Review Summary
See a synthesized overview of the key takeaways from verified reviews of Wiz CNAPP.
See a synthesized overview of the key takeaways from verified reviews of Wiz CNAPP.
Wiz is a company that aids organizations across various sizes and sectors to swiftly detect and eliminate crucial risks in AWS, Azure, GCP, OCI, Alibaba Cloud, and Kubernetes. This enables these organizations to develop quicker and with enhanced security.
Do You Manage Peer Insights at Wiz?
Access Vendor Portal to update and manage your profile.
The API first nature of the product allows us to build and maintain the system in IaC which allows us to keep our configuration up to date, and the context aware severity ensures we're only alerting teams to issues that are relevant and require their attention to resolve. The setup process allows us to take a phased approach, initially ensuring we have coverage across our estate, and then enabling additional features as our maturity grows. The code to cloud feature helps us discover the right level of the tech stack to implement the resolution, and as we gain further confidence in the product, the ability to set up auto-remediation via pull requests looks like it will be a big win for us.
- Easy to use UI/UX - Direct integration with AWS - Various lenses for security, compliance, etc
- Very intuitive UI and fast time to value - Strong graph-based context that helps connect findings across cloud assets, exposures, etc - Good visibility for cloud and k8 env.
Ignoring issues outside of the global ignore rules (i.e. using a .wiz file) feels very immature compared to the rest of the product. The IDE integration also lacks some basic features like the ability to see rule IDs to build out the aforementioned ignore rules. Ownership of repos again could do with some work, it's not easy to map repos to projects without jumping through hoops such as resource tagging rules.
- It's difficult to know which features are included in which SKU and whether or not we need them - After sales support is lackluster
- Alert and findings volume can still be high at scale, so prioritizing and noise reduction could be stronger - Some teams may want deeper customization in workflows, policy tuning and reporting