M
Mid-Market (51-1000 emp.)
"Clean UI, Strong Cloud Visibility, and Great CLI for CI/CD Security"
What I like most about Wiz is its clean and intuitive user interface, which makes it easy to navigate across projects, cloud environments, and security findings.
The project management capabilities are especially useful for organizing assets, separating environments, assigning ownership, and tracking remediation progress.
Wiz CLI is another significant advantage because it allows security checks to be integrated directly into developer workflows and CI/CD pipelines, helping identify vulnerabilities, secrets, misconfigurations, and other risks before deployment.
The findings are clearly presented, prioritized by risk, and supported with useful context such as affected resources, attack paths, remediation guidance, and business impact.
Overall, Wiz provides strong visibility across the cloud environment, reduces the time required to investigate findings, and helps security and engineering teams collaborate more effectively. I can't open jira tickets for all findings, only for issues. Vulnerability and patch management, performance increase, all-in-one product.
M
Mid-Market (51-1000 emp.)
"Strong Attack-Path Visibility and AI Querying, but MCP and Jira Traceability Need Work"
Wiz excels at cloud security posture visibility and attack path analysis. It clearly shows the full access path from the internet to internal resources—not just alerts, but actual exploitable paths. We have it integrated with AWS, GCP, GitHub, and Jira, and the integrations work smoothly for tracking findings through to remediation.
The MCP integration with Claude AI is a standout feature—we can query security findings in natural language in real time, saving significant time compared to manually navigating the console. Asking 'is this asset exposed to the internet?' and getting an immediate, accurate answer with full network path details is genuinely useful. The MCP API connection can drop mid-response when querying large datasets—for example, querying all HIGH/CRITICAL findings across the environment (140,000+ results) caused timeouts. Filtering options help, but better handling of large result sets would improve the experience. VPC Flow Logs visibility could also be featured more prominently in the UI when they are disabled, as this is an important gap for network traffic auditing. Additionally, reverse-lookup from a Jira ticket number to the corresponding Wiz resource is unreliable—sometimes the linked asset cannot be found, which breaks the traceability workflow between ticketing and security findings. Before Wiz, we lacked unified visibility across our AWS and GCP environments—we couldn't easily tell which assets were internet-exposed or had exploitable attack paths without waiting for external penetration test results. Wiz solved this by providing continuous, agentless scanning with clear attack path visualization. Since integrating Wiz with Claude AI via MCP, our security team can query findings in natural language in real time, significantly reducing the time spent navigating the console manually. This has shifted us from reactive (finding issues only during annual pentests) to proactive security posture management.
"Effortless Setup and Comprehensive Cloud Visibility"
Agentless, quick to deploy, and hassle-free. The best part: it doesn't overwhelm you with alerts—it highlights real attack paths, so you know what to prioritize. The AI features are intriguing and likely in high demand—Mika answers complex security questions and generates reports in plain language, and the new agents (Green, Red, Blue) indicate the direction of the platform. Licensing for WIZ Cloud and WIZ Code is a weak point—it's inflexible and not transparent enough, and determining what you need (and its cost) takes more effort than necessary.
Reporting could be more flexible. Also, you can't assign owners to fix vulnerabilities, making remediation harder to track. A single clear view across our cloud, with noise filtered out, allows a small team to focus on critical risks—less manual searching, faster fixes.
"Wiz Provides Clear, Actionable Multi-Cloud Risk Visibility with Fast, Agentless Setup"
One of the things I value most about Wiz is how it simplifies cloud security visibility across complex environments. The platform provides an intuitive way to identify critical risks, correlate vulnerabilities, misconfigurations, exposed secrets, and toxic combinations—all in a single view.
What stands out is the agentless approach, rapid deployment, and the ability to prioritize issues based on real impact rather than just alert volume. It helps security and infrastructure teams focus on what truly matters—the support was excellent while integrating with our VUL Platform.
The graph-based visualization and contextual risk analysis make investigations much easier, especially in multi-cloud environments. Wiz has significantly improved operational efficiency and collaboration between security, cloud, and DevOps teams.
A modern platform that makes cloud security management far more practical and actionable.
Also, their AI mode helped us a lot with vulnerabilities and affected systems. I can't find any issues with Wiz at this moment; their performance is excellent. Wiz solves one of the biggest challenges in modern cloud security—lack of visibility and context across multi-cloud environments.
Instead of security teams working across multiple disconnected tools, Wiz brings vulnerabilities, misconfigurations, exposed secrets, malware risks, identities, and cloud configurations into a single platform with clear risk prioritization.
What benefits me most is:
• Faster identification of critical issues that actually matter
• Better visibility across AWS, Azure, and GCP environments
• Reduced alert fatigue through contextual risk analysis
• Easier collaboration between security, cloud, and infrastructure teams
• Agentless deployment, making onboarding and scaling much simpler
The security graph and attack path visualization are especially valuable because they help quickly understand how separate low-risk findings can combine into a real business risk.
Overall, Wiz helps move from reactive security operations to proactive cloud risk management with much better efficiency and clarity.
"Wiz Delivers Unified Multi-Cloud Visibility with Executive-Level Security Insights"
What I appreciate most about Wiz is how it transformed cloud security from a fragmented, reactive process into a unified, strategic business enabler. As Co-founder of Cysfera, I value platforms that enable faster movement without compromising security, and Wiz does exactly that.
The visibility Wiz provides across multi-cloud environments is outstanding. It enables security, DevOps, and engineering teams to understand risks in context, prioritize what truly matters, and remediate issues promptly. Instead of being overwhelmed by alerts, we get actionable insights tied to actual business impact.
Another major differentiator is the simplicity of deployment and usability. Wiz delivers enterprise-grade security without creating operational friction, which is crucial for growing companies and modern cloud-native environments.
From a leadership perspective, Wiz helps align security and innovation. It gives executives confidence that the organization can scale securely while maintaining agility and operational efficiency. Nothing! It's an amazing product, and I recommend it to all customers worldwide. Wiz solves one of the biggest challenges in modern cloud environments: gaining complete visibility and prioritizing real security risks across complex, multi-cloud infrastructures.
Before Wiz, security teams often dealt with fragmented tools, alert fatigue, and limited context between vulnerabilities, identities, workloads, and cloud configurations. Wiz consolidates all this into a single platform that provides contextual risk analysis, allowing teams to focus on the issues that genuinely matter instead of wasting time on low-impact alerts.
For us at Cysfera, this translates into faster threat detection, better risk prioritization, and improved collaboration between security and engineering teams. It helps reduce operational overhead while increasing confidence in our cloud security posture.
Another key benefit is enabling the business to scale securely. Wiz allows us to accelerate cloud adoption and innovation without adding unnecessary friction to development and operations. From an executive perspective, that balance between agility and security is extremely valuable.
S
Senior Security Engineering Manager
"Wiz Consolidated Our Vulnerability Management and Improved Leadership Visibility"
Wiz makes my vulnerability management workflows simpler and more unified. I managed to merge Cloud Security Management and Vulnerability Management into a single program with one product, providing leadership with visibility and achieving the most significant progress I've made in years. Plus, the product is advancing rapidly with new capabilities that give us insights into our exposure I never imagined. The vulnerability scanners aren't fully comprehensive, so we depend on other connected products for data. This is a cost trade-off; hopefully, we won't need external tools in the long run. Cloud security management and vulnerability management, unified with better visibility.
"Actionable Cloud Risk Visibility with an Intuitive Interface"
Wiz provides me with clear, actionable visibility into our cloud risks through an intuitive UI. It integrates smoothly with our cloud environment, performs consistently, and helps engineering and security teams prioritize the issues that matter most. Onboarding was easy, and the context Wiz adds around each risk significantly boosts our efficiency and ROI. Some vulnerabilities were only displayed after being formally acknowledged, rather than during earlier discussions when they were already known. Before Wiz, understanding our cloud security posture required substantial manual effort across multiple AWS accounts and tools. Wiz gives us a unified view of vulnerabilities, misconfigurations, excessive permissions, and exposed resources, allowing us to prioritize the risks that truly matter and resolve them much faster.
"Wiz Provides Clear Visibility into Critical Cloud Risks"
Wiz offers us visibility into risks and exposures in our cloud environment that other tools either overlook or make difficult to prioritize. The ability to quickly determine what's most important and understand the potential impact has helped us minimize time spent on noise and focus on real security issues. The main challenge is the sheer volume of information Wiz provides, which can feel overwhelming initially. It takes time to learn how to best navigate the platform and prioritize findings, especially for teams new to cloud security. Wiz helps us identify and prioritize cloud security risks before they turn into operational or business problems. The platform provides a centralized view of our cloud environment and connects vulnerabilities, exposures, identities, and resources in an easy-to-understand manner. We've also found the AI-powered insights useful for quickly grasping findings and recommended remediation steps. Overall, it has cut down investigation time and helped us concentrate on the issues that matter most to our security posture.
"Superb Cloud Risk Visibility and Fast Insights with Wiz"
The standout feature of Wiz is the deep visibility it gives us into our cloud environment. We can now easily pinpoint risks and understand how they connect to identities, workloads, exposed services, secrets, permissions, and more. It's been incredibly useful to have clear insight into which issues demand immediate attention versus those that can wait.
The graph-based approach is another significant advantage, as it doesn't just list findings but provides the surrounding context. On the integration front, we've managed to feed most of our data into Wiz. Overall, Wiz has been instrumental in helping us identify misconfigurations and exposure paths far quicker than manual methods.
Performance-wise, Wiz is very responsive. The dashboard is user-friendly, and most features load promptly. It also seems to handle sophisticated graphs and toxic combinations seamlessly.
The return on investment justifies the price. An analyst could spend days tracing a toxic combination, but Wiz identifies it within hours of implementation. This has freed up our time to focus on current priorities.
We've had minimal need to contact support, which I see as a positive. The documentation is current, and the onboarding process was hassle-free, giving us full cloud visibility in a matter of hours.
With the introduction of new AI features, it's evident that Wiz heavily integrates AI into its product. I've particularly enjoyed Mika AI; this chatbot can identify and diagnose issues and even write complex security graph queries for rapid visibility. The new Wiz green, blue, and red agents have also significantly improved our time-to-remediation for certain issues. One area that could use improvement is the SAST scanner. We've found it generates a considerable number of false positives, requiring manual review before acting on findings.
Another side effect of the agentless approach is that remediation feedback isn't always immediate. While agentless scanning offers many operational benefits, after fixing an issue, it might take until the next scan—daily in our case—before we see confirmation, which can slow down validation during active remediation.
I'd also like to see enhancements to the Wiz IDE extension. It has required authentication more often than expected, which can disrupt developer workflows when used regularly. I've noticed our developers often opt for Wiz PR comments instead.
Wiz helps us tackle the challenge of maintaining visibility and control across our ever-expanding cloud environment. Without a platform like Wiz, we'd struggle to identify exposed resources, risky permissions, secrets, misconfigurations, or toxic combinations.
The biggest benefit is prioritization. Instead of treating every finding as urgent, Wiz helps us understand which issues have the most exposure and should be tackled first. This saves employee time and focuses our remediation efforts on the most impactful actions.
Wiz's shift-left mindset is also valuable. Developers and infrastructure specialists can now see when they create a risky resource, rather than only discovering it later. By embedding security by design into our SDLC, we've noticed fewer new issues arising in Wiz, and our overall issue list is actually decreasing.
"Exceptional Security Visibility, Great Reporting, and Reliable Support"
The sheer range of security insights Wiz provides is enormous, giving us coverage that no other tool matches. The interface, though dense, is easy to navigate, and the reporting capabilities are top-notch. We managed to secure a reasonable price during negotiations, and the out-of-the-box integrations are plentiful. It also comes preloaded with knowledge of numerous regulatory frameworks, which continues to expand. Our post-sales support has been fantastic as we collaborate with them to develop an upcoming platform feature. Compared to our previous solution, Wiz is a clear upgrade, and even after just a few months in production, we've encountered no downsides. It offers me comprehensive visibility into my entire environment, covering all standard infosec aspects while also helping me meet various compliance requirements thanks to its built-in regulatory support.