Wiz Go Bundle
Unified cloud visibility has improved risk mapping and reduces code-level vulnerabilities quickly
What is our primary use case?
Wiz is being tested to compare against Checkmarx, examining scanning capabilities, native visibility, ease of deployment, and code-level analysis. The proof of concept has completed, and we had interaction with the user interface, gaining the ability to use some of the features and functionality of Wiz. The scanning process was very easy, with a single pane of glass making it simple to move from one feature to another. There is significant customization involved, allowing for bespoke configuration to meet specific requirements. Wiz provided many advantages, and the proof of concept was very impressive. The interface was simple to use and quick to become familiar with.
We were able to examine risks and vulnerabilities very easily, which was the main focus of the initiative—to identify exactly where the vulnerabilities, risks, and threats were located and to detect and identify those immediately within the framework provided. Multi-cloud risk mapping proved very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. There was immediate information available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.
What is most valuable?
The best feature Wiz offers is the ability to identify different threats, weaknesses, and vulnerabilities, with vulnerabilities being the main focus because that is what we have to communicate to our coders and developers. We were able to see what specific vulnerabilities contained in terms of root cause analysis, such as whether libraries needed updating, whether certain CVEs were related to those vulnerabilities, and how common those vulnerabilities were, including whether patches or fixes were available. Significant information was available that could help remediate numerous issues. Vulnerabilities identification and detection were very important; we were immediately able to see through drilling down exactly what was available in terms of remediation, whether it was possible immediately or what could be done afterward.
In terms of posture management, it was fantastic because we could see how risks were mapped across multi-cloud infrastructure seamlessly. The threat detection algorithms and mapping prioritized vulnerabilities based on actual exposure, allowing us to see critical, high, medium, or low priorities instantly. The deployment was also very easy.
Wiz has positively impacted our organization with improved remediation speed and efficiencies in terms of time saved, as well as reducing false positives. We are currently conducting deep code scanning alongside posture management, and we have seen improvements and efficiencies in both areas. Final metrics have not been established, and I am certain that will be completed in October once analysis is finished. However, the initial findings and recommendations are very positive, indicating benefits in time saved and efficiency, as well as economies of scale in performing tasks more easily and quickly while eradicating false positives and achieving a clearer picture of real vulnerabilities.
Wiz has met my expectations in terms of accuracy and reliability of output, with the co-pilot functionality being very good. The assistant services from AI exceeded what I had anticipated. Although the full range has not been tested, my experiences, along with my colleagues', have been very impressive regarding the outputs generated by AI.
What needs improvement?
While Checkmarx may perform better in some deep code scanning aspects, Wiz is considerably easier to use, has a better user interface, and offers a more compelling argument for its use. It is more robust and stable, making these positive points quite clear. The only slight negative is its scanning capability compared to Checkmarx, but it is still very good. Additional comments regarding needed improvements around scanning capabilities or any other area where Wiz could catch up to Checkmarx are not necessary.
For how long have I used the solution?
Wiz has been used for a proof of concept over the course of a few weeks. A decision regarding adoption will be made by our company based on the findings and recommendations from the participants in the proof of concept initiative.
What do I think about the stability of the solution?
Wiz is stable based on proof of concept experience, and it is certainly much more stable than Checkmarx.
What do I think about the scalability of the solution?
I am very impressed with Wiz's scalability. We began with 50 licenses and quickly increased that number to 200. It was efficient in scaling up. While we anticipate needing in excess of 200 licenses moving forward, we are confident Wiz can handle that demand.
How are customer service and support?
Customer support receives a rating of 10 because we had a few initial questions, and they responded quickly and professionally, resolving all our issues regarding identity and access management in a short period.
Which solution did I use previously and why did I switch?
The main solution currently in use is Checkmarx. We considered switching because Checkmarx experienced several outages and failures in service delivery, prompting us to explore other options in the marketplace.
How was the initial setup?
During the proof of concept, there was minimal interaction with other applications. There was a link to Jira and Confluence for ticket creation, but since it was a proof of concept, much of the information was dummy data. Wiz was used primarily in isolation to see how the product would function on its own, without integration with other products.
What about the implementation team?
Post-sale support services were not used during the proof of concept. The next step will be to collect all findings and make recommendations to senior management, who will decide whether to implement Wiz within the company.
What was our ROI?
A return on investment has not been technically realized yet, but efficiencies have been achieved in terms of fewer false positives and reduced analyst time on resolving vulnerabilities. These metrics will become clearer in October after assessing how Wiz performed against Checkmarx. The initial findings are encouraging, and we are optimistic about future assessments.
What's my experience with pricing, setup cost, and licensing?
No involvement occurred with pricing, setup cost, and licensing for Wiz since it was a free proof of concept. Approximately 200 licenses were provided for the initiative, but pricing moving forward is unknown. It is expected to be more expensive than Checkmarx; however, the overall feeling is that Wiz is the more stable and user-friendly product, strong with features and functionality, potentially favoring the decision to move forward.
Which other solutions did I evaluate?
The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.
What other advice do I have?
Multi-cloud risk mapping was very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. Significant immediate information was available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.
The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.
My overall rating for this review is 9.
Easy, Fast Setup with Best-Practice Templates Across Many Platforms
User-Friendly Security Boost with Some Delays
Efficient Cloud Security Visibility with an Intuitive UI
The solution allowed us to to find and resolve issues that we would not have found or resolved without it (also thanks to the green/red agents).
Wiz: agentless cloud visibility with Security Graph and truly prioritized risks
One of the advantages I appreciate the most is the Zero Alert Fatigue: it identifies only real risks and concrete attack paths (Toxic Combinations), minimizing false alarms.
Among the main disadvantages is the complexity of the initial integration: even though the scanning is fast, correctly configuring policies, reports, and more advanced workflows requires in-depth expertise and some time to be set up properly.
Wiz Unified Our Vulnerability Management and Boosted Leadership Visibility
Clear, Actionable Cloud Risk Visibility with an Intuitive UI
Intuitive Wiz UI, Powerful AI, and Helpful Support
Clean UI, Powerful Cloud Visibility, and a Great CLI for CI/CD Security
The project management capabilities are especially useful for organizing assets, separating environments, assigning ownership, and tracking remediation progress.
Wiz CLI is another major advantage because it allows security checks to be integrated directly into developer workflows and CI/CD pipelines, helping identify vulnerabilities, secrets, misconfigurations, and other risks before deployment.
The findings are clearly presented, prioritized by risk, and supported with useful context such as affected resources, attack paths, remediation guidance, and business impact.
Overall, Wiz provides strong visibility across the cloud environment, reduces the time required to investigate findings, and helps security and engineering teams collaborate more effectively.
Perfromance increase,
All in one product
Powerful Attack-Path Visibility and AI Querying, but MCP and Jira Traceability Need Work
The MCP integration with Claude AI is a standout feature — we can query security findings in natural language in real time, which saves the security team significant time compared to manually navigating the console. Being able to ask "is this asset exposed to the internet?" and get an immediate, accurate answer with full network path details is genuinely useful.