Review Summary
See a synthesized overview of the key takeaways from verified reviews of Wiz CNAPP.
See a synthesized overview of the key takeaways from verified reviews of Wiz CNAPP.
Wiz is a company that aids organizations across various sizes and sectors to swiftly detect and eliminate crucial risks in AWS, Azure, GCP, OCI, Alibaba Cloud, and Kubernetes. This enables these organizations to develop quicker and with enhanced security.
Do You Manage Peer Insights at Wiz?
Access Vendor Portal to update and manage your profile.
The features we like most are the IAC code scanning that enabled us to check Terraform, CF and K8s manifests files and the ability to identify open-source libraries that are vulnerable and another feature we like most is its secret detection in the code repos and container images which helps us to prevent accidental exposure of API keys and tokens.
wiz builds a graph that correlates identities, data , mis configurations and vulnerabilities to show realistic attacker paths
Wiz provides great visibility across multi-cloud environments and workloads without requiring agents. Its prioritization engine is excellent, correlating vulnerabilities, misconfigurations and identity risks into a single view. The UI is simple and intuitive and integrations with CI/CD pipelines and other platforms (i.e. ticketing system) makes remediation fast and efficient.
One of the main dislikes is its price. Also, the interface, while clean, is so dense with telemetry and features that it takes a few months to understand and master.
high licensing cost, especially at large cloud, scale . comes with limited runtime protection compared to full cwpp/edr solutions. requires tuning to reduce noise and fully leverage advanced features
The main challenge is cost scalability for very large environments. Some advanced compliance features require additional configuration and can be difficult for users with no prior experience with CNAPPs. Also, some work needs to be done on cloud resource categorization as Wiz engine sometimes fails to discriminate between actual virtual machines and other items/devices.