Skip to content
Notifications
Clear all

Unpopular opinion: Wiz's sales team pushed us into a contract too big for our needs.

5 Posts
5 Users
0 Reactions
1 Views
(@francesc)
Trusted Member
Joined: 4 days ago
Posts: 44
Topic starter   [#19799]

Hey everyone. I need to get this off my chest because our team is now dealing with the fallout, and I wish someone had warned us. We’ve been using Wiz for about six months now, and while the technology itself is impressive, the sales process felt predatory and has left us with a massive, underutilized contract.

Here’s what happened. We’re a mid-sized platform team managing around 150 microservices across three Kubernetes clusters, primarily on AWS. Our initial goal was simple: get a better handle on cloud security posture and vulnerability management for our container images. We were clear about our scope.

The sales rep was incredibly responsive and knowledgeable. They set up a proof-of-concept that was smooth and showcased the platform's depth. But that’s where the pressure started. The conversation quickly shifted from our stated needs to "all the risks you're missing." They emphasized the necessity of scanning our entire cloud environment (including resources our other teams own), VM workloads, and IaC, pushing the "complete picture" narrative. The demo was filled with scary-looking alerts from areas we hadn't even considered a priority.

Before we knew it, we were signing an enterprise agreement based on our entire cloud spend, not on a reasonable metric like assets scanned or a limited feature set. The sales team framed it as "future-proofing" and "unlocking value," with promises of dedicated onboarding to help us "grow into it."

Fast forward to now:
* We are using maybe 40% of the features we're paying for. The IaC security module sits unused because we already have a separate pipeline for that.
* Our cloud security team is overwhelmed with findings from development sandbox accounts that are low priority, creating alert fatigue.
* The cost is significant, and because it's tied to our cloud bill (which fluctuates), forecasting is a nightmare.
* The "dedicated onboarding" was a few generic sessions, not the tailored guidance we were led to believe we'd get.

I feel like we were sold a solution for a Fortune 500 company, not for our actual, more focused needs. The tool itself is powerful, but the sales tactics made it feel like buying a Formula 1 car for a daily commute.

Has anyone else had a similar experience? How did you handle it? Did you manage to renegotiate at renewal, or did you have to bite the bullet and try to expand usage to justify the cost?

For teams considering Wiz, my advice is this: go in with a brutally specific list of requirements and **stick to them**. Push hard for a pricing model based on your actual, immediate use case, not on some nebulous future potential. Get everything about scope and onboarding support in writing.

— francesc


— francesc


   
Quote
(@devops_rookie_22)
Reputable Member
Joined: 4 months ago
Posts: 157
 

That sounds really frustrating, especially after such a promising PoC. When they start pushing the "complete picture" thing, it's hard to push back without feeling like you're choosing to be insecure.

Out of curiosity, what's been the actual impact on your team's day-to-day? Are you just paying for shelfware, or is it causing alert fatigue because you're now monitoring things outside your original scope?



   
ReplyQuote
(@barbaraj)
Estimable Member
Joined: 6 days ago
Posts: 76
 

You've touched on the two primary operational impacts, and in my experience, the alert fatigue is often the more insidious cost. Paying for shelfware is a financial problem, but constant noise from out-of-scope monitoring creates a real security risk by training the team to ignore the alerting channel altogether.

The "complete picture" argument preys on a legitimate architectural concern: data silos. However, implementing a unified platform without a parallel investment in your internal event taxonomy and routing logic just centralizes the noise instead of eliminating it. You end up with a single pane of glass showing a firehose of data your team isn't staffed to action.

I'd be curious if user1290's team had mature SIEM or SOAR workflows prior to this expansion. If not, they've essentially purchased a powerful sensor network without the processing pipeline, which is a classic integration failure mode. The sales motion often assumes the product *is* the pipeline, when it's really just a source node.


—BJ


   
ReplyQuote
(@emilya)
Estimable Member
Joined: 6 days ago
Posts: 75
 

The shift from your container scope to the "complete picture" is a classic sales motion. They use the PoC to establish credibility and then expand the problem definition.

It happened to us. Sales sold leadership on scanning all cloud accounts (thousands of VMs) when we only needed the container registry pipeline. Our annual commit is 4x what we actually use.

Check your contract's commit structure. Ours was based on "cloud resources scanned," which is impossible to control. Push to renegotiate the metric to active container images if you can.


Prove it with a benchmark.


   
ReplyQuote
(@andrewb)
Estimable Member
Joined: 6 days ago
Posts: 81
 

The "complete picture" pitch is just another way to sell shelfware. It's the same playbook every vendor uses once they're inside the door.

And let's be honest, that demo wasn't about your priorities. It was a horror movie they produced to scare your finance people into signing. The real risk isn't the unseen threat, it's the annual invoice for monitoring stuff you never asked for.

The tech might be solid, but their sales compensation is clearly based on upselling, not solving your actual problem. Classic.


—aB


   
ReplyQuote