What I like most about Wiz is the visibility it provides across our cloud environment. It makes it much easier to understand where risks exist and how they relate to identities, workloads, exposed services, secrets, permissions, and more. It’s especially valuable that we now have clearer insight into which issues need to be handled immediately versus later.
The graph based approach is also a big plus because it doesn’t just show findings, it shows the context around them. On the integration side, we are able to ingest most of our data into Wiz. Overall, Wiz has definitely helped us identify and follow up on misconfigurations and exposure paths much faster than we could have done manually
In terms of performance, Wiz is quite speedy. The dashboard is great to work with, and most elements open quickly. It also seems to handle complex graphs and toxic combinations with ease
The ROI justifies the price for this product. An analyst might take days to find a toxic combination, while Wiz can surface it within hours of being rolled out. That has given us more time to focus on the things that matter right now
We haven’t needed to contact support much yet, which I take as a good sign. Most of the documentation is up to date, and onboarding was smooth. We were able to get full cloud visibility within hours.
With the rollout of new AI capabilities, it’s clear that Wiz is using AI extensively in the product. I’ve especially enjoyed Mika AI. This chatbot can help identify and diagnose issues, and it can even write complex security graph searches to get visibility quickly. With the new Wiz green, blue, and red agent, we have also seen a much faster TTR for some issues. Review collected by and hosted on G2.com.
One area that could be improved is the SAST scanner. In our experience, it can generate a fair number of false positives, which means findings need manual validation before action is taken.
Another consequence of the agentless approach is that remediation feedback is not always instant. While agentless scanning has many advantages from an operational perspective, after fixing an issue it can sometimes take until the next scan cycle before it becomes clear whether the remediation was correct. In our case, this cycle is daily. This can slow down validation during active remediation work.
I would also like to see improvements to the Wiz IDE extension. It has required authentication more often than I expected, which can interrupt developer workflows when regularly using it during development. I’ve noticed our developers often rely on the Wiz PR comments instead. Review collected by and hosted on G2.com.