We've been running Prisma Cloud for a year. It does the job, mostly. The container and IaC scanning finds real issues. Cloud security posture alerts are fine.
But the bill is insane. It feels like we're paying for 100 features we don't use. The biggest issue? It's a fortress. Getting our data out or integrating with anything non-Palo Alto is a fight. Their support pushes their other products constantly.
Looking at Wiz or Lacework now. Is the "completeness" worth the lock-in and premium price? For a team that just needs core CSPM and container security, probably not. Anyone else jump ship? What was the actual cost to switch?
I'm a product manager for our internal platforms team at a mid-size fintech. We handle about 500 containers across two clouds and have used Prisma Cloud, Wiz, and evaluated Lacework.
Here's my breakdown on the core criteria you asked about:
1. **Switching Effort:** The biggest hidden cost wasn't the new license, it was staff time. Re-configuring alert rules and integrating with our existing notification channels took about 50 person-hours. You can't export your historical data from Prisma, only configuration details.
2. **Pricing Model Clarity:** We saw a 40% cost reduction moving to Wiz on a 2-year commit. Their per-resource model is more straightforward for us than Prisma's confusing feature bundles. Lacework was priced competitively with Wiz in our quote. The pain is you'll re-run a full PoC to get accurate numbers.
3. **Core Functionality Parity:** For CSPM and container vulnerability scanning, Wiz had 100% feature parity for our needs. Prisma's value is in its network security modules (firewall analysis, flow logs), which we never touched. If you don't use those, you're paying for them.
4. **Vendor Relationship:** Support responsiveness dropped noticeably for us after onboarding. As you said, feature requests were often met with pitches for their other products. Our account team at Wiz has been more focused on the actual platform we bought, though it's still early days.
My pick would be Wiz for your stated use case of core CSPM and container security. The platform felt modern, the API is open, and the cost was justifiable. The deciding factor is how much you value a truly agentless architecture - if that's critical, Wiz wins. If you have a heavily containerized workload and want deep runtime protection beyond vuln scanning, tell us more about that need, as Lacework might be worth another look.
Reviews build trust.
That 50 person-hour estimate for reconfiguring alerts is really useful. We've only looked at the surface costs. Did you find the alert logic itself was portable, or did you have to rewrite everything from scratch against the new vendor's schema?
The fortress analogy is accurate, especially for data egress. We hit the same wall trying to pipe findings into our internal risk dashboard. Their API rate limits and schema are designed to keep you inside their console.
Your point on paying for unused features is the central economic problem. The "completeness" you're paying for includes agent-based workload protection and serverless scanning layers that add operational overhead if you don't need them. For a shop focused on core CSPM and container registry scanning, a more modular toolset can reduce both cost and cognitive load.
The actual switching cost often includes re-baselining your alert thresholds because each platform's risk scoring algorithm is a black box. You'll lose your historical "signal vs noise" tuning.