An honest view of Wiz and how it helps Cloud focused organizations
Overall Satisfaction with Wiz
We utilize Wiz for Cloud vulnerability management, its used to detect high fidelity security issues, and configuration changes/drift that can happen over time. Its great because it can be implemented in a way that allows us to see these changes as they happen without fear that something could be changed without centralized visibility. We utilize it in a self service in mind so development teams can utilize the tool to help them remediate their areas issues, while giving security and architecture teams global views.
Pros
- Global visibility
- Raising high confidence security concerns
- Access control to allow you to segment project access while simultaneously allowing central teams such as architecture and security global view.
Cons
- Its not always obvious what needs to be configured in the CSP to allow Wiz to handle advanced features
- While it is higher fidelity than most security tools, it can raise some false positives regarding external exposure.
- Wiz has helped enable us to achieve lower SLAs when it comes to vulnerability management because it can put the engineers in the tool to see the issue even for beyond CVE's but configuration issues.
- The issues Wiz raises are considered more valuable as it helps address the real risk of different configurations depending on the exposure of an asset.
We have deployed Wiz in is this manner. Adding Wiz through our central account management means we provision it just enough access to make use of the features we want to use are enabled. We can have any new accounts automatically added across our multi cloud environment improving visibility significantly and it can be done with out much assistance from any internal support teams.
We utilize the support graph to help prioritize security issues with in our environment. This helps us to have engineering attack the highest risk issues, and provides some insights into why it thinks this. It uses a combination of different configurations that increase or decrease the risk such as broad account access, external expose etc. These are all very helpful in moving toward remediation.
- Lacework, CrowdStrike Falcon and Orca Cloud Security Platform
Wiz is a solid solution over these other products, it has capabilities in all clouds that we utilize that others didn't have at the time. Its much easier to segment access than CrowdStrike as an example. Engineers quickly because familiar with the tool to help reduce the issues it was finding.
Do you think Wiz delivers good value for the price?
Yes
Are you happy with Wiz's feature set?
Yes
Did Wiz live up to sales and marketing promises?
Yes
Did implementation of Wiz go as expected?
Yes
Would you buy Wiz again?
Yes


Comments
Please log in to join the conversation