Review Summary
See a synthesized overview of the key takeaways from verified reviews of Wiz CNAPP.
See a synthesized overview of the key takeaways from verified reviews of Wiz CNAPP.
Wiz is a company that aids organizations across various sizes and sectors to swiftly detect and eliminate crucial risks in AWS, Azure, GCP, OCI, Alibaba Cloud, and Kubernetes. This enables these organizations to develop quicker and with enhanced security.
Do You Manage Peer Insights at Wiz?
Access Vendor Portal to update and manage your profile.
The API first nature of the product allows us to build and maintain the system in IaC which allows us to keep our configuration up to date, and the context aware severity ensures we're only alerting teams to issues that are relevant and require their attention to resolve. The setup process allows us to take a phased approach, initially ensuring we have coverage across our estate, and then enabling additional features as our maturity grows. The code to cloud feature helps us discover the right level of the tech stack to implement the resolution, and as we gain further confidence in the product, the ability to set up auto-remediation via pull requests looks like it will be a big win for us.
wiz builds a graph that correlates identities, data , mis configurations and vulnerabilities to show realistic attacker paths
The features we like most are the IAC code scanning that enabled us to check Terraform, CF and K8s manifests files and the ability to identify open-source libraries that are vulnerable and another feature we like most is its secret detection in the code repos and container images which helps us to prevent accidental exposure of API keys and tokens.
Ignoring issues outside of the global ignore rules (i.e. using a .wiz file) feels very immature compared to the rest of the product. The IDE integration also lacks some basic features like the ability to see rule IDs to build out the aforementioned ignore rules. Ownership of repos again could do with some work, it's not easy to map repos to projects without jumping through hoops such as resource tagging rules.
high licensing cost, especially at large cloud, scale . comes with limited runtime protection compared to full cwpp/edr solutions. requires tuning to reduce noise and fully leverage advanced features
One of the main dislikes is its price. Also, the interface, while clean, is so dense with telemetry and features that it takes a few months to understand and master.