What is our primary use case?
My use case for
Wiz is basically for overall security, focusing on vulnerability management, infrastructure security, and application security, all of that combined. I have my
AWS accounts where I run multiple services, so that's where I'm utilizing
Wiz to the core optimum, utilizing all of its capabilities. Even as an inventory management tool, I think it has been really helpful because it keeps a record of every change, making it very functional.
How has it helped my organization?
Wiz has helped me consolidate some tools, as it is not just doing the job of the security tool alone. It has good inventory management, good vulnerability management, and we do not need to invest in multiple tools. All aspects such as infrastructure, application, vulnerabilities, and the regular security scoring patterns are in-built into Wiz along with the inventory manager, which has helped us reduce one or two tools here and there.Wiz has reduced alert fatigue in my organization, as it is very accurate in terms of reporting the issues, which has definitely improved, and I don't see a concern.
What is most valuable?
The best features of Wiz that I appreciate the most include trends of security, such as how we have been getting issues reported and how frequently we are closing them, along with the capabilities to notify a user and a channel on Slack, which have all been really helpful beyond just doing its main job as a security framework.The extent to which the Wiz runtime sensor has helped identify active threats more effectively compared to other solutions I've used is significant, as it refreshes based on a schedule in terms of the latest findings. It has been pretty effective for our use case, as I keep checking for anything new reported there. We also have a ticketing mechanism attached to it, so as soon as a security issue is figured out, it creates a ticket on
Jira, allowing us to keep track of issues, and it is pretty responsive in terms of catching the latest issues.Wiz has helped me achieve zero criticals in issue queues, as it detects a range of issues whether it is the end of life of a product or an actual security issue, such as an exposed port or a compromised service.
What needs improvement?
In Wiz, the areas that have room for improvement would include some autonomous capabilities, such as having an agent declare where, since we are in the era of AI, it can auto-solve some low or medium alerts. High and critical issues would still need manual handling, but some level of alerts being handled autonomously would be good. More or less, Wiz is doing well, but the false alerts at random times would be another area for improvement. I would also appreciate seeing it go deeper on the security aspect, expanding beyond just infrastructure and application to include potential issues stemming from APIs, as currently it focuses more on the infrastructure pieces. Having more visibility in API endpoints, microservices, and application code running on the infrastructure would be beneficial.
For how long have I used the solution?
I have been using Wiz for the past 18 months.
What do I think about the stability of the solution?
The stability of Wiz has been good, with no downtime, bugs, or glitches. Just today I was not able to load it, but I wouldn't blame it that much as I have always been able to access the application when reaching out. I would rate the stability out of 10 as about nine or 10.
What do I think about the scalability of the solution?
Wiz is scaling well for our use case, so I would rate scalability a 10 out of 10.
How are customer service and support?
I would rate technical support as about nine, as we had a couple of cases where the responses were delayed quite a bit, but apart from that, they have been spot on.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I cannot name the vendor I used previously, but the reason for switching to Wiz was the added features that we were getting, which offered more control on cloud security.
How was the initial setup?
The deployment process of Wiz was easy and not complex. It was fairly straightforward, honestly. The internal configurations took time due to the different applications we have, but I don't think there was any delay from the Wiz side.It took about three to four weeks to deploy Wiz, as the time taken was more about how we wanted to structure the projects and boxes inside Wiz from our perspective. We were operational from the first week and integrated with
SSO projects by the third or fourth week.
What about the implementation team?
The integration capabilities of Wiz were generally seamless, although we had some complications with Oracle accounts. Integration with
AWS was pretty straightforward, but with
Azure and Oracle, Oracle had some limitations regarding what it could report to Wiz. However, I think there was some more fine-tuning and adjustments done by the Wiz team to ensure Oracle could also be onboarded correctly, so that worked out.
What was our ROI?
The purchase of Wiz was a direct purchase rather than through the AWS marketplace or a partner purchase.
What's my experience with pricing, setup cost, and licensing?
My thoughts on the pricing of Wiz is that for our use case, it has been moderate, as I was using a different tool earlier, so it's not been a very large jump. I would say it resides in that moderate zone, and it's not something that raises eyebrows, so I think we're good.
Which other solutions did I evaluate?
I would say Wiz is in the top tier, and it might just be the leading product as well. While there are a couple more products out there, I think Wiz is definitely leading the course at this point.
What other advice do I have?
I have created some custom dashboards, charts, and counters, and I have created some custom reports that are sent out, including a lot of widgets for my reporting of all the accounts that I have. I have almost seven to eight accounts where very large workloads are running, and in total, there are almost 20 accounts, so it gives a very good view to summarize all of the accounts in one place.My business is a medium enterprise with about 5,000 employees.The maintenance of Wiz is fairly easy, with a few people looking into it, but it's not as though their whole time is dedicated to Wiz, which is a good part.I absolutely recommend Wiz to other users because of its ease, features, and user-friendliness, allowing anyone to come in, configure all the things they want out of Wiz, and start using it. There is no doubt about that. I would rate this review an 8 out of 10 overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)