Mobile & Gadgets

Common mistakes with Wiz’s agentless cloud scanner

Security teams face risks regarding roadmap neutrality following the Google acquisition attempt and must address supply chain gaps between code scanning and production. Effective posture management requires connecting identity entitlements with misconfigurations to prevent breaches.

Common mistakes with Wiz's agentless cloud scanner

The Google acquisition and neutrality concerns

Google announced an agreement to acquire Wiz for approximately $32 billion in March 2025. This all-cash deal remains under regulatory review, and Wiz continues to operate and sell as an independent company. The acquisition creates specific procurement risks for organizations that rely on AWS or Azure. If your primary cloud estate uses these competing providers, you must ask how Google ownership affects the roadmap neutrality of the Wiz platform. You should add roadmap-protection language to any multi-year commitments to ensure the product remains viable for multi-cloud environments. Competitors in the market will likely discount their prices aggressively to capture customers who worry about Wiz’s future direction under Google. Will Google prioritize its own security products over the Wiz platform once the integration is complete?

The supply chain blind spot

When security teams evaluate Wiz versus Snyk, they often ignore the massive security gap that exists between the moment code is scanned in a pipeline and the moment that code is actually running in a production environment. Wiz builds its visibility from the outside in by reading cloud provider APIs and disk snapshots. It creates an inventory of VMs, containers, and serverless functions without installing runtime agents. Snyk focuses on the developer workflow by scanning application manifests and container base images before they reach production. Neither platform verifies if the artifact deployed to production is the exact binary that passed the authorized CI/CD pipeline. This gap in build integrity allows for supply chain incidents where the reviewed code is clean but the shipped artifact is not.

The reality of cloud misconfigurations

Cloud misconfigurations cause 99% of cloud security breaches. In August 2025, UpGuard researchers discovered that a major Indian bank’s transaction data leaked across the internet because of a single misconfiguration in an S3 bucket. This same incident exposed 273,000 banking transaction records. Just weeks later in September 2025, another misconfiguration leaked 2.73 lakh NACH payment records. A critical CVE on a stopped test VM lacks the danger of a medium issue on an internet-facing production service with regulated data. Security teams often make the mistake of treating policy hygiene as separate from vulnerability management. They find many vulnerabilities but fail to realize that a misconfigured security group or an over-permissive IAM role turns a software weakness into a major breach.

The identity layer and attack paths

Cloud breaches often run through over-privileged identities instead of just open storage buckets. Effective cloud security requires identity analysis to see which principals can reach sensitive data. If an attacker compromises a service account with admin-like permissions, lateral movement becomes easy. Wiz uses a Security Graph to connect misconfigurations, vulnerabilities, and identity permissions into attack-path visualizations. Many teams fail when they treat identity entitlements as an add-on rather than the core of their posture management. You must ensure your tool connects misconfigurations, identities, and reachability into a single view of what is actually exploitable.

Agentless visibility versus runtime depth

Agentless scanning provides rapid visibility across multi-cloud estates by using APIs and snapshots. Orca Security uses SideScanning to inspect block storage, and Wiz uses optional eBPF-based sensors for Kubernetes and Linux environments. These agentless tools offer speed and low deployment overhead. However, they often lack the runtime depth found in sensor-based products. If your environment relies heavily on Kubernetes or complex container runtimes, you might miss the behavioral telemetry needed for deep investigation.

Tool Category Platform Support Key Strength Pricing
Wiz CNAPP AWS, Azure, GCP, OCI Agentless graph-based risk analysis Custom quote
Orca Security CNAPP AWS, Azure, GCP SideScanning, zero-agent deployment $50,000-$500,000+/yr
Prisma Cloud CNAPP AWS, Azure, GCP, Alibaba Code-to-deploy lifecycle coverage Custom quote
CrowdStrike Falcon XDR / CNAPP AWS, Azure, GCP Endpoint-to-workload threat detection Custom quote
Cloudaware CMDB-backed CSPM AWS, Azure, GCP, 60+ services Asset inventory + security correlation $200/mo
Tenable Vulnerability / CSPM AWS, Azure, GCP Exposure-based prioritization Custom quote
Datadog CSPM / CWP AWS, Azure, GCP Observability-native security $15/host/mo+

Competitive alternatives and pricing

The market provides many ways to address cloud security. Prisma Cloud covers the widest lifecycle from code to deployment, but it requires a 200-endpoint minimum which can exclude smaller teams. Microsoft Defender for Cloud is the natural choice for Azure-heavy estates because it integrates with Entra ID. For teams that want to avoid agents entirely, Orca Security is a strong alternative, and its pricing is often 15% to 30% lower than Wiz for equivalent scope. Datadog makes sense if your security findings must live next to your operational telemetry. Cloudaware provides a much cheaper option at $200 per month for teams that need asset inventory and correlation without enterprise budgets.

Proof of concept and remediation flows

Detection does not equal security. A common mistake is buying a CNAPP and never assigning ownership of findings to the correct engineering teams. Findings must land where fixers live, such as in Jira tickets or IaC pull requests. During a Proof of Concept (PoC), you should run a pass/fail exercise against your live estate. You should record your cloud accounts, regions, assets, and daily log volume before starting. Build a test pack containing a public storage bucket, an exposed management port, an over-permissive IAM role, an unencrypted resource, and a known critical CVE. If the tool does not push these findings into your existing ticketing workflow, the tool fails. You should check if the tool handles policy violation detection and owner assignment in plain English before you sign a contract.

Procurement and contractual safeguards

Wiz remains the product to beat, but you must buy it with acquisition-aware contract language. Vendr data from August 2026 shows that Wiz deployments have a median price of $150,000, with a range from $30,213 to $535,196. Many reviewers note that license costs increase automatically and that the platform can be expensive for mid-sized companies. Do not sign a multi-year deal without modeling your resource growth and ingestion capacity. Ensure your contract includes protections for your roadmap and multi-cloud neutrality. Test if the tool provides evidence exports with timestamps and control mapping for the specific frameworks your auditors require.