WIZ Cloud Infrastructure Security Platform logo

    WIZ Cloud Infrastructure Security Platform

    Sold by
    Wiz provides an entirely new approach to cloud security that for the first time identifies the actual risks hidden in your cloud infrastructure.

    Ratings and reviews

    4.7
    889 ratings
    2 star
    1 star
    82%
    17%
    1%
    0%
    0%
    29 AWS reviews
    |
    860 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (889)
    Sonaansha Sonaansha

    Centralized cloud risk visibility has transformed how our team prioritizes and remediates issues

    Reviewed on Sep 11, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Wiz for around six months. My main use case for Wiz is cloud security visibility and risk management, as I use it to identify misconfigurations, vulnerabilities, and potentially security risks across a cloud environment. Having this information in one place makes it easier for the security team to prioritize issues and focus on the risks that need attention first.

    An example of how my team uses Wiz for risk management or visibility is identifying a cloud resource with a security misconfiguration and prioritizing it based on the associated risk. Instead of manually checking every resource, the team can quickly see the issue, understand its potential impact, and route it to the right team for remediation, making the review process much more efficient.

    I also use Wiz as a central point for getting an overall view of the cloud security posture. It helps us bring different security findings together, prioritize the important risks, and give us a clear picture of where attention is needed. The centralized visibility is probably the biggest benefit for all of us.

    Wiz is primarily used in our public cloud environment, having integrated with a cloud account so the team can get centralized visibility into configurations, vulnerabilities, and security risks across the environment without managing separate tools for each account.

    Wiz has helped us consolidate some of our cloud security workflows into a single platform, making it easier to prioritize critical risks because we can see the related findings and context together instead of switching between multiple tools. It reduces the noise and helps the team focus on issues that have the greatest potential impact.

    The runtime sensor has improved our visibility into active threats by providing more context around what is happening in the environment, making it easier to distinguish active threats from lower findings and focus the team's attention on threats that require immediate investigation compared to previous solutions.

    What is most valuable?

    The best features Wiz offers include centralized cloud visibility, risk prioritization, and the identification of misconfigurations and vulnerabilities. I also appreciate how Wiz connects different findings and provides context around the potential impact, making it easier to focus on the issues that actually matter instead of treating every alert the same way.

    The feature that has made the biggest difference for our team is centralized cloud visibility, as it gives us a much clearer view of our overall security posture and helps us quickly identify which sources have the highest priority risks. This saves time compared to manually referring to different cloud environments and security findings separately.

    I appreciate that the features work together rather than operating as completely separate tools, as the combination of visibility, risk context, and prioritization makes it easier for the team to understand what needs attention first. It keeps the security workflow relatively simple while still providing a good level of detail.

    Overall, Wiz has a positive impact on our organization by improving our visibility into the cloud environment and making it easier to identify and prioritize security risks. The centralized view has also helped the team spend less time manually viewing findings and focus more on addressing the issues that have the greatest potential impact.

    What needs improvement?

    Wiz is already quite strong, but the platform could be made even easier for new users with more guided workflows and simpler explanations of some of the more advanced findings. I would also like to see further improvements in reporting and customization so the team can tailor dashboards and reports more closely to their specific needs.

    One area I would like to see improved is the user experience around complex findings, as having more contextual guidance on why an issue is important and the recommended remediation steps would make it easier for newer team members to act on findings. More flexible reporting and dashboard options would also be useful.

    What do I think about the stability of the solution?

    Overall, I have found Wiz to be stable and reliable in day-to-day use, consistently providing visibility across our cloud environment without experiencing major stability issues. The platform has been dependable for monitoring security posture and keeping track of risks over time.

    What do I think about the scalability of the solution?

    I rate Wiz's scalability quite positively, as it works well as the cloud environment grows and makes it possible to maintain visibility across multiple accounts and resources from a centralized platform, making it easier for the security team to scale monitoring and risk management without significantly increasing the manual effort.

    How are customer service and support?

    Overall, I have had a positive experience with Wiz customer support, as the team has been responsive when I needed help with configuration or understanding specific findings. Their guidance has helped me resolve questions faster, although the response time on more complex issues could sometimes be improved.

    Which solution did I use previously and why did I switch?

    I previously used CrowdStrike as a cloud security solution, but I was not finding it working according to my needs, so I needed to switch. I chose Wiz, which has been more efficient and has been working very well.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing for Wiz has been fairly straightforward, as the setup was relatively smooth once the cloud environment and integrations were configured. The licensing model was easy for me to understand, with the overall cost feeling reasonable considering the visibility and security coverage Wiz provides across the cloud environments.

    What was our ROI?

    While I have not calculated a formal ROI with specific financial figures, the overall impact of Wiz has been positive, as it saves time by bringing cloud security findings and context into one place and reduces manual investigation and prioritization. It also helps the existing team work more efficiently without needing additional resources just to manage cloud security visibility.

    Which other solutions did I evaluate?

    I evaluated a few other cloud security platforms before choosing Wiz, mainly comparing them on cloud visibility, risk prioritization, ease of deployment, integrations, and overall usability. Wiz stood out because it provided a more centralized view of our cloud environment and made it easier to understand and prioritize the risks I was seeing.

    What other advice do I have?

    While I have not formally measured the impact with specific numbers, the time savings from using Wiz are noticeable, as it reduces the amount of manual effort needed to view cloud resources and prioritize findings. The team can get context around the risks much faster, helping us respond to important issues most efficiently.

    Wiz has reduced alert fatigue for the team, mainly by providing better context and helping prioritize the findings that matter most. While I have not formally measured the reduction over a specific period, the team spends noticeably less time sorting through low findings and can focus more quickly on critical risks.

    I use Wiz post-sale support services when needed, which have been helpful for resolving configuration questions and getting guidance on more complex security findings. Having that support available helps our team troubleshoot issues faster, using the time I could otherwise spend figuring out certain problems on my own.

    Wiz has helped us reduce and prioritize critical issues, although we have not consistently reached zero criticals in the issue queue. Its prioritization and contextual information make it easier to identify the most important issues and get them assigned for remediation, which has improved our overall response process.

    I recommend Wiz to organizations looking for better visibility and centralized management for cloud security risks, advising that they clearly define their cloud accounts and security priorities before deploying it. The platform can surface a lot of information, so taking time to understand its prioritization features will help the team get the most value from it. I rate this product nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2866275

    Unified cloud visibility has improved risk mapping and reduces code-level vulnerabilities quickly

    Reviewed on Sep 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Wiz is being tested to compare against Checkmarx, examining scanning capabilities, native visibility, ease of deployment, and code-level analysis. The proof of concept has completed, and we had interaction with the user interface, gaining the ability to use some of the features and functionality of Wiz. The scanning process was very easy, with a single pane of glass making it simple to move from one feature to another. There is significant customization involved, allowing for bespoke configuration to meet specific requirements. Wiz provided many advantages, and the proof of concept was very impressive. The interface was simple to use and quick to become familiar with.

    We were able to examine risks and vulnerabilities very easily, which was the main focus of the initiative—to identify exactly where the vulnerabilities, risks, and threats were located and to detect and identify those immediately within the framework provided. Multi-cloud risk mapping proved very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. There was immediate information available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.

    What is most valuable?

    The best feature Wiz offers is the ability to identify different threats, weaknesses, and vulnerabilities, with vulnerabilities being the main focus because that is what we have to communicate to our coders and developers. We were able to see what specific vulnerabilities contained in terms of root cause analysis, such as whether libraries needed updating, whether certain CVEs were related to those vulnerabilities, and how common those vulnerabilities were, including whether patches or fixes were available. Significant information was available that could help remediate numerous issues. Vulnerabilities identification and detection were very important; we were immediately able to see through drilling down exactly what was available in terms of remediation, whether it was possible immediately or what could be done afterward.

    In terms of posture management, it was fantastic because we could see how risks were mapped across multi-cloud infrastructure seamlessly. The threat detection algorithms and mapping prioritized vulnerabilities based on actual exposure, allowing us to see critical, high, medium, or low priorities instantly. The deployment was also very easy.

    Wiz has positively impacted our organization with improved remediation speed and efficiencies in terms of time saved, as well as reducing false positives. We are currently conducting deep code scanning alongside posture management, and we have seen improvements and efficiencies in both areas. Final metrics have not been established, and I am certain that will be completed in October once analysis is finished. However, the initial findings and recommendations are very positive, indicating benefits in time saved and efficiency, as well as economies of scale in performing tasks more easily and quickly while eradicating false positives and achieving a clearer picture of real vulnerabilities.

    Wiz has met my expectations in terms of accuracy and reliability of output, with the co-pilot functionality being very good. The assistant services from AI exceeded what I had anticipated. Although the full range has not been tested, my experiences, along with my colleagues', have been very impressive regarding the outputs generated by AI.

    What needs improvement?

    While Checkmarx may perform better in some deep code scanning aspects, Wiz is considerably easier to use, has a better user interface, and offers a more compelling argument for its use. It is more robust and stable, making these positive points quite clear. The only slight negative is its scanning capability compared to Checkmarx, but it is still very good. Additional comments regarding needed improvements around scanning capabilities or any other area where Wiz could catch up to Checkmarx are not necessary.

    For how long have I used the solution?

    Wiz has been used for a proof of concept over the course of a few weeks. A decision regarding adoption will be made by our company based on the findings and recommendations from the participants in the proof of concept initiative.

    What do I think about the stability of the solution?

    Wiz is stable based on proof of concept experience, and it is certainly much more stable than Checkmarx.

    What do I think about the scalability of the solution?

    I am very impressed with Wiz's scalability. We began with 50 licenses and quickly increased that number to 200. It was efficient in scaling up. While we anticipate needing in excess of 200 licenses moving forward, we are confident Wiz can handle that demand.

    How are customer service and support?

    Customer support receives a rating of 10 because we had a few initial questions, and they responded quickly and professionally, resolving all our issues regarding identity and access management in a short period.

    Which solution did I use previously and why did I switch?

    The main solution currently in use is Checkmarx. We considered switching because Checkmarx experienced several outages and failures in service delivery, prompting us to explore other options in the marketplace.

    How was the initial setup?

    During the proof of concept, there was minimal interaction with other applications. There was a link to Jira and Confluence for ticket creation, but since it was a proof of concept, much of the information was dummy data. Wiz was used primarily in isolation to see how the product would function on its own, without integration with other products.

    What about the implementation team?

    Post-sale support services were not used during the proof of concept. The next step will be to collect all findings and make recommendations to senior management, who will decide whether to implement Wiz within the company.

    What was our ROI?

    A return on investment has not been technically realized yet, but efficiencies have been achieved in terms of fewer false positives and reduced analyst time on resolving vulnerabilities. These metrics will become clearer in October after assessing how Wiz performed against Checkmarx. The initial findings are encouraging, and we are optimistic about future assessments.

    What's my experience with pricing, setup cost, and licensing?

    No involvement occurred with pricing, setup cost, and licensing for Wiz since it was a free proof of concept. Approximately 200 licenses were provided for the initiative, but pricing moving forward is unknown. It is expected to be more expensive than Checkmarx; however, the overall feeling is that Wiz is the more stable and user-friendly product, strong with features and functionality, potentially favoring the decision to move forward.

    Which other solutions did I evaluate?

    The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.

    What other advice do I have?

    Multi-cloud risk mapping was very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. Significant immediate information was available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.

    The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.

    My overall rating for this review is 9.

    Hospital & Health Care

    Easy, Fast Setup with Best-Practice Templates Across Many Platforms

    Reviewed on Aug 19, 2026
    Review provided by G2
    What do you like best about the product?
    very easy and quick to set up and covers a lot of platforms and has many best practice templates
    What do you dislike about the product?
    there are a lot of tabs and the main interface is very busy
    What problems is the product solving and how is that benefiting you?
    a single view of cyber security posture of different organisations
    david z.

    User-Friendly Security Boost with Some Delays

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    I find Wiz very easy to use, which is a huge plus for me. I also like the red agent feature because it helps me to add security to my system effectively. The initial setup was very easy, which made getting started with Wiz smooth.
    What do you dislike about the product?
    I dislike that it takes 24 hours to inform me.
    What problems is the product solving and how is that benefiting you?
    I use Wiz to add security to my system. It's very easy to use, and the red agent helps in enhancing my system's security.
    Alternative Medicine

    Efficient Cloud Security Visibility with an Intuitive UI

    Reviewed on Aug 07, 2026
    Review provided by G2
    What do you like best about the product?
    Very efficient view of all cloud assets and security aspects of the infrastructure. very intuitive UI and simple integration and implementation. Onboarding was easy.
    The solution allowed us to to find and resolve issues that we would not have found or resolved without it (also thanks to the green/red agents).
    What do you dislike about the product?
    Can be a little costly when workloads grow, but still worth the investment.
    What problems is the product solving and how is that benefiting you?
    Wiz gives us a 360-degree view of all our cloud assets, including issues, vulnerabilities, and EOL components. Instead of dealing with thousands of lines of vulnerabilities and issues, it helps us focus and prioritize what needs to be fixed first. AI agents (green/red) help resolve issues and discover others that are otherwise invisible.
    Government Administration

    Wiz: agentless cloud visibility with Security Graph and truly prioritized risks

    Reviewed on Aug 06, 2026
    Review provided by G2
    What do you like best about the product?
    The most useful aspect of Wiz, in my opinion, is the agentless approach combined with the Security Graph: it analyzes the entire cloud environment via API (without installing software) and clearly maps the relationships between vulnerabilities and access.

    One of the advantages I appreciate the most is the Zero Alert Fatigue: it identifies only real risks and concrete attack paths (Toxic Combinations), minimizing false alarms.
    What do you dislike about the product?
    The aspect I appreciate least about Wiz is the high cost, calculated based on the number of resources/workloads.

    Among the main disadvantages is the complexity of the initial integration: even though the scanning is fast, correctly configuring policies, reports, and more advanced workflows requires in-depth expertise and some time to be set up properly.
    What problems is the product solving and how is that benefiting you?
    Help improve our posture and correct the misconfigurations on our public clouds.
    Austin H.

    Wiz Unified Our Vulnerability Management and Boosted Leadership Visibility

    Reviewed on Aug 04, 2026
    Review provided by G2
    What do you like best about the product?
    Wiz simplifies and unifies my vulnerability management workflows. I was able to combine Cloud Security Management and Vulnerability Management into a combined program with one product and help bring visibility to leadership and make the largest stride I have ever made in years. Not to mention the product is improving at such a rapid pace with new capabilities that help us better understand our exposure in ways I have never imagined.
    What do you dislike about the product?
    The vulnerability scanners are not full fledged and we rely on using other products connected in to get data. This is a trade off for cost and hopefully we wont need external costs longer term
    What problems is the product solving and how is that benefiting you?
    Cloud security management and Vulnerability Management. Unified and more visibility.
    Doron M.

    Clear, Actionable Cloud Risk Visibility with an Intuitive UI

    Reviewed on Aug 03, 2026
    Review provided by G2
    What do you like best about the product?
    Wiz gives me clear, actionable visibility into our cloud risks through an intuitive UI. It integrates well with our cloud environment, performs reliably, and helps engineering and security teams prioritize the issues that matter most. Onboarding was straightforward, and the context Wiz adds around each risk significantly improves our efficiency and ROI.
    What do you dislike about the product?
    Some vulnerabilities were surfaced only after they had been formally acknowledged, rather than during the earlier discussions when they were already known.
    What problems is the product solving and how is that benefiting you?
    Before Wiz, understanding our cloud security posture required significant manual work across multiple AWS accounts and tools. Wiz gives us one clear view of vulnerabilities, misconfigurations, excessive permissions, and exposed resources, allowing us to prioritize the risks that actually matter and resolve them much faster.
    Media Production

    Intuitive Wiz UI, Powerful AI, and Helpful Support

    Reviewed on Jul 30, 2026
    Review provided by G2
    What do you like best about the product?
    Wiz UI, WIZ AI, and WIZ support, Wiz grpahql makes data fetching easy. WIZ provides easy integration with different applications.
    What do you dislike about the product?
    Understanding WIZ pricing is a bit difficult.
    What problems is the product solving and how is that benefiting you?
    It helps me bring all my cloud environments and services into one place, which makes vulnerability and posture management much easier.
    Facilities Services

    Clean UI, Powerful Cloud Visibility, and a Great CLI for CI/CD Security

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Wiz is its clean and intuitive user interface, which makes it easy to navigate across projects, cloud environments, and security findings.

    The project management capabilities are especially useful for organizing assets, separating environments, assigning ownership, and tracking remediation progress.

    Wiz CLI is another major advantage because it allows security checks to be integrated directly into developer workflows and CI/CD pipelines, helping identify vulnerabilities, secrets, misconfigurations, and other risks before deployment.

    The findings are clearly presented, prioritized by risk, and supported with useful context such as affected resources, attack paths, remediation guidance, and business impact.

    Overall, Wiz provides strong visibility across the cloud environment, reduces the time required to investigate findings, and helps security and engineering teams collaborate more effectively.
    What do you dislike about the product?
    I cant open jira tickets for all the findings only for issues.
    What problems is the product solving and how is that benefiting you?
    Vulnerability and patch management,
    Perfromance increase,
    All in one product