WIZ Cloud Security
Wiz is a cloud native application protection platform that provides comprehensive security for cloud environments. The service identifies risks across containers, serverless functions, and virtual machines. It prioritises vulnerabilities by analysing the entire cloud stack to help organisations remediate critical issues and ensure continuous compliance through one unified interface.
Features
- Security platform that provides comprehensive security for cloud environments
- Scan cloud environments without installing software agents
- View interconnected risks and relationships across your entire cloud
- Identify and fix critical security issues based on exploitability
- Find over-privileged accounts, enforce least privilege access
- Automatically locate and classify sensitive data stored in clouds
- Scan infrastructure code to fix issues before production deployment
- Monitor active workloads for suspicious behavior and real-time threats
- Generate audit reports standards and regulatory requirements automatically
- Give teams direct access to fix their own risks
Benefits
- Manage all cloud risks through one single dashboard
- Focus on fixing the most dangerous risks first
- Generate regulatory reports quickly with continuous automated monitoring
- Secure environments instantly without managing complex software agents
- Fix security flaws early to speed up application delivery
- Provide developers direct access to resolve their own risks
- Trace entire attack paths using intuitive visual mapping tools
- Secure confidential information across diverse cloud storage locations
- Receive real-time alerts to stop active security breaches
- Share actionable security insights across different technical departments
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 5 3 3 8 9 3 3 7 2 9 3 9 8 1
Contact
NG-IT LTD
Operations Team
Telephone: 0330 223 3915
Email: gcloud@ng-it.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Security analytics
- Governance, risk and compliance
Data security
- Information protection
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- It integrates seamlessly with Amazon Web Services AWS, Microsoft Azure, Google Cloud Platform GCP, Alibaba cloud, Oracle Cloud Infrastructure, OCI, VMWare, Linode cloud
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Continuous visibility requires active, stable connections between your cloud environment and the Wiz SaaS control plane. For real-time threat blocking or memory-resident attack detection, you must deploy the optional runtime sensor alongside the agentless core
- System requirements
-
- Requires administrative API access to your cloud environment accounts
- Needs secure port 443 access to Wiz SaaS backend
- Requires specific cross-account roles for cloud resource visibility
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
"We provide 24×7×365 email and ticketing support, with response times governed by strict SLAs.
For critical (P1) and high‑impact (P2) issues, we respond within 30 minutes.
Medium‑impact (P3) tickets receive a response within 2 hours, and standard requests (P4) within 4 hours.
All tickets raised via email, phone, or the customer portal enter our ITSM system immediately, where they are prioritised and actioned by the service desk. Our monitoring systems also auto‑generate tickets to ensure rapid response without user intervention." - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- Remote support can be provided and is priced based on each customer environment.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Wiz Academy: A self-paced online portal featuring certification tracks, video tutorials, and interactive labs for all skill levels.
Onboarding Workshops: Expert-led sessions focused on initial setup, environment connection, and establishing security baselines.
Technical Documentation: A comprehensive, searchable library providing step-by-step configuration guides and API references.
In-Platform Support: Real-time, interactive walkthroughs and tooltips that guide users through remediation tasks directly within the console.
Tailored Training: Bespoke instructor-led sessions for specialized teams, focusing on complex multi-cloud architectures or specific compliance needs.
Community Knowledge: Access to regular webinars and user forums for sharing best practices and advanced threat-hunting techniques. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Microsoft Word
- Microsoft Excel
- End-of-contract data extraction
- Upon contract termination, access to the SaaS interface and API is revoked. Wiz follows a standard data deletion policy, purging customer metadata from its systems after a defined retention period (typically 30 to 90 days) as outlined in the Service Agreement. Users must complete all data extraction before the subscription end date.
- End-of-contract process
- The contract expires user accounts are disabled and removed. Customer Monitoring is removed where required.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Provided to end users at onboarding project kickoff
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Our service is accessible through the Principle Networks Customer Portal, which provides a single, easy‑to‑use interface for managing your service. Through the portal, users can log and track support tickets, view all open and historic cases, update case details, and add additional information. You can also view contracts, check contract terms and end dates, manage approved contacts, and update company information. Administrators can manage user permissions and request reporting. The portal ensures customers have full visibility of their service at any time, with secure access controlled through Microsoft authentication.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- Internally, we validate accessibility through standard browser‑based accessibility tools, automated audits, and manual checks to ensure key functions such as viewing tickets, updating cases, managing contacts, and reviewing contracts remain accessible to all users. As part of our continuous‑improvement approach, we review user feedback and adjust the interface where necessary to improve clarity, readability, and ease of interaction for customers who rely on assistive tools.
- API
- Yes
- What users can and can't do using the API
-
"Key capabilities of the Wiz API include:
Custom Automation: Programmatically trigger actions such as bulk adding cloud connectors, running on-demand environment scans, or updating security policies across multiple accounts.
Workflow Integration: Ingest real-time security ""Issues"" and audit logs into third-party tools like Datadog, Jira, or ServiceNow for centralized monitoring and automated ticket generation.
Data Manipulation: Perform complex data queries to export specific risk findings, asset inventories, or compliance reports for custom internal dashboards and audit preparations.
DevSecOps Orchestration: Integrate security guardrails directly into CI/CD pipelines to automatically block non-compliant builds based on real-time API feedback.
Advanced Investigations: Feed contextual telemetry from the Wiz Security Graph into security orchestration and response (SOAR) platforms to accelerate incident investigations and containment. " - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users can tailor security policies, compliance frameworks, and risk-scoring logic. You can define custom ""Toxic Combinations"" to flag specific threats unique to your business. Alerting rules, remediation workflows, and automated reporting templates are also fully configurable.
How users can customize:
Customization is managed through the intuitive web-based console or via the GraphQL-based API. Within the console, users select from pre-defined templates or build custom queries using the Wiz Security Graph. For automated environments, Infrastructure as Code (IaC) integrations allow security guardrails to be customized directly within development pipelines.
Who can customize:
Security Administrators: Have full rights to modify global policies, risk thresholds, and compliance mappings.
Compliance Officers: Can customize reporting views and audit evidence collection parameters.
DevSecOps Leads: Can configure CI/CD guardrails and API-driven automation.
Project Owners: Can customize specific dashboard views and alerts for their assigned cloud environments using Role-Based Access Control (RBAC)."
Scaling
- Independence of resources
-
Wiz ensures consistent performance through a multi-tenant architecture designed for total isolation. The platform uses elastic scaling to automatically expand resources during peak demand. Logical resource isolation prevents one user’s activity from affecting another, while API rate limiting prevents system monopolization.
Heavy analysis is offloaded to distributed regional clusters, and decoupled data pipelines ensure the management console remains responsive during large-scale scans. These measures, combined with high-availability failover across multiple zones, guarantee a stable experience for every customer regardless of total platform load.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Principle Networks measures service performance through clearly defined SLA‑driven metrics, including rapid incident response and resolution times across all priority levels, 24×7 monitoring of device and service availability, and continual tracking of case volumes, service origins, closure reasons, and overall SLA compliance. These metrics are reviewed through structured service reports and monthly service reviews to ensure consistent first‑response performance, timely resolution, proactive issue detection, and continuous service improvement, all under an ISO 20000‑1 accredited service management framework.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- WIZ Inc.
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
API Export: Use the GraphQL API to programmatically download all security issues, asset inventories, and audit logs in JSON format.
Manual Downloads: Export specific datasets, compliance reports, and vulnerability findings directly from the management console as CSV or PDF files.
Third-party Integration: Forward data in real-time to external storage, SIEMs, or data lakes (e.g., Snowflake, Splunk, or S3 buckets) to maintain a continuous historical record.
Inventory Reports: Generate and save comprehensive snapshots of the cloud environment and its security posture - Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
-
Wiz secures data in transit using TLS 1.2+ encryption for all communications. The agentless SideScanning process ensures only resource metadata—not raw disk data—is transmitted to the SaaS console.
Connections are established using secure IAM roles or Service Principals, eliminating the need for shared secrets. Mutual authentication ensures secure communication between authorized environments and the platform. For enhanced security, private networking options are available to keep traffic off the public internet, ensuring your sensitive cloud infrastructure data remains fully protected.
Availability and resilience
- Guaranteed availability
-
We guarantee high availability across our managed services through 24×7×365 monitoring, proactive alerting, and resilient architecture. Our services operate under IS 20000‑1‑aligned service management, with strict SLAs governing response and resolution. For incident availability, we commit to a 30‑minute response for P1 and P2 incidents, with target fix times of 2–5 hours for critical issues, depending on whether the solution is resilient, hardware‑based, or dependent on third‑party circuits. Lower‑priority issues follow defined SLA timelines to maintain consistent service quality.
Where contractual availability SLAs are in place, we provide service credits if availability falls below the agreed threshold. Credits are calculated using a transparent formula based on the number of hours outside SLA multiplied by the proportional hourly service cost. This ensures customers receive fair compensation for any material downtime.
Our approach combines continuous monitoring, resilient design, rapid engineering response, and clear escalation paths to maintain service uptime and minimise disruption. - Approach to resilience
-
Wiz ensures high availability through a cloud-native, distributed architecture. The service is hosted across multiple Availability Zones, providing automatic failover if a data center fails. Its agentless SideScanning is decentralised, ensuring that local scanning continues even if the central console experiences latency.
The platform utilises elastic scaling to handle sudden surges in global demand without performance degradation. Automated backup and disaster recovery protocols ensure data integrity, while a decoupled backend separates data ingestion from the user interface to maintain responsiveness. - Outage reporting
-
Public Status Page: A dedicated, real-time Status Page provides the current operational state of all platform components and regional hosting locations.
In-Platform Notifications: Critical alerts and maintenance schedules are broadcast directly within the management console to inform active users of potential disruptions.
Email Alerts: Administrators can subscribe to automated email notifications for instant updates on service incidents, progress reports, and resolution confirmations.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
We restrict access to management interfaces by ensuring they are never exposed to the public internet; configuration access is limited to internal networks or VPN/Zscaler‑protected connections, with MFA enforced for all administrators. Only named, authorised users with role‑based access can perform changes, and all administrative access is logged and periodically reviewed.
Support channels are similarly restricted: only authenticated users on compliant corporate devices can access systems, governed by conditional access policies enforcing location, device posture, and MFA. Users must request changes through the servicedesk using verified identities, ensuring only authorised personnel can engage support functions. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
We follow a comprehensive set of information security policies that cover access control, secure configuration, encryption, incident management, risk management, acceptable use, business continuity, data handling, and secure development. These policies define how we protect data, manage systems securely, and ensure confidentiality, integrity, and availability across all services.
Our governance structure is led by the Information Security Team, with overall accountability held by senior leadership. Operational responsibility for maintaining and enforcing the Information Security Management System sits with the Head of Service Operations, supported by technical leads and policy owners.
To ensure policies are consistently followed, we use controlled documentation, mandatory annual security and GDPR training for all staff, formal onboarding/offboarding processes, and strict access‑control reviews. Compliance is reinforced through internal audits, continuous monitoring, and a defined incident‑reporting process that requires any suspected breach or security event to be reported immediately for investigation.
This structured approach ensures security responsibilities are clear, risks are managed, and policies are embedded in day‑to‑day operations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We comply with formal configuration and change‑management processes that form part of our ISO‑2000-1 aligned Information Security Management System (ISMS) and IT Service Management framework.
Our configuration management approach ensures that all assets, systems, and device configurations are documented, version‑controlled, and maintained through approved configuration baselines. Configuration changes are tracked, reviewed, and stored centrally, ensuring accuracy, traceability, and rollback capability where required.
Change management follows a structured, risk‑aware workflow. All must be requested, assessed for impact and risk. High‑risk changes follow enhanced governance, including technical peer review. Emergency changes are documented retrospectively and reviewed to ensure control effectiveness. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We assess threats through continuous monitoring, regular vulnerability scanning, and risk evaluation across all services. Threat intelligence is sourced from vendor security advisories, industry feeds, government alerts (e.g., NCSC), and community CVE databases. Patches are prioritised by severity: critical vulnerabilities are actioned and deployed as quickly as possible, typically within 24–72 hours, with lower‑risk issues scheduled into routine maintenance cycles. Findings are tracked through our internal change and incident management processes to ensure full remediation and verification.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We assess threats continuously using vendor advisories, CVE feeds, security bulletins, and monitoring tools to identify vulnerabilities relevant to our services. High‑ or critical‑risk vulnerabilities are patched proactively, typically within 24 hours where they present an immediate threat, while all other vendor‑rated high/critical patches are deployed within a 14‑day target window. Lower‑risk issues follow scheduled maintenance cycles. Threat intelligence comes from vendor notifications, industry security alerts, and active monitoring of supported platforms. This ensures rapid mitigation, stable patching, and consistent protection across all managed environments.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a defined incident‑management process with predefined workflows for common events, including priority‑based handling and a dedicated P1/Major Incident procedure with automated bridges and communication steps. Incidents are reported via email, phone, proactive monitoring alerts, or directly through the Customer Portal, all of which create a case in our ITSM system with full classification and prioritisation. We provide incident reports through post‑incident reviews, including Major Incident Reports, which are generated and shared with affected customers after resolution.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer proof of concept evaluation to a limited number of users. The proof of concept scope and term is defined based on the requirements of the customer.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 22%
- Between £500,001 and £1,000,000
- 30%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- CDL Group
- ISO 9001 accreditation date
- Tuesday 1 July 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E29042f9-0029-4a93-840f-4178125bdd61
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 76366978-ee23-40f3-80dd-8b48234414fd
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-