No more typing reviews! Try our Samantha, our new voice AI agent.
Lead Software Engineer at Persistent Systems
MSP
Top 20
Jun 30, 2026
AI-assisted code reviews have improved security posture and boost developer productivity
Pros and Cons
  • "I would definitely recommend Wiz Code to boost development and productivity because I have seen significant positive improvements since I started using it."
  • "One noticeable aspect is that we are receiving some false positives, but this is better compared to the previous tool I used."

What is our primary use case?

The first and foremost use case for Wiz Code is cloud security, and later I implemented Wiz Code for static application review and application security.

What is most valuable?

Smart AI fixes and contextual dashboards stand out as the best features Wiz Code offers.

When we have new developers or newcomer developers, with the help of Smart AI fixes in Wiz Code, they are able to understand and fix the code within a given time, which takes very little time to fix while providing more technical details, with fixes, recommendations, and best practices.

Native developer tools in Wiz Code are very helpful because we have received positive feedback from developers who are happy and find it easy to use. The developer dashboards we have utilized to show to our leadership management provide a better understanding of the current security posture of application security.

Wiz Code has positively impacted our organization by showing significant improvement.

What needs improvement?

I would like to work more to understand Wiz Code's complete functionality because I have been using it for the last year, but I have not had the time to explore it completely.

One noticeable aspect is that we are receiving some false positives, but this is better compared to the previous tool I used. If Wiz Code can work on the backend to decrease this noise from false positives, it will be better.

For how long have I used the solution?

I have been using Wiz Code for the past year in my current role.

Buyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.

What other advice do I have?

Before pushing the code into developer production, I use Wiz Code as the main tool to scan the static code during static code review. I have identified multiple vulnerabilities, including passphrase detection, XSS vulnerability, and potential SQL injection vulnerabilities, which have helped us greatly and gained trust from our clients.

As of now, I am very satisfied that Wiz Code is helping us in a robust way. In further developments, I expect more complex and very technical micro-granularity features to be implemented, which would help more to check the code at a granular level.

Regarding Wiz Code's AI capabilities, I would say its governance and security concerning data privacy are much better because the data terms and policies I read about Wiz Code during the agreement assure me of the privacy of my company's client data.

I would say the accuracy and reliability of output for Wiz Code's AI capabilities are nearly 85 percent, considering small glitches on the false positives.

I would definitely recommend Wiz Code to boost development and productivity because I have seen significant positive improvements since I started using it.

I have rated Wiz Code at 8 based on my experience, as I do not have any complaints apart from the false positives.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 30, 2026
Flag as inappropriate
PeerSpot user
Manager Cybersecurity Operation at Grant Thornton (US)
Real User
Top 20
May 8, 2025
Enables efficient management of vulnerabilities and project inventories
Pros and Cons
  • "I rate Wiz's customer service as ten out of ten."
  • "I cannot recommend Wiz to others until I have a clear understanding of its full capacity and benefits."

What is our primary use case?

We are using Wiz for many deployments in terms of vulnerability and also our Microsoft tenants, two different Microsoft tenants. We use it to manage our projects.

Wiz's automated compliance checks are the reason for our use case. I am actually working on the GCCR audit, which is the reason I was looking at it. There are still some things I need clarity on in my own meeting this morning.

What is most valuable?

I might not be able to give substantial information as I do not use the most valuable features of Wiz day-to-day in full capacity. I can check managing each of my projects and check vulnerabilities across each of those projects across each of the tenants. It allows you to manage your inventories that you have in different subscriptions or different tenants on your technology. Then you can configure different kinds of policies that you use around each of those.

What needs improvement?

I have not used Wiz in full capacity, so I cannot provide detailed improvement suggestions. I just started fully going through each feature to have a basic, comprehensive understanding of the product itself.

I cannot recommend Wiz to others until I have a clear understanding of its full capacity and benefits. In my organization, we have Rapid7, which is a vulnerability management tool, we have Wiz, and we have Microsoft Defender. I need to understand the reason for that decision in the first place to be able to look at the benefit to my organization.

For how long have I used the solution?

I started with Wiz some months ago.

What was my experience with deployment of the solution?

I do not know how long it took for us to actually deploy Wiz, as I was not within the corporation when it was deployed.

What do I think about the stability of the solution?

So far, I would say Wiz is stable to the best of my knowledge.

What do I think about the scalability of the solution?

My thoughts on the scalability of Wiz so far is that it is scalable for me and good for us.

On a scale of one to ten, I would rate the scalability of Wiz as nine.

How are customer service and support?

I rate Wiz's customer service as ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

I find the initial setup of Wiz straightforward in my opinion.

On a scale of one to ten, I would rate how easy it is to set up Wiz as nine, if ten is the easiest.

What about the implementation team?

I do not know how many people it took to deploy Wiz. However, it is always the vendor and probably my director that was in the position which I was before.

What was our ROI?

I do not know if Wiz has impacted our operational costs related to cloud security or any kind of return on investment or operational impact that it has for us.

Which other solutions did I evaluate?

I do not really know the main differences between Wiz and other vulnerability management solutions such as Defender, but they perform similar functions.

When comparing Wiz to Defender, I think they do almost the same thing. The only difference is that Defender will give you RISK call. However, Wiz can give you a risk call against your investment because it is not a Microsoft solution.

What other advice do I have?

I work in accounting with Wiz in a large enterprise business.

Wiz does not require a lot of maintenance on our side. It is just ease of use. Wiz maintains most of it.

I have not used Wiz's AI capabilities to enhance our security threat detection as I just started looking at it. I have not really done much with that so far.

Overall, I would rate Wiz as good. I get everything I want, just the same way it is for every other solution, so I am going to rate it nine out of ten.

I rate Wiz a nine out of ten instead of a ten until I use the solution based on use cases and exploitation of the product, and what it gives me. If I am able to do that in full capacity, then I will give it ten. This is just based on what I still see so far. Until I get to see the benefits and everything, then my rating might be different in two weeks' time. At this moment, this is how it is.

RISC call is what I mean by that, RISC (R I S K).

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Wiz
September 2026
Learn what your peers think about Wiz. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,117 professionals have used our research since 2012.
Vulnerability Management Analyst at a government with 1-10 employees
Real User
Top 20
May 27, 2026
Improved vulnerability visibility has reduced critical risks and maintains healthier app security
Pros and Cons
  • "Wiz Code has positively impacted our organization as it helped us to maintain a healthy application security side of the company and to remediate our vulnerabilities."
  • "Wiz Code could be improved by showing us the dependencies that are affecting us; if we are upgrading one dependency, it would be helpful to know if down the road that's going to cause any problems with other dependencies."

What is our primary use case?

My main use case for Wiz Code is for application security, to scan vulnerabilities and prioritize the vulnerabilities based on results.

When a new vulnerability is published, I review the findings from Wiz Code and see if we are exposed with our versions we are using, and if we need to upgrade, what version, and what priority it needs to be based on the risk there.

What is most valuable?

The best features Wiz Code offers are the threat vulnerability picture and view by repository.

I value the vulnerability picture and the repository view because they help me to see all the vulnerabilities we have and to prioritize them.

Wiz Code has positively impacted our organization as it helped us to maintain a healthy application security side of the company and to remediate our vulnerabilities. Since using Wiz Code, we have reduced the number of our vulnerabilities by 50%, criticals by 90%, so we are very satisfied with it.

What needs improvement?

Wiz Code could be improved by showing us the dependencies that are affecting us; if we are upgrading one dependency, it would be helpful to know if down the road that's going to cause any problems with other dependencies.

For how long have I used the solution?

I have been using Wiz Code for more than six months.

How are customer service and support?

5

What other advice do I have?

Regarding Wiz Code's AI capabilities, I think its governance and security are very good; we are satisfied with the green and red events.

I think the accuracy and reliability of output from Wiz Code is approximately 95% accurate. I would rate this review a 9.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 27, 2026
Flag as inappropriate
PeerSpot user
reviewer2780310 - PeerSpot reviewer
Specialist - Information Security at a tech vendor with 1,001-5,000 employees
Real User
Top 20
Nov 21, 2025
Enables comprehensive visibility into cloud risks and supports tailored compliance reporting across teams
Pros and Cons
  • "What I appreciate most about Wiz is that the compliance and CSPM aspects of this cloud-native application protection offering are genuinely better than other products available in the market."
  • "I have seen some lagging or downtime a couple of times, but I am not sure why it happened."

What is our primary use case?

My use cases for Wiz mostly revolve around cloud security posture management, compliance, internal opex reporting, and shift-left security tooling, centered around compliance and cloud security shift-left.

What is most valuable?

What I appreciate most about Wiz is that the compliance and CSPM aspects of this cloud-native application protection offering are genuinely better than other products available in the market. Having worked on Prisma, Orca, and Qualys as well, when I compare Wiz with everything else, it definitely has an edge. The graph queries and graph explorer in Wiz are exceptionally well done by their team, giving me a complete view of resources, how they relate to other resources in the account or in other accounts, and how they pose an external threat or risk.

I have created boards in Wiz for internal projects and teams depending on what product line it is, and I have tried creating custom dashboards. My experience with creating custom dashboards is that it is neither easy nor difficult; it is somewhere in between. Obviously, it is not the same as Power BI or any other visualization tool, so I understand it will not be at that level, but it gets the job done. I get a high-level overview of trends of the findings or non-compliant items, and it accomplishes what I need. I also do not expect it to be at that level because that is not what it is built for.

What needs improvement?

I really cannot think of anything that Wiz can improve, because the use cases I deal with have almost all features that cater to them, so I really do not have anything in mind right now.

One thing Wiz can do better is regarding support for the open-source fork of Terraform called OpenTofu. Many organizations are moving from Terraform to OpenTofu to save costs in licensing, but their documentation does not officially state that they are supporting OpenTofu, so that would be beneficial to have. Since it is just a copy of Terraform, it should not be a difficult addition, but that would be a valuable feature.

For how long have I used the solution?

I have been using Wiz in my career for close to one and a half years.

What do I think about the stability of the solution?

I have seen some lagging or downtime a couple of times, but I am not sure why it happened. It was just a couple of times, and it did not impact what I was doing.

What do I think about the scalability of the solution?

Wiz is very scalable.

How are customer service and support?

I have contacted Wiz's technical support. The quality and speed of the support are very good; most of the time, I do get the answers I am looking for, and if not, the team works internally. If there is no feature, they raise a feature request for us, so it has been very good. On a scale from 1 to 10, I would give Wiz's support a 10.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment of Wiz is very easy for me. The first time I deployed Wiz, it took me approximately 10 to 20 minutes, depending on the availability of the other team. When they are available, I usually get it done within 10 or 15 minutes, or even less than that when we have all the prerequisites ready.

What about the implementation team?

Wiz does require some maintenance on my end, but it is minimal. The maintenance involves configuring connectors for Wiz, and it does require a few permissions for Wiz to scan the cloud accounts and other resources. That is the only maintenance needed, such as adding or updating the role in Wiz if other permissions or services introduced by the cloud provider are not covered.

Which other solutions did I evaluate?

I have used some alternatives and similar solutions to Wiz. I remember the names of those alternatives; one is Palo Alto's Prisma Cloud, and the other was Qualys' tool, which was kind of a makeshift tool, not a full-fledged CSPM, but they called it CSPM. When I compare Wiz to those tools, I prefer Wiz a lot more because it is definitely a couple of notches above all those tools. They have done much better with their UI, which is very organized, whereas Prisma is mostly a lot of acquisitions and a lot of tools stitched together and offered as a SaaS solution. Not saying it is bad, but Wiz does it better than what they have been doing.

What other advice do I have?

I personally have not worked on Wiz Runtime Sensor, so I cannot really comment on whether it has helped identify active threats more effectively compared to any other solutions that I have used. We have plans, but not yet. I would rate this review overall as a 9.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Analyst at a educational organization with 201-500 employees
Real User
Top 20
May 30, 2026
Cloud insights and AI have streamlined how I identify and verify daily vulnerabilities
Pros and Cons
  • "Wiz Code has positively impacted my organization because it is better on a daily basis; we receive new cases, and it is easy to analyze and take care of them."
  • "The dashboards can be better; we have dashboards, but they are really complex and have a lot of information."

What is our primary use case?

My main use case for Wiz Code is for vulnerabilities. I receive a specific vulnerability from some assets, and I analyze and try to verify if they are positives or false positives. In general, all of my work regarding Wiz Code involves vulnerabilities.

What is most valuable?

Wiz Code's cloud part is good; I am able to see the IDs, the assets, and the information, which in general makes it easier to find where the vulnerability is. The organization of the data helps me find where the vulnerability is; I don't really use the dashboard much.

The AI feature is the other part that I like most with Wiz Code; it helps a lot and makes it easier to search for something. For example, if I need to do some query to look up a specific vulnerability or assets, it is easier.

Wiz Code has positively impacted my organization because it is better on a daily basis. We receive new cases, and it is easy to analyze and take care of them. It made things easier in that we receive a specific vulnerability, and if I select that one, we are able to see everything regarding the vulnerability, the asset, and the owners, for example.

What needs improvement?

The dashboards can be better; we have dashboards, but they are really complex and have a lot of information.

For how long have I used the solution?

I have been working in my current field for almost three years.

What do I think about the stability of the solution?

Wiz Code is stable with no downtime or reliability issues.

What do I think about the scalability of the solution?

Wiz Code's scalability can handle growth or increased workload well.

How are customer service and support?

I have never reached out to Wiz Code's customer support, so I don't have experience with that.

Which solution did I use previously and why did I switch?

I did not previously use a different solution before Wiz Code.

What's my experience with pricing, setup cost, and licensing?

I don't have much experience with pricing, setup cost, and licensing because my company bought it, so I just use it for free.

Which other solutions did I evaluate?

I didn't evaluate other options before choosing Wiz Code.

What other advice do I have?

I think Wiz Code is pretty much better right now. I only use it for what is already specified. I don't know what advice I would give to others looking into using Wiz Code because I think we use it more for company work and I don't know how much I would use it privately since this is more a company tool. I would rate my overall experience with Wiz Code as a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 30, 2026
Flag as inappropriate
PeerSpot user
reviewer2755878 - PeerSpot reviewer
Cloud Security Engineer at a tech vendor with 11-50 employees
Real User
Top 10
Sep 10, 2025
Helps eliminate critical issues and streamline threat investigation
Pros and Cons
  • "Wiz has helped my organization achieve zero criticals in its issue queues after a month."
  • "It would be better if, when you get an alert type, you are able to view the regex or alert logic without having to dig through all the different options; it is difficult to find where the alert logic is because you have to go to the investigations and then actually find and search for the individual alert."

What is our primary use case?

I use Wiz for both my own company and other companies to detect and investigate vulnerabilities and any type of alerts that pop up. 

What is most valuable?

I am really enjoying the new Threat Detection that they have set up; it is pretty nice. I appreciate the way that it lays out the data.

For some of my customers, I create custom dashboards, charts, or counters, and they're actually really helpful. It's quite easy. They have extensive technical documentation that guides you through the process. Additionally, there are short videos available in each section that demonstrate how to do things.

Wiz has helped my organization achieve zero criticals in its issue queues after a month. 

What needs improvement?

It would be better if, when you get an alert type, you are able to view the regex or alert logic without having to dig through all the different options; it is difficult to find where the alert logic is because you have to go to the investigations and then actually find and search for the individual alert. If they just showed the alert logic, that would be really nice. 

Also, if there was an easier way for threats to convert those into issues rather than having to set up a custom rule to pull those in as issues, it would be great.

For how long have I used the solution?

I have been using Wiz for just under a year.

What do I think about the stability of the solution?

I have not seen any sort of instability with Wiz; I was curious how their SRE team works because I have not seen a single downtime.

What do I think about the scalability of the solution?

Wiz scales really efficiently; I have worked with some huge companies that have multiple clouds and thousands of workflows, and it all seems to work.

How are customer service and support?

We have account executive people that we talk to for help with Wiz. We talk to them sometimes when new features come out or when we see weird things for the first time. They provide help with writing either new regex alert queries or just helping us figure out how to do something with using the product. They are very helpful and very responsive, and if they cannot get you the answer, then they will find someone to help you; it has been as quick as a turnaround time of one business day, which is really good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used CrowdStrike, Prisma, and I think that Wiz is the best out of all of them. Wiz is good at conveying the information for the active threats. The way that it shows you is easier to understand as a human. It is about the same quality of detection, but the presentation is better.

How was the initial setup?

It's really easy. It's very user-friendly, and it's very intuitive.

My team had Wiz set up already when I joined, but I have gone through the whole setup process myself; they let me reset it up. I found that to be pretty simple. It only took about an hour and a half to install Wiz because we do not have a super big system.

Once you set up Wiz, it is good to go. As a security engineer, you need to maintain the alerts and keep that stuff moving. Once we have the system in place, I have not noticed it disconnect any of our accounts. It seems once you set it, it is good to go.

What about the implementation team?

One person can deploy Wiz; they just have to have the right access.

What's my experience with pricing, setup cost, and licensing?

I don't know how much we pay, but I do know that Wiz charges a lot. However, they're offering a good product, so it might be fair. I haven't seen the exact numbers.

What other advice do I have?

I would rate Wiz a 10 out of 10. I really like it.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Pietro Villivà - PeerSpot reviewer
Business Line Manager at S2E
Real User
Sep 16, 2024
Useful for security assessment and maintaining correct security posture
Pros and Cons
  • "The tool's most valuable feature is its attack path analysis."
  • "Not having an on-prem version can be an obstacle for customers who have a large workload in an on-prem environment."

What is our primary use case?

I use the solution for test and demo environments, and then we deploy the platform's last version for our customers. We use the advanced license type, so we have all the features in the platform.

The tool is used for security assessment and maintaining our customers' correct security posture. We have different types of customers, so there are different types of use cases. But in general, the main need is for the maintenance of cloud security posture.

What is most valuable?

The tool's most valuable feature is its attack path analysis. The feature of the tool for inspecting running containers and the new feature of intelligent artificial intelligence security posture is good. With the attack path analysis, I can see the perfect path of a possible attack, I can see the exposure of different types of resources, and I can stop the attack with the remediation or suggestion of the platform. Regarding the container runtime security, I can see how the container runs and what type of action the container takes during execution. I can take some action to modify the running of the container. For the artificial intelligence security posture, I can see the misconfiguration problem with the security permission that customers give to the platform, like Bedrock or OpenAI, and so on. We can help the customer resolve this problem of data security exposure and so on. All such features are effective in identifying vulnerabilities. The platform allows users to collect information without the need for an install agent. So it's totally agentless, and it is a great feature. I don't need to install an agent, so onboarding the platform is very easy and very speedy.

What needs improvement?

The tool keeps improving on a weekly basis. Wiz enters into a lot of partnerships with other technologies. I don't have any idea about the improvements needed in the tool at the moment.

For me, Wiz is a very complete product, but it is not the perfect one. Other technologies are better for our customers' specific use cases. A possible way to grow the tool is by introducing new functionality or features.

In the future, the tool can introduce an on-prem infrastructure or platform. Not having an on-prem version can be an obstacle for customers who have a large workload in an on-prem environment.

The onboarding can be done in five minutes or five to ten minutes. Then, there is the configuration, and it depends on the type of the use case of the customer. There is a customer that has simple use cases for whom the onboarding can be done in four to eight hours a day. If there are some customers with a lot of use cases and a lot of different cloud providers, more time is needed. In general, we don't need more than five days to deploy the tool, even in the case of a very complex architecture and hybrid cloud environment.

To deploy the tool, we need to have access to the account of the customer, and Wiz is a stuff that we need to make with the customer. We do the onboarding together. The customer creates the correct authorization in the cloud platform and gives us the key to connect to the platform, and then the platform connector starts and begins to collect information.

For how long have I used the solution?

I have been using Wiz since 2023. My company is a service integrator and a partner of Wiz. I use the solution's latest version.

What do I think about the stability of the solution?

It is a stable solution. Stability-wise, I rate the solution an eight to nine out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a ten out of ten.

I don't know the exact number of users because every customer can create a user autonomously on the platform. So, I don't have availability at the moment for the total number of users. We have five customers at the moment, and we have done a lot of PoC during the last two years. I suppose that we will have around 22 different customers. If you need a number, a minimum of 60 users use the tool.

My customers are medium and large enterprises.

How are customer service and support?

The solution's technical support was excellent. We have had excellent communication and availability for any of our needs or questions. They answer quickly, and we have had a great experience with the technical support. I rate the technical support a nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

If one is difficult and ten is easy to set up, I rate the product's initial setup phase a nine out of ten.

The solution is deployed on the cloud. In the future, the tool can introduce an on-prem infrastructure or on-prem platform, but at the moment, it is only cloud.

What's my experience with pricing, setup cost, and licensing?

If one is cheap and ten is expensive, I rate the tool's price as a five out of ten. The pricing depends on the customer and the dimension of the environment, whether the customer is strategic or not. I suppose that it is available at a middle price. In some cases, it has a very aggressive price, so very cheap, in order it's expensive. In particular, if the workload is poor, they can't make grid cells, so the price is high, and it is not in terms of real value but in terms of the budget of the customer.

What other advice do I have?

The tool can be used for all customers who don't have a security structure or security team inside because the platform is very easy to use. It is a very useful tool for developer teams that can use the platform without having security knowledge, and the platform helps the developer of code applications. The tool adapts to a use case in which there is a SOC team because of the rich data that the SOC can correlate and manage.

I recommend the tool to companies that use cloud products. Wiz can be integrated with other customer platforms because it enriches information and makes inaction very valuable in terms of security.

I rate the tool as an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
reviewer2244411 - PeerSpot reviewer
Security Architect/Staff Engineer at a consultancy with 10,001+ employees
Real User
Top 5Leaderboard
Nov 17, 2024
Streamlined cloud security integration with a powerful cloud-native application protection platform
Pros and Cons
  • "Wiz is a very powerful product technologically."
  • "We are still analyzing its behavior as we are in the midst of the implementation."

What is our primary use case?

Our primary use case is related to using Wiz as a cloud-native application protection platform. We are currently in the midst of onboarding resources and streamlining the integration of Wiz.

How has it helped my organization?

It has been user-friendly, and most of the integrations and configurations are straightforward.

What is most valuable?

Wiz is a very powerful product technologically. Our requirement is related to the CNAPP solution, which is a cloud-native application protection platform. It is user-friendly, and most of the integrations and configurations are straightforward.

What needs improvement?

I have not measured certain abilities on a scale yet. The ultimate value depends on the requirements of your organization.

For how long have I used the solution?

We are still in the midst of implementing Wiz. As such, we are still analyzing its behavior.

What do I think about the stability of the solution?

We are still analyzing its behavior as we are in the midst of the implementation.

How are customer service and support?

We still get support for at least a month by default after implementing any tool. As of now, everything is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In the past, I worked with Check Point, specifically their firewall product and RaaS VeeTrail subproducts. I no longer use Check Point products as I switched my domain from network security to application security and cloud security.

How was the initial setup?

Since we are still in the midst of implementing the new solutions within our environment, it is a work in progress.

What about the implementation team?

We are currently onboarding resources and working to streamline the implementation of Wiz.

What's my experience with pricing, setup cost, and licensing?

This feedback is not based on much experience yet, as we have only conducted POV or POC.

Which other solutions did I evaluate?

We compared Wiz with other products, such as Orca and other industry standard solutions.

What other advice do I have?

I do not want my name or my organization's name to be reflected in any of the feedback provided.

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mindaugas Dailidonis - PeerSpot reviewer
Security Solutions Architect - Cloud Security Consultant at a consultancy with 10,001+ employees
Real User
Top 5
Mar 11, 2026
Advanced security insights and comprehensive risk visibility across multi-cloud environments
Pros and Cons
  • "Wiz saves time by validating a network misconfiguration by not only looking at the cloud asset configuration but also by testing if a port that is stated to be open is actually open."
  • "We noticed some capabilities that were lacking, specifically ignoring some false-positive Issue findings. The good news - with the latest update, this has been resolved."

What is our primary use case?

We use Wiz to monitor cloud security across Azure, Oracle OCI, and Google GCP cloud environments. With Wiz implementation we aim to eliminate the security team from security findings communication and triage and allow development, cloud and infrastructure teams direct access to security configuration findings - saving time for everyone involved.

The client has around over 2000 workloads in Azure, and more than 200 in Oracle OCI, as well as small cloud presence in Google GCP.

For the initial deployment, we aim to enable good visibility across all cloud platforms (width), as well as across different levels of visibility (depth) by employing CSPM, CIEM, DSPM, EASM, CDR and other capabilities offered by Wiz. 

Going forward, we plan to implement cloud forensics feature, as well as integrate it into our CI/CD pipelines and code repositories for preventative capabilities.

How has it helped my organization?

The integration is still in its early stages, and I will continue to update this report as we move forward. That being said, everything has been excellent so far!

Wiz helped to detect multiple virtual machines in Azure and Oracle OCI cloud environments that had problems, including crypto-miners and malware. Furthermore, Google GCP usage in the company was discovered by Wiz, which the other two CNAPP tools we've tested have missed. 

We also discovered credentials stored on the disk of a virtual machine in the test/dev environment, which could potentially provide access to parts of other cloud environments if compromised (allow lateral movement).

We can confidently say that we now see the full picture of risk across our cloud environments, including internet-exposed, vulnerable (unpatched) and misconfigured cloud assets, as well as sensitive data stored in those cloud assets.

We're currently going through the process of user onboarding to enable time savings for security team and streamline the time to take action to remediate the findings.

What is most valuable?

The time savings and the many moments of "if I was building a CNAPP, this is how I would do it" were where Wiz had already implemented what I wished for. Wiz also saves time by validating a network misconfiguration by not only looking at the cloud asset configuration but also by testing if a port that is stated to be open is actually open.

The Wiz product team recognises that the world doesn't revolve around Cyber Security teams. This is evident in their emphasis on providing clear and simple remediation advice and offering explanations of the alerts, making it easy for non-security team members to understand what’s happening and why. This was one of the key criteria why Wiz has been selected over the competitors.

My favourite is the EASM/External Exposure view and overall package - full risk visibility. It allows us to prioritize, and I mean truly prioritize, what should be addressed first. We can now see cloud workloads exposed to the internet in case of critical vulnerabilities, and if these workloads hold or can access sensitive data, we can act fast and patch these workloads first, and therefore reduce our overall risk exposure time.

Another favourite feature is the ability to give feedback and quickly raise a support case, as well as the comment option for each finding in Wiz web portal. It enables simple, yet effective collaboration between security, cloud, infrastructure and development teams.

What needs improvement?

While over the past few years Wiz has improved a lot (and I mean A LOT!), there are some areas that are still lacking.

One of them is runtime security. Coverage of serverless workloads could be improved, though knowing some of the constraints on the cloud provider's side, I do understand this may be challenging. The good news is that I see these gaps being addressed in Wiz' roadmap.

The other point that didn't improve that much is built-in reports. These still have room for improvement, especially the executive summary reports. However, this is compensated by the excellent Dashboards available in Wiz web portal.

For how long have I used the solution?

I have been using this solution since June 2024. 

With two main cloud platforms fully onboarded, the integration project is still ongoing.

What do I think about the stability of the solution?

The solution is very stable. We observed a case where some of the newly introduced built-in policies caused minor discrepancies in the alert count, but the Wiz support team promptly resolved the issue.

What do I think about the scalability of the solution?

So far, so good! No issues were observed in scalability.

How are customer service and support?

Support is excellent. We had 10 to 15 TAC cases open; most are addressed, and few that remain open have updates and a clear path towards resolution.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, I used Check Point's CloudGuard (while it was still called Dome9), Prisma Cloud by Palo Alto Networks, and Microsoft's Defender for Cloud (since 2020, when it was still called Azure Security Center). I have also tested Orca Security CNAPP solution in a PoC setting for about a month.

How was the initial setup?

The setup is straightforward. There were no issues with either cloud connector that I used (Azure, OCI and Kubernetes).

What about the implementation team?

I am a consultant working on this integration - HLD, LLD, integration itself, policy review/triage of findings, and user training/onboarding. The support team has been great! From sales to customer success - it has been a smooth ride. 

What was our ROI?

The main ROI will be the time savings from not needing to write a basic remediation advisory for the dev team and then send/track it using email.

What's my experience with pricing, setup cost, and licensing?

The sizing script provided by Wiz is fairly accurate. The support team will help you accurately identify the licensing needs. We've done it, and it is spot-on.

Which other solutions did I evaluate?

We evaluated two other CNAPP solutions.

What other advice do I have?

So far, I really like the solution and the team supporting our integration.

While it's quite early for a full review, we already have the key parts functionality deployed, and I will be updating this review once the integration is finalized next year (code security for CI/CD, cloud incident response and forensics, and automation of preventative capabilities remains on our to-do list).

Disclaimer: I received a typical customer "swag" package (jumper, backpack, thermal cup) from Wiz, but I can confidently say it had no influence on the content of my review of the CNAPP solution.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 11, 2026
Flag as inappropriate
PeerSpot user
reviewer2129682 - PeerSpot reviewer
Senior Information Security Engineer at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Feb 19, 2026
The dashboards are easy to read and visually pleasing, so you can understand everything quickly
Pros and Cons
  • "The automation roles are essential because we ultimately want to do less work and automate more. The dashboards are easy to read and visually pleasing. You can understand things quickly, which makes it easy for our other teams. The network and infrastructure teams don't know as much about security as we do, so it helps to have a tool that's accessible and nice to look at."
  • "The reporting isn't that great. They have executive summaries, but it's only a compliance report that maps all current issues to specific controls. Whether you look at one subscription or project, regardless of the size, you will get a multipage report on how the issues in that account map to that control. Our CSO isn't going to read through that. He won't filter that out or show that to his leadership and say, "Here's what we're doing." It isn't a helpful report. They're working on it, but it's a poor executive summary."

What is our primary use case?

When we first purchased Wiz in 2022, our goal was to identify vulnerabilities in our cloud environment, including misconfiguration and other issues. It was also useful in identifying inactive resources that we can terminate to save money.

It also helps us automate some minor tasks that we don't want to do manually, such as forwarding issues to the appropriate teams. Wiz has various workflows to route the vulnerabilities it discovers to the right teams. We integrated it with ServiceNow, enabling us to send ServiceNow incidents to the teams. We can also send Azure DevOps work items to developers.

Fast forward to 2026 and Wiz has exploded in capabilities, and we are now leveraging it for much more than just CSPM. Specifically, we now have it scanning our GitHub and ADO repos as well as integrating directly with GitHub and Terraform Cloud for gating mechanisms. Specifically, we can define what type of behavior (IaC misconfigurations, secrets exposure, vulnerabilities) is acceptable in our environment and prevent anyone from violating that behavior. I am hoping to begin also using Wiz for drift detection and prevention.

More recently, Wiz released a unified vulnerability management (UVM) solution following their acquisition of Dazz. While this is certainly a need of ours, and while I was able to POC this within Wiz and appreciated the insights it provided, we have already signed a contract with another vendor. This is something we would like to explore in the future as Wiz matures in this area. We have also begun using CrowdStrike's cloud workload protection rather than Wiz's. This is also an area we intend to explore in the future.

How has it helped my organization?

Wiz helps us reduce and manage our issues. Six months ago, we had no idea where we had problems in the cloud. We used another tool, but we still didn't know where most of the issues were. Wiz made it so easy to see from a high level. 

Before adding any projects, it showed us all the open issues we needed to fix. It started with the big ones because Wiz groups the issues by control. For example, you can see you have 100 issues under one control, so you start by trying to fix that. We can fix these 100 issues across all accounts by fixing one control.

Maybe we can put in some guardrails or prevent people from doing something problematic using CI/CD. Wiz helps us identify issues, prioritize them, and determine which ones should be resolved globally. 

If something can't be fixed at the highest level, Wiz can automatically send it to the appropriate teams. Wiz enabled us to define a structure for routing issues to people. We add a set of AWS accounts to a project and make them owners, so automation rules can be defined to send tickets to all project owners. That functionality helps us get the tool to operate.

Wiz is like a blind spot detector. You don't know what you don't know, so all I know now is what Wiz tells me. We don't leverage any native AWS features, so we rely solely on Wiz now. We're heavily in the cloud, but we still get our feet wet with it and ensure it's set up correctly. 

Wiz was the first tool we used to determine what we should look at and fix. We are notified when people do things they shouldn't, and employees are taking more responsibility for that. People are more conscious about what they put in their AWS accounts. 

Employees know they're being monitored and are responsible for it at the end of the day. Our InfoSec team will see it and ping them about it. They'll also see it when they get a ticket for the issue that they need to fix. It helps to create a secure-by-design mindset.

Addressing blind spots gives us peace of mind because we know that what we're doing makes sense. We can implement guardrails, understand why people continue to do things wrong and discover ways to prevent the problem from happening. It helps us develop best practices.

Wiz hasn't reduced the staff we need, but it has automated many tasks. It has built-in integration with other tools we can leverage by configuring automation rules. You don't need an external automation solution or a SOAR platform because you can do everything with Wiz's native tools. 

It allowed us to decommission a cloud security tool that wasn't working well. Besides that, we haven't consolidated much because we don't have many other cloud tools. I expect a tool like Wiz could replace a traditional vulnerability scanner, like Rapid7. I prefer it over something like that. However, there will always be a use case for a traditional on-prem vault scanner for desktops, firewalls, and other hardware that doesn't have agents on it. 

We still need an endpoint detection tool and a traditional vault scanner. But if we were using other cloud security tools like Divvy and Lacework, we could have consolidated both of them into this.

What is most valuable?

The automation rules are essential because we ultimately want to do less work and automate more. The dashboards are easy to read and visually pleasing. You can understand things quickly, which makes it easy for our other teams. The network and infrastructure teams don't know as much about security as we do, so it helps to have a tool that's accessible and nice to look at.  

It's easy to see what needs to be fixed, which is crucial for the other teams. We are trying to adopt a comprehensive governance approach. The security team isn't necessarily responsible for fixing the problems, but we are responsible for ensuring they get fixed. We need to route things to the infrastructure team, and it's straightforward for them to find everything on the dashboard.

Wiz lets you group AWS accounts logically into projects. We have AWS accounts associated with an application, so we create a project named after that application, and the project owners will receive any related incidents. It's easy to identify who's responsible. It requires some configuration, but it's handy. 

They have a security graph with a point-and-click interface, so you can click the resources you want to search for. If you aren't sure what you're looking for, you can click through. You open the little browser, and it says "EC2 instance." When you click on that, it populates several other options. You see that the EC2 instance has a network interface and click it. That has a public IP, so you can start granularly filtering down using the security graph. 

I can use the security graph for threat hunting and identifying resources. I can click on a virtual machine and see it has been detected. I have AWS and VMware integrated so that I can see more than just our cloud environment. It provides visibility into the VMware environment. I can drill down further based on a specific project or subscription. I can see all the VMs in a particular project if I want. If I do that on our infrastructure project, it changes the results, and now I see around 800 VMs in this project.

It helps you understand the resources associated with individual projects. You can do that at the subscription level and narrow it down. It will show you that one project uses S3 buckets and another has VMs. You can determine if assets are active or inactive. It's a valuable tool. 

They have a new inventory feature that allows you to detect and classify technologies. For example, let's say a Linux server has an FTP application installed, but we're not supposed to have those on our Linux servers. You can mark it as unwanted. Wiz has controls triggered when you classify something as an unwanted technology, so it generates incident reports for your projects based on what you've specified in the inventory. If I say FTP is undesirable, it will detect that on resources and send tickets to the appropriate teams notifying them to fix it.

I like the features for managing SLAs. You can define SLAs, set due dates, and use the security graph to see if any SLAs are due soon. I also think they do an excellent job with SSO implementation. Using SAML role mappings, we can integrate Wiz with our identity provider and set it up based on different groups. It's simpler to manage user access. We don't need to do all that manual stuff no one wants to do.

The ability to scan every layer without agents is a huge selling point because we're multi-agent. We are heading in that direction, so it's vital to have something that works that way. We use agents where necessary because we've got endpoint detection and response. We have a vulnerability scanner that isn't agent-based. Reducing the number of agents, we must maintain on servers or desktops is essential. They fall a bit short when it comes to performing on-demand scans. However, I don't think that's their goal.

I don't think Wiz wants people to come in and click "scan now." In some cases, having more frequent scanning than what they currently have would be helpful. It is a little confusing to understand which scanner does what. They have disk and data security scanners that scan buckets and a dynamic scanner that scans other things. I don't know which scanner is doing what or if they all follow the same schedule. I don't think we could use it if it weren't agentless.

What needs improvement?

The reporting isn't that great. They have executive summaries, but it's only a compliance report that maps all current issues to specific controls. Whether you look at one subscription or project, regardless of the size, you will get a multipage report on how the issues in that account map to that control. Our CSO isn't going to read through that. He won't filter that out or show that to his leadership and say, "Here's what we're doing." It isn't a helpful report. They're working on it, but it's a poor executive summary.

All the other reports look great when you try to create them. I can pull a report of issues for a specific project, but it's a CSV file with findings, which isn't helpful. I expect a slick visual summary that looks like what they have on the dashboard. They spend a lot of time making the dashboard easy to understand, but you can't get that information into a report for our executive leadership. We want to show them the trends and what we're doing. It's critical for our team to demonstrate the tool's value. At the end of the year, we have to go to a meeting and show management the progress we made this year. I can only do that by going into open issues, putting them all in notepad, and taking a couple of screenshots. 

I would also like the dashboards to be customizable. They have excellent dashboards, but you can't create or customize them. At the same time, Wiz seems open to that feedback, and I think they're relatively new. They're growing fast and implementing new features quickly, so I hope this will be added soon.

A third issue is that we can't provide email notifications on connector status. Everything comes into Wiz through a connector. Our AWS environment is added as a connector, and there's no way to notify anyone if an issue is detected. We could wake up the next morning and not have any data from our AWS cloud environment because there was an issue with the connector, but no one would've known about it. I think that's something that needs to be fixed.

Wiz has room for improvement in terms of risk assessment. It has a severity meter with five levels: critical, high, medium, low, or informational. If I click on the highs, it sorts the issues by the control with the most total issues. They're all high, but it doesn't prioritize based on anything other than the number of issues that are impacted by that control. It's not a priority. It tells you you'll get the most bang for your buck if you fix this one. There's no risk score or anything like that.

For example, if a public-facing device has a significant vulnerability, it will consider that business context and label it "critical," but that's all it does. All the severity levels have the same weight. Wiz prioritizes well in terms of sorting the issues into broad categories. However, it doesn't prioritize those. I'm looking at all the highs right now, and I don't know if one of these is more impactful to fix than the other.

It helps to have an overview showing that 103 resources will be impacted if we fix this control. We can fix the control at the global level, put guardrails around it, and prevent the issue from happening in the future. You can start thinking that way, but it doesn't tell you this is more severe than other issues in the same severity category.

For how long have I used the solution?

We have been using Wiz since October 2022.

What do I think about the stability of the solution?

I've never seen Wiz go down. It sometimes loads slowly, but that hasn't happened recently.

What do I think about the scalability of the solution?

Wiz automatically scales with you. It's seamless.

How are customer service and support?

I rate Wiz support a nine out of ten. Originally, they offered support through a chat app on their website, which was awful. They recently changed to Zendesk, which has been so much better. We also have a Slack channel with some of our account team. They've been excellent.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used Lacework, but it couldn't operationalize like Wiz, and there were a lot of false positives. We found Wiz because we needed a replacement for Lacework that provided a better idea of our cloud environment.

Wiz does a better job than Lacework. It shows you what you need to fix on the front page. Lacework didn't do that as well, and it wasn't easy to automate. Once we knew what needed to be fixed in Lacework, it was difficult to forward the issue to the appropriate team. Wiz shows you what to fix and makes it easy to fix it.

How was the initial setup?

Setting up Wiz is as straightforward as you want it to be. It's easy to set up, but there's a lot to learn, and there will be more as Wiz continues to add features. Being there from the beginning was nice because I learned all about the scanners and how they worked. 

Wiz is a SaaS solution connected to AWS, Azure, and our on-prem VMware environment in our data center. We worked with the Wiz team for the most part, but the platform is easy enough to do it yourself.

We already had Lacework, so we knew what we wanted to connect. We knew we wanted to connect our AWS and Azure cloud environments. We weren't thinking about VMware during our POC. We didn't care to add VMware. Our traditional vulnerability scanners would pick up the on-prem stuff, but they added it as an integration, so we decided to evaluate it. 

I was primarily responsible for deploying the solution, but I'm not a cloud engineer, so we called on some cloud resources to assist. If it's a one-person IT team with access to the cloud environment, they could do that on their own. I don't have access to certain things in AWS, so I needed our cloud team, which is two people, but I only worked with one of them. 

Some Wiz components require on-prem hardware. The VMware connector requires an agent-based server deployment. I deployed an EC2 instance with Docker on it, and each VMware vCenter environment requires its own agent. It was easy to set up, but some on-prem infrastructure is necessary to connect to them, get the information, and push it up to the cloud.

Though Wiz is a SaaS solution, it requires some maintenance on our side. If we have issues with the connectors, they must be fixed to ensure everything is coming in properly. If Wiz makes changes requiring additional permissions that impact the connectors or they release a new feature that requires additional permissions, we need to make some manual adjustments on our end.

What was our ROI?

We almost realized an ROI. The company only operationalized Wiz in January, even though we've had the tool for a while. We went through the POC. Then we tried to figure out the best method for implementing it and getting stuff out to our teams. I disappeared for a month because I was on paternity leave, so we've had maybe half a month where teams were addressing issues Wiz raised. Our issue count isn't increasing, and we continue to enable more rules and controls. People are starting to take accountability and proactively address issues they've seen in the ticketing system. 

I think we're reaching the point where we'll see a return on investment, and we'll be there by the end of the year. We started at the cloud level and already started implementing some of the things Wiz recommended. It might not trigger an issue on the platform, but it's one of those best practices. 

We realized value almost immediately, even during the POC. We plateaued a bit in terms of the ROI because we fixed some of the low-hanging fruit. We were like, "Okay, now what do we do?" We started creating accounts and putting them in projects. We set up the ticketing and tried to figure out where things were going. That took a few months to get going, and now we've enabled some of those. As time passes, we'll start to address some of these issues globally and hopefully implement the CI/CD stuff. 

What's my experience with pricing, setup cost, and licensing?

Wiz is pretty expensive. It costs more than others in the market. For example, Lacework was half as much. We didn't get as much obviously, but it was half as much. The other platform was even less than Lacework, so Wiz is at the higher end of the market.

Which other solutions did I evaluate?

We looked at other tools like Ermetic. Rapid7 was actively pitching DivvyCloud to us. It's now called Insight Cloud SEC. We didn't evaluate that one though. We evaluated Ermetic but didn't do a POC. The company briefly tried them, and they didn't meet our expectations. Wiz is easier to use and navigate than the other solutions. 

What other advice do I have?

I rate Wiz a nine out of ten. I recommend evaluating it with a full POC, but be prepared to set up connectors and go through the entire process. You'll know if you like the tool within a month. Try it if you have the budget. 

If you're concerned about getting too many alerts from multiple solutions, I would say it depends on what you can consolidate. Not everything can be consolidated into Wiz. At the same time, Wiz mainly reports actual issues, and there isn't a lot of noise or false positives. Wiz will detect specific resources that might be exposing ports to the internet and trigger an issue on that. But that's by design. In some cases, you might have network resources that a firewall needs to have exposed to the internet in that way.

Wiz has accounted for everything, so you can configure it to ignore particular issues for a given resource. They've implemented a few ways to work around issues you don't want to address so you can clear from the interface and get people to focus on what's important.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Feb 19, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Wiz Report and get advice and tips from experienced pros sharing their opinions.