stronger secret scanning protections
Pros and Cons
  • "Approximately 30 to 40% of vulnerabilities are being remediated quicker and easily because Wiz Code has an auto-fixing PR feature available for IAC code, which helps us fix issues quickly."
  • "Wiz Code could be better in secret scanning where no push protections are enabled at the GitHub or GitLab level to prevent pushing secrets on GitHub itself."

What is our primary use case?

Our AppSec journey focuses specifically on secret scanning to SCA, and we have been using Wiz Code IAC lately to perform Terraform and IAC code scannings for security posture before deployment to the cloud. Wiz Code has another feature where we ingest AppSec findings from Semgrep, Snyk, and Gosec.

When developers write microservices with containers, Azure Functions, or any sort of microservice or monolithic applications, they use a default branch focused towards production and feature branches. Approximately 30 to 40% of code comes via AI agentic development. When engineers develop new features, their code is scanned as part of the feature branch using Wiz Code. Wiz Code supports first-party and third-party code scanning along with secrets and IAC, and provides constructive feedback for security hygiene and code posture. Engineers or agents receive this feedback, act upon it, and fix findings before merging to the default branch, which may be main or any release branch we have. Our CD pipeline then kicks in. Wiz Code fits into our Application Security Posture Management and gives us thorough insights.

What is most valuable?

I prefer Wiz Code specifically because it creates less friction and the intuitive UI helps me significantly. Wiz Code has a rules policy that is not noisy for the engineering team, which is quite important. Less false positives with Wiz Code is the key USP that I love.

The UI is everything in the AppSec world and dashboards. If results are not constructively presented and showcased with prioritizations and metrics, they will be misguided. Wiz Code helps us show results in the best way, and this has been consumed by the engineering team with good prioritization metrics. Wiz Code has a UI dashboard and performance metrics that help us triage vulnerabilities quicker.

People are writing secure code with good visibility about how the code is performing and the posture is becoming visible. Wiz Code has helped us have better visibility across our source code and gives us thorough insights.

What needs improvement?

Wiz Code could be better in secret scanning where no push protections are enabled at the GitHub or GitLab level to prevent pushing secrets on GitHub itself. There appear to be limitations in terms of Wiz Code as an external party to SCM source code management systems, which makes this somewhat problematic. Otherwise, it still seems to be good.

For how long have I used the solution?

I have been using Wiz Code for around 15 months.

Buyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.

What other advice do I have?

Approximately 30 to 40% of vulnerabilities are being remediated quicker and easily because Wiz Code has an auto-fixing PR feature available for IAC code, which helps us fix issues quickly. We also use it for containers. Using Wiz OS, we were able to resolve many vulnerabilities, and Wiz Code scans those and gives assurance that these particular images are not vulnerable anymore. Secure coding practices are improving.

Wiz Code is used to develop our AppSec dashboards. We have our internal CMDB tied up to Wiz. Wiz Code is used as an inventory to see our application security postures. It is used across our engineering teams, product teams, vulnerability management team, GRC, architecture teams, CISO, head of engineering, head of cybersecurity, and SecEng teams, all of whom use Wiz Code for checking the posture of our applications.

Wiz Code has mature ways of handling AI, which seems to be good. The efficacy seems to be very good. The review rating for this product is 7.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 23, 2026
Flag as inappropriate
PeerSpot user
MohammedYasin - PeerSpot reviewer
Senior AI, SRE and Automation Engineer at a tech vendor with 5,001-10,000 employees
MSP
Top 20
Dec 9, 2025
Cloud security has improved and detects vulnerabilities across multi-account environments
Pros and Cons
  • "If anyone wants to secure their infrastructure, cloud environment, or Kubernetes cluster, I would strongly recommend Wiz as a tool because it is easy to use and user-friendly."
  • "Once you get a threat and fix it, to see that fix reflected in Wiz, you have to wait 24 hours. That is something I am not happy with."

What is our primary use case?

Wiz serves as our enterprise tool for securing our cloud platform. We use AWS as our cloud platform and have Wiz integrated across multiple accounts for IT, engineering, and other departments. Within IT itself, we have different environments including development, production, and stage accounts. In every account, we have Wiz integrated and use policies based on the environment. For example, the dev environment has a less secure policy while production has a high-security policy. Technically, we use Wiz for securing our cloud platform.

What is most valuable?

The best feature of Wiz is the ability to detect any security violations across multi-cloud platforms and the ability to integrate for creating security incidents and vulnerability incidents. It works very well for scanning the environment, detecting vulnerabilities, and reporting them based on our requirements. It can generate reports via email or create ServiceNow incidents. It has helped me identify threats more easily. When it comes to the Kubernetes cluster, we do not have any other option for detecting vulnerabilities. This is the only way we observe our Kubernetes clusters to determine whether they are secured or not. Regarding speed, I cannot compare it with other solutions, but so far, we are happy with the way it works.

Wiz has improved our business in many ways. While I do not know in numbers how it has helped the business gain more profit, as a technical expert and part of our IT architect team, I would say Wiz has helped tremendously to secure our cloud platform. There were many security vulnerabilities existing before we implemented this solution that were not at all in our attention because there was nothing to scan and report what was wrong. After implementing Wiz, it has helped significantly. There was a program for implementing high-security measures in our environment, and Wiz has contributed substantially to that program.

What needs improvement?

I feel there is a delay in detection, though I am uncertain whether this is due to our implementation disadvantage. Wiz can detect all the issues, threats, and security vulnerabilities, but the delay may be due to the time taken for running a scan because we have a 24-hour scan cycle. When I checked with the team, there was no on-demand scanning possibility. We still see improvement scopes in this area. It does the work, but we are not seeing the changes very fast. Once you get a threat and fix it, to see that fix reflected in Wiz, you have to wait 24 hours. That is something I am not happy with.

One improvement that I am looking for in Wiz is the capability for on-demand scanning. That should be available. Second, we should be able to see the fixes faster. Once a threat is detected and we apply the fix, we want to see that result updated in the dashboard or portal as soon as possible. If Wiz can detect it faster and update it in the portal, that would be beneficial.

For how long have I used the solution?

I have been using Wiz for more than two years, approximately two years and four months.

What do I think about the stability of the solution?

Regarding stability, it is stable. I would rate it nine out of ten.

What do I think about the scalability of the solution?

Regarding scalability, I would also rate it nine out of ten.

How are customer service and support?

I would rate the technical support of Wiz eight out of ten on a scale from one to ten, with ten being the best.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

When comparing Wiz with other software, I did not use any other software similar to Wiz for the same purpose. A similar tool was Qualys, but we used Qualys for a different use case. We used it for vulnerability scanning of our servers, not end-user devices. For securing or detecting threats from cloud accounts, I do not have any other tool that I am aware of. Qualys is another vulnerability management tool, but the use cases are different, so I do not have the expertise to compare.

How was the initial setup?

Deployment took approximately three months.

What about the implementation team?

From one to ten, with one being cheap and ten being expensive, I would rate the implementation cost a seven.

What was our ROI?

Wiz does require some maintenance.

What's my experience with pricing, setup cost, and licensing?

Wiz does require some maintenance.

Which other solutions did I evaluate?

My thoughts on the pricing of Wiz are that it is not cheap, but it is cost-efficient. From one to ten, with one being cheap and ten being expensive, I would rate it a seven.

What other advice do I have?

I would recommend Wiz to anyone. If anyone wants to secure their infrastructure, cloud environment, or Kubernetes cluster, I would strongly recommend Wiz as a tool because it is easy to use and user-friendly. It has tight integration with many tools out-of-the-box for sending alerts, creating emails, and creating incidents.

My advice to others looking to implement Wiz is that when you implement Wiz, if your hybrid environment is not managed properly, it will be difficult to implement. It is better to make some cleanup and ensure that the environment you are going to implement meets Wiz standards. If you do not take care of that and simply implement Wiz, you will encounter many issues being reported by the system. It is better to follow the prerequisite standards of your cloud account and then implement the solution. Otherwise, you will see many issues being reported.

Regarding whether Wiz has helped reduce alert fatigue, I do not have a definitive answer because we do not see that much decrease in the alerts. Initially, when we implemented Wiz, since we were not using any tool like that before, there were too many alerts. Because it was the first implementation, it started sending too many alerts. Later on, the alerts decreased, but this decrease was not because of Wiz itself. Rather, it was because we implemented security fixes wherever Wiz reported threats or vulnerabilities. That is how the number of alerts got reduced. I feel we can also customize the Wiz policy to reduce the number of alerts, but I am not at that level here, so I do not have that expertise.

My overall rating for this solution is eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.
Solomon Henry - PeerSpot reviewer
Cybersecurity Consultant (Enterprise Projects & Detection Engineering) at Lighthouse Technology
Real User
Top 5Leaderboard
Jun 19, 2026
Security projects have achieved zero failures and deliver consistent protection for cloud workloads
Pros and Cons
  • "From the CNAPP focus, it has been serving me exceptionally with zero failure rate since I've been using it."
  • "The pricing of Wiz Code is a little bit higher for small enterprises that I run, but it's something that I can manage."

What is our primary use case?

I am an end user of Wiz Code and I use it for personal projects.

I use Wiz Code for Kubernetes baseline and for security CNAPP projects.

As a security engineer using Wiz Code, I can say that when running my Kubernetes on the AWS cloud and on Azure, I haven't had any errors, so my production teams operate smoothly with a zero failure rate.

From the Kubernetes baseline focus I have with Wiz Code, I think it's perfect, and from the CNAPP focus, it has been serving me exceptionally with zero failure rate since I've been using it.

I have strong models that I work with when setting up Wiz Code; I use AI to enhance my security projects, so most of the challenges I face, I fix from a security engineering perspective, and the installation process was smooth.

I use Wiz Code on-premises because I work with Active Directory, while I do have a cloud that I'm running on Azure, but I'm considering deploying most of my EC2 instances on AWS while thinking about the pricing.

What is most valuable?

Throughout my years of experience with Wiz Code, I've explored a wide range of resources, and I haven't had issues with the exploration resources, plus it's flexible. I have used Wiz Code for over two years now, and I haven't had any failures.

I appreciate how Wiz Code approaches insecure default detection, IAC, and runtime visibility, as well as Kubernetes misconfiguration analysis, and I value the developer-focused remediation guidance and integration into broader cloud security operations; these are my honest technical feedback based on a practitioner's perspective.

The pricing of Wiz Code is a bit high for some beginner's level and intermediate users, but I think it's quite affordable for now.

What needs improvement?

I haven't really explored the scalability of Wiz Code yet, but I'm looking to explore it on the production side for my DevSec project scheduled to start in about two weeks from now.

The pricing of Wiz Code is a little bit higher for small enterprises that I run, but it's something that I can manage.

For how long have I used the solution?

I have been using Wiz Code for about two years now.

What do I think about the stability of the solution?

I have used Wiz Code for over two years now, and I haven't had any failures.

From the CNAPP focus, it has been serving me exceptionally with zero failure rate since I've been using it.

What do I think about the scalability of the solution?

I haven't really explored the scalability of Wiz Code yet, but I'm looking to explore it on the production side for my DevSec project scheduled to start in about two weeks from now.

How are customer service and support?

This is my first time communicating with the technical support of Wiz Code.

Which solution did I use previously and why did I switch?

I haven't used a different solution for the same use cases before Wiz Code; it came to me highly recommended, and I am comfortable and satisfied with the services I receive.

How was the initial setup?

I have strong models that I work with when setting up Wiz Code; I use AI to enhance my security projects, so most of the challenges I face, I fix from a security engineering perspective, and the installation process was smooth.

What about the implementation team?

I haven't used any official documentation, guides, or manuals for Wiz Code.

What's my experience with pricing, setup cost, and licensing?

For now, I haven't considered a second choice other than Wiz Code; I am satisfied with the services I am getting, with my only challenge being the pricing.

Which other solutions did I evaluate?

When I researched options, Wiz Code came at the top of my list, and I haven't looked elsewhere ever since then.

What other advice do I have?

I have projects scheduled for production with Wiz Code that I will be exploring this month, specifically in two weeks' time.

When I explore more on my upcoming project with Wiz Code, I will always provide feedback on whatever I notice.

The flexibility of Wiz Code made me choose it over other options; for a small enterprise such as myself, the pricing was flexible and affordable, and the user interface fits well with the project I am working on. I give this review a rating of 8.5 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 19, 2026
Flag as inappropriate
PeerSpot user
Product Management Cybersecurity Leader at a tech vendor with 10,001+ employees
Real User
Top 20
Jun 18, 2026
Cloud security has become more prioritized and consolidated but still needs better context and bundling
Pros and Cons
  • "Overall, I believe Wiz is doing a great job, simplifying many aspects for security professionals and enterprises."
  • "As an extensive user of Wiz, I have noticed that one critical area Wiz is missing is context."

What is our primary use case?

I am using Wiz for CNAPP and DSPM, primarily for vulnerability and exposure management. These are the key areas I am focusing on, and over the last five years, I have been actively working with Wiz. Prior to that, I used it for a specific customer deployment in my previous organizations.

What is most valuable?

There are several resources deployed on the cloud, and we are monitoring those assets. Wiz has a very strong AI engine that can correlate these findings, and I believe that is the clearer differentiator from other products in the market. We are using Wiz to define the correlation, and it works perfectly by defining priority based on impact and likelihood. I feel this saves considerable rework from security engineers and the team, helping us to immediately act on these exposure issues and address high and critical vulnerabilities.

All other security tools I have seen mainly focus on impact and try to map directly with the CVSS. I think that context is outdated now because threats have changed and patterns have evolved. It clearly requires a different approach so that we can use it enterprise-wide, and security leaders should get clear visibility on the likelihood of these incidents and decide whether to spend resources on them.

Wiz is performing quite well with the existing CNAPP capability. However, Wiz has additional functionalities under Wiz Code, and there are other modules coming for AI security. That is definitely new, which Wiz offers, and it is completely different from existing solutions.

From a security tooling perspective, every enterprise is bombarded with thousands of tools and nobody knows how to consolidate them and what those different data points should be used for. That has been one of the nightmares, where most people simply spend their resources managing those tools and remediating the same issues on different platforms. Using Wiz Code and the other matching capability helps me eliminate the redundancy of tools in my infrastructure. That is a significant win, as I can see everything in a single pane of glass.

The response time has drastically increased, and the data we are getting is more focused. That is something truly required in security, as you need to respond as quickly as possible to breaches because they occur in fractions of seconds. Therefore, quick responsiveness is something Wiz has truly achieved.

What needs improvement?

As an extensive user of Wiz, I have noticed that one critical area Wiz is missing is context. It is performing well in terms of reporting issues and mapping to the environment, but many false positives are generated because it lacks context. I would appreciate Wiz ingesting customer context, understanding how I am using it and what my infrastructure looks like, so it can determine whether something is truly an issue for me. I do not want to keep dealing with thousands of vulnerabilities and marking them under ignore rules or wasting time assessing everything only to find they are false positives. This is an area where Wiz really needs to focus.

Secondly, regarding remediation, Wiz has playbooks, but it is not adding anything new. If I wanted to use Wiz with AI infrastructure, it could provide more guidance on best practices and how to implement them.

Currently, Wiz has three modules: Wiz, Wiz Code, and CNAPP. At some point, Wiz needs to rethink this and consider a bundled offering for more benefit to customers and product owners. If I buy CNAPP and later move to Wiz Code, there may be conflicting or overlapping features. People could be confused about why to use Wiz Code and what is different. It should look like a simple bundle, indicating what you are getting and when to use each. Currently, when to use what is missing, and while it is documented, as an enterprise decision maker, I do not want to spend time repeatedly on the same tools. I want a single comprehensive solution. Wiz Code should be the default offering as a simple, pay-as-you-go model without requiring separate deployments.

The lack of context is an issue. The tool is performing well, but without context, it generates many false positives, which every organization using Wiz struggles with. Secondly, the multiple offerings lead to confusion, as people may hesitate to use the next solution, such as Wiz Code. These two aspects are holding me back from giving a higher rating.

For how long have I used the solution?

I have been using Wiz for almost five years.

What other advice do I have?

As a security product manager and extensive user, I recommend that people explore Wiz. It simplifies their lives with many new features and capabilities. It allows for easy adoption in defining benchmarks and a minimum security baseline for organizations, something that is harder with other tools. Some solutions claim to have specific capabilities, but they do not deliver. Based on my hands-on experience, I can say that Wiz is a clear differentiator, and people should definitely consider it.

Wiz helped consolidate tools, but there were overlapping capabilities, and we still are not getting a complete view. To a certain extent, it helped with consolidation, but there is still room for improvement. I provided feedback suggesting that Wiz Code and other capabilities should be under the same bundle with a pay-as-you-go model, as it can be time-consuming to enable these capabilities later.

Overall, I believe Wiz is doing a great job, simplifying many aspects for security professionals and enterprises. The dashboard is quite nice, and with the introduction of the MCP, I am only concerned about remediation, context defining, and bundling of offerings. These are three areas I want Wiz to focus on to make their product even better. I would rate this product a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 18, 2026
Flag as inappropriate
PeerSpot user
Wellington Franham - PeerSpot reviewer
CEO at Century Data
Real User
Top 5Leaderboard
Oct 12, 2025
Has enabled consistent risk analysis and compliance tracking across multiple cloud environments
Pros and Cons
  • "Wiz can accomplish this and easily provide the total inventory in the cloud, which is crucial when managing large cloud databases or environments such as AWS, Azure, or Google environments, where it's difficult to have one view for all cloud components."
  • "An area that Wiz can still continue to improve is FinOps."

What is our primary use case?

We are a Wiz user and partner, so we have an environment using Wiz, and our use case is to provide risk analysis. We have dashboards to understand the main risks and categorize them, and we use these to get the baseline and reports. We personalize some reports.

What is most valuable?

The best features of Wiz are the AI, risk analysis, the framework, and the compliance frameworks, so we can check if our frameworks comply with CCPA or similar regulations, and the toxic combination. We can identify active threats more effectively with granularity in databases, operational systems, and access keys, so the granularity of the Wiz view is the key for this kind of risk analysis.

We can provide an inventory, which is crucial when managing large cloud databases or environments such as AWS, Azure, or Google environments, where it's difficult to have one view for all cloud components. Wiz can accomplish this and easily provide the total inventory in the cloud.

Wiz has helped us analyze critical issues, and it can provide guidance on how to mitigate these issues to resolve them, offering step-by-step instructions.

What needs improvement?

An area that Wiz can still continue to improve is FinOps.

For how long have I used the solution?

I have been using Wiz for almost one and a half years.

How are customer service and support?

My experience with Wiz's support has been satisfactory.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We analyzed other options before choosing Wiz. For example, we looked at Orca, which lacks functionality such as toxic combination or resolving issues easily. Wiz can provide a better way to resolve critical issues, while Orca can show the issues but not truly resolve them.

What other advice do I have?

We use Wiz in the cloud with AWS and GCP. We use both AWS and GCP almost equally. The time frame to achieve zero criticals in our issue queues depends on the environment. While we don't achieve zero criticals, some problems can be solved in two or three weeks while others may occur. It's optimal to work toward zero critical issues, but it depends on the installation or the cloud dynamics.

Some customers achieve zero critical issues, and Wiz has a program that rewards this achievement with a puzzle. Wiz offers pricing for both huge and small environments, and customers can purchase it from the Google Marketplace. In my opinion, Wiz has a competitive price.

I rate Wiz between 9 and 10 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2244411 - PeerSpot reviewer
Security Architect/Staff Engineer at a consultancy with 10,001+ employees
Real User
Top 5Leaderboard
May 21, 2026
Unified security platform has reduced triage time and gives real-time visibility into code risks
Pros and Cons
  • "Wiz Code is a platform that serves most of these features as a single entity, which has definitely reduced the time for triaging the security aspects of vulnerabilities and helps in overall innovation for the team."
  • "Metadata ingestion and probably the integration of Wiz Code platform is something which is missing."

What is our primary use case?

Wiz Code is designed for scanning code repositories for vulnerabilities, whether through static scans, dynamic security scans, or by identifying vulnerabilities in third-party libraries. Overall, it's a complete package that can help scan code repositories and code bases while flagging findings that are not beneficial for organizations.

We have integrated Wiz Code with our GitHub repositories and have been tracking the findings. With real-time code tracking, developers and security engineers from our team are able to see findings and misconfigurations within the code in real-time, and they can reach out to specific developers for remediation of those findings.

Automated code reviews are something we have in process. We have developed a CI/CD pipeline automation that can be integrated with the code repository and utilize Wiz Code for this purpose, so that pull requests can be triggered to lead to automatic remediation. However, this is specific to organizational needs. Some teams do require prior review before implementing any changes, whether minor or major, and they do require proper peer review for those pull requests. As far as automations are concerned, we have tested this within our environment, but it is specific to developer and team needs.

What is most valuable?

Wiz Code is itself a feature. Apart from Wiz, these are the specific features that Wiz Code has introduced. Earlier it was a single bundle package, but once Wiz was acquired by Google, they have separate SKUs, and Wiz Code is one of them. The feature itself is for code repositories.

As far as innovations are concerned, getting security on a single platform with respect to all findings, whether static findings, dynamic findings, secrets findings, or third-party library dependency findings, helps at a broader level when it comes to innovation. As a developer, I do not need to use different tools. Earlier in a traditional method, I used to rely on different tools for third-party library dependency findings, static findings, and dynamic findings. Wiz Code is a platform that serves most of these features as a single entity, which has definitely reduced the time for triaging the security aspects of vulnerabilities and helps in overall innovation for the team.

What needs improvement?

Every tool has some sort of improvement required. No tool can be said to be one hundred percent secure, so there's always a scope for improvement. When it comes to Wiz Code, how they are ingesting the metadata with respect to the integrated platform is something they can improve upon. In fact, they have already started working on this and are continuously improving those data ingestion parts with the integrated platform, whether GitHub, Bitbucket, or GitLab. Whatever information the platform is ingesting can be further used for automation as well. If I want to create some sort of policy by ingesting those data, I can do that. However, that requires visibility to the API that can support these integrations. In summary, there is a good scope for improvement for this platform.

Metadata ingestion and probably the integration of Wiz Code platform is something which is missing. They are already working on that. With the advancement of GenAI and AI, most vendors are in the AI race, and they want to make sure they are supportable for other platforms that are currently used in vibe coding. This is something I think Wiz Code can work on, making those integrations accessible for vendors available in the market.

For how long have I used the solution?

I have been working with Wiz Code for approximately one year.

How are customer service and support?

I haven't used much technical support specific to Wiz Code, but overall, as far as technical support and customer success interaction are concerned, I would say it is good. I do not have a very bad experience with those folks.

How was the initial setup?

The initial setup for Wiz Code is most straightforward.

What's my experience with pricing, setup cost, and licensing?

The topic of their pricing is confidential, which I'm not authorized to share. However, it is a bit expensive, but that depends on how broad your organization is and what your use case is. If you are a small scale enterprise organization, you probably would not pay such a hefty amount of money to protect your organization. However, if you're a big organization, if the organization is a large-scale enterprise organization and it's a reputable organization, then probably if you get most of the things in a single platform, then you do some trade-offs. In summary, it depends on where or what organization you're from and what your use case is.

What other advice do I have?

I'm working with Wiz Code as well, but I just wanted to understand why you are asking these specific questions. Do you want a review on a certain product?

There are some Check Point products still used in my company, but that would be specific.

I would rate this review at eight point five out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 21, 2026
Flag as inappropriate
PeerSpot user
reviewer2808789 - PeerSpot reviewer
Senior Software Engineer - Security at a financial services firm with 501-1,000 employees
Real User
Top 20
Mar 19, 2026
Automation has transformed cloud and container security posture and reduced manual effort
Pros and Cons
  • "Wiz is one of the finest tools that I have used so far, and it gives visibility to all the services based resources, which other tools do not give."
  • "I choose eight out of ten because there is always room for improvement."

What is our primary use case?

My main use case for Wiz is that it identifies misconfigurations within the cloud services and misconfiguration within the Kubernetes platform. We also detect vulnerabilities within the runtime from the containers. Once we have those findings in place, we run a cron job within the GitLab pipeline wherein it pulls all vulnerabilities and misconfigurations and then creates tickets to the respective teams through Jira or through ServiceNow. Everything is totally automated. A Python function has been created which pulls all the vulnerabilities, performs data enrichment to identify the ownership, and then assigns the SLA and the SLA breach timeline, based on which it is then posted to the respective groups.

What is most valuable?

The best features Wiz offers in my experience are the collective findings that you get to see for each resource, which is called something as issues. It combines all findings, whether it is exposed to the internet, whether it has misconfigurations, whether there is encryption in place, or whether there is an IAM issue in place. You get to see all findings for a particular resource in one view, which Prisma or some other tool was not offering at this moment. Wiz is also offering ASPM at a service management level, KSPM, and AI security.

Wiz has positively impacted my organization because with the consequence model, as and when the consequence model triggers, every team goes ahead and mitigates the findings to ensure that it is not escalated to the CEO level. The automation is helping us to drive our platform to be more secure.

What needs improvement?

I choose eight out of ten because there is always room for improvement. Possibly I am not able to identify it, but definitely there would be some room for improvement. Nothing is perfect in terms of security.

We are in the process of getting to zero-day vulnerabilities.

For how long have I used the solution?

I have been using Wiz for the past two years, enabling CSPM and CWP mainly, but as of now we have also started with KSPM, which is Kubernetes security posture management and data security posture management as well in my current company.

What do I think about the stability of the solution?

Wiz is stable in my experience.

What do I think about the scalability of the solution?

Wiz's scalability is good as of now because the attributes we need in terms of identifying vulnerabilities is pretty good compared to Prisma.

How are customer service and support?

Customer support is good. They are really helpful, but it is only the management who gets to interact with the sales team.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did evaluate CrowdStrike, Tenable One, and Prisma Cortex.

How was the initial setup?

We create dashboards with the automation, so all the findings being pulled from Wiz are enriched first, and then we store all those findings with the SLA metrics into a Grafana dashboard.

What was our ROI?

I have seen a return on investment with Wiz, specifically in that we need fewer employees.

What other advice do I have?

I would advise others looking into using Wiz to definitely compare it with all the other tools that are in the market. Wiz is one of the finest tools that I have used so far, and it gives visibility to all the services based resources, which other tools do not give. It also helps to create custom policies based on Rego, which is one of the easiest solutions that anyone can develop. I give this product a rating of eight out of ten and would definitely recommend Wiz.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 19, 2026
Flag as inappropriate
PeerSpot user
PrashantGupta2 - PeerSpot reviewer
Software Engineer L2 at a tech vendor with 5,001-10,000 employees
Real User
Top 5Leaderboard
Sep 20, 2026
Automated scanning has safeguarded our pipelines and continuously improves cloud security
Pros and Cons
  • "I feel that the automated scanning system of images and accounts offered by Wiz is amazing, and the best part is that they provide solutions as well, allowing us to solve the problems without looking elsewhere."
  • "I think speed is important; Wiz waits for approval before suggesting a new vulnerability solution, so a faster cycle would help developers prepare before an attack occurs."

What is our primary use case?

My main use case for Wiz is to scan the vulnerabilities related to our system.

We are planning to introduce Wiz into our CI/CD, scanning the Docker image whenever it gets built, so if there is any vulnerability, we can refer to the Wiz report and resolve it before pushing the code.

The cloud security democratization aspect of Wiz is crucial, as our company offers various services and must ensure data security and product quality while managing threats from older dependencies or JARs.

What is most valuable?

I feel that the automated scanning system of images and accounts offered by Wiz is amazing, and the best part is that they provide solutions as well, allowing us to solve the problems without looking elsewhere.

The automated scanning stands out for me because when our security team raises a ticket, the solutions provided in the Wiz report help us debug those issues, and I rely 100% on the Wiz solutions.

Wiz has positively impacted our organization by solving many issues, such as ensuring we do not have vulnerable code in our production environment, protecting our customer data, and helping us maintain system security from potential threats.

I notice that whenever the scans are completed, we consistently upgrade our system, and Wiz scans for any unused infrastructure that we are not using or maintaining, pointing out vulnerable files that can be upgraded or deleted.

Wiz does allow us to consolidate tools, providing abundant infrastructure information before billing is affected and recommending solutions for any public-facing vulnerabilities, which enables us to rely on Wiz to address critical infrastructure issues.

I feel that Wiz has reduced alert fatigue in our organization by approximately 70%.

What needs improvement?

I believe Wiz is 100% correct in what it does, and if there is any improvement needed, it would be more mature reporting and solutions, as Wiz detects threats only when they have a solution available.

I think speed is important; Wiz waits for approval before suggesting a new vulnerability solution, so a faster cycle would help developers prepare before an attack occurs.

For how long have I used the solution?

I have been using Wiz for two years.

What do I think about the stability of the solution?

Wiz is stable.

What do I think about the scalability of the solution?

For my use case, I do not experience any issues with Wiz's scalability, and I see that it can handle various services, making it highly scalable and reliable.

How are customer service and support?

Customer support was helpful in resolving issues caused by a mistake on our part during configuration.

Which solution did I use previously and why did I switch?

I do not have prior experience with any solutions besides Wiz, so I feel that Wiz does the job perfectly in identifying active threats.

Which other solutions did I evaluate?

We have only used Wiz, and when I joined my company, Wiz was the ultimate choice for us.

What other advice do I have?

I find Wiz's AI capabilities to be very capable, as we sometimes chat with the AI and review reports for better understanding.

The accuracy and reliability of Wiz's output are quite good, and the AI helps clarify any doubts I have regarding the reports.

I advise others looking into using Wiz to rely on it smartly and trust the solutions it provides.

I rate this review as 9 out of 10.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 20, 2026
Flag as inappropriate
PeerSpot user
Wellington Franham - PeerSpot reviewer
CEO at Century Data
Real User
Top 5Leaderboard
Oct 11, 2025
Provides detailed analysis and helps manage risks effectively
Pros and Cons
  • "Wiz has helped my organization by allowing us to analyze the critical issues and providing the best way to mitigate these issues with step-by-step guidance."
  • "FinOps is an area where Wiz needs enhancement."

What is our primary use case?

We are a Wiz user and partner. We have an environment using Wiz, and our use case is to provide risk analysis.

We have dashboards to understand and categorize the main risks. These dashboards help us generate baseline reports, and we have personalized some of these reports.

How has it helped my organization?

It can provide an inventory. When you have a large cloud database or environment, Wiz can provide you easily with the total inventory that you have in the cloud. 

Wiz has helped my organization by allowing us to analyze the critical issues and providing the best way to mitigate these issues with step-by-step guidance. We don't achieve zero criticals. This often depends on the environment, as solving some problems can lead to two or three others arising. Therefore, navigating through the critical issues is essential, but it relies on the specific installation you have or the dynamics of your cloud setup. Some customers have successfully reached a state of zero critical issues, and we have a program designed to support this. If they are interested in achieving this goal, we can provide them with materials or insights to help them.

What is most valuable?

Wiz's best features are the AI risk analysis and the compliance frameworks. We can check if frameworks are compliant, such as CCPA, and the toxic combination.

The Wiz runtime sensor identifies active threats more effectively by allowing us to run the analysis with granularity in databases, in operational systems, and some access keys. The granularity of the Wiz view is the key for this kind of risk analysis.

What needs improvement?

FinOps is an area where Wiz needs enhancement.

For how long have I used the solution?

I have been using Wiz for almost one and a half years.

How are customer service and support?

I had experience with Wiz's support, and I would rate it a nine out of ten.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

Wiz can accommodate both huge and small environments. You can purchase Wiz from Google Marketplace, for example. Wiz seems to have a competitive price.

Which other solutions did I evaluate?

We evaluated other options such as Orca before choosing Wiz. We analyzed Orca because it lacks certain functions, such as toxic combination or resolving issues easily. Wiz performs better at providing the best way to resolve critical issues, while Orca can only show the issues without resolving them.

What other advice do I have?

I would rate Wiz a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2860389 - PeerSpot reviewer
Vulnerability Management at a tech vendor with 1,001-5,000 employees
Real User
Top 20
Jun 23, 2026
Cloud security has strengthened and vulnerability exposure reduces across multi-cloud environments
Pros and Cons
  • "Overall, Wiz Code is a very good tool to use in any organization, whether mid-level or high-level, and it is very useful and user-friendly for employees."
  • "There are many improvements that could be made to Wiz Code, but I would point out that sometimes it gives false results, though not every time."

What is our primary use case?

We are using Wiz Code for cloud security across AWS, Google Cloud Platform, and Azure. We utilize Wiz Code for vulnerability scanning and misconfiguration issue detection across all three cloud platforms.

For vulnerability management with Wiz Code, we perform daily checks for vulnerabilities and receive CVEs, which we then provide to appropriate teams for remediation guidance. Regarding misconfigurations, we primarily focus on IAMs. If any extra privileges exist with any users, we work with the team to fix these issues.

Wiz Code is very useful for us because it is agentless, so it does not require attention for storage issues on VMs or Kubernetes. It is very useful and supports cloud environments such as Amazon Web Services, Microsoft Azure, and Google Cloud. We use this for identity management, misconfiguration issues, and CSPM security posture management.

What is most valuable?

CSPM is a cloud security posture management feature in Wiz Code. We review the percentage metrics in Wiz Code, and when we identify anomalies or vulnerabilities and fix them, we follow the score on Wiz Code.

Previously, we identified over 500,000 vulnerabilities before Wiz Code. After implementing Wiz Code, we identified more vulnerabilities and misconfiguration issues but reduced the score significantly. Now we identify only 200,000 vulnerabilities, which means Wiz Code helped us reduce 300,000 vulnerabilities in our organization.

First of all, Wiz Code has given us more accurate results. When we identify vulnerabilities, we review that vulnerability and CVE, check publicly affected vulnerabilities in our organization, and determine which VMs are affected. We segregate the data based on CVE codes and work with other teams to remediate these vulnerabilities or address OS upgrades and end-of-life issues.

The AI capabilities in Wiz Code are a very good feature. Employees working on this will get more remediations and detailed remediation guidance. If some tools provide a vulnerability list without remediation guidance, Wiz Code reduces the load of searching for remediation information. For governance and security, Wiz Code is very helpful. It scans everything and provides really deep scans, identifying more vulnerabilities than other tools can find. Vulnerability management is my primary focus, and Wiz Code is a very good tool for this.

What needs improvement?

There are many improvements that could be made to Wiz Code, but I would point out that sometimes it gives false results, though not every time. We know that Wiz Code scans our environment once a day. If it scanned twice a day, that would be more accurate. This is a suggestion from my side.

For how long have I used the solution?

I have been using Wiz Code for the past two and a half years.

What do I think about the stability of the solution?

I did not participate in the integration part as my senior handled those tasks, but I heard that the integration was very easy for any organization.

What do I think about the scalability of the solution?

It is very easy to use, especially the dashboards and everything. We have created many dashboards in Wiz Code for our utilization. We use Wiz Code dashboards and queries daily to identify vulnerabilities.

How are customer service and support?

I would say that they are very responsive. When we initiate a case for Wiz Code customer support, they immediately respond and contact us to help reduce that issue and address any possibilities. It is very good.

Which solution did I use previously and why did I switch?

Previously we used Rapid7, and now we are using Defender. Wiz Code is better than both Defender and Rapid7 and gives more accurate results.

What other advice do I have?

It is very easy to pick up on this new tool, and Wiz Code is very useful and easy to learn and apply in our day-to-day work. We plan to keep Wiz Code for a long time with our subscription through 2030. Wiz Code is a good tool that gives accurate results for our environment and is very useful and user-friendly for employees. Overall, Wiz Code is a very good tool to use in any organization, whether mid-level or high-level. Wiz Code fits any organization. I have given this tool a rating of nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 23, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros sharing their opinions.