Full Report
It's a common question we hear from prospects: "Does Wiz actually do runtime, or is it just risk prevention?" The short answer is yes, Wiz does runtime.
Analysis Summary
# Industry News: Wiz Solidifies Position in Runtime Security Market
## Summary
Cloud security leader Wiz has officially pivoted from its "agentless-only" origin to a comprehensive Cloud-Native Application Protection Platform (CNAPP) by heavily integrating runtime security. Through the recent release of the eBPF-based Wiz Runtime Sensor and the "Wiz Defend" suite, the company now offers real-time threat detection and automated forensics across containers, VMs, serverless, and AI infrastructure.
## Key Details
- **Date:** July 6, 2026 (Article Publication)
- **Companies Involved:** Wiz
- **Category:** Product Update / Market Positioning
## The Story
Wiz rose to dominance in the cybersecurity sector by championing "agentless" visibility, allowing organizations to scan cloud environments for risks without the friction of installing software on every server. However, as the market matures, the distinction between "risk prevention" (scanning) and "runtime protection" (active monitoring) is blurring.
The company is addressing the "agentless vs. agent" debate by arguing that both are necessary for a complete security posture. Over the last six months, Wiz has aggressively expanded its **Wiz Runtime Sensor**, an eBPF-powered tool that provides real-time visibility into executing workloads. Recent updates include:
* **Wiz Defend:** A detection and response layer integrated into the platform.
* **The Security Graph Integration:** Runtime signals (like active network connections) are now fed directly into Wiz’s proprietary Security Graph to identify "toxic combinations" that static scanning misses.
* **Operating System Expansion:** Launch of a memory-safe Runtime Sensor for Windows and expanded support for serverless containers (Google Cloud Run, AWS Fargate, Azure Container Apps).
* **Automated Forensics:** The General Availability of Wiz Forensics, which captures high-fidelity data at the exact moment a threat is detected.
## Business Impact
### For the Companies Involved (Wiz)
Wiz is successfully shedding the "vulnerability scanner" label to become a full-spectrum security platform. This increases their Total Addressable Market (TAM) and makes their platform stickier, as they can now replace legacy Endpoint Detection and Response (EDR) or Cloud Workload Protection Platforms (CWPP) within cloud environments.
### For Competitors
Legacy security providers and newer CNAPP rivals (like Palo Alto Networks, CrowdStrike, and Sysdig) now face a direct challenge in the runtime space. Wiz is leveraging its massive "agentless" install base to upsell runtime agents, potentially squeezing competitors out of established accounts.
### For Customers
Customers benefit from a "single pane of glass" that combines risk posture with active threat response. The automated forensics feature specifically addresses a major pain point: the high cost and complexity of investigating ephemeral cloud workloads (like containers) that disappear shortly after an attack.
### For the Market
This signifies the consolidation of the CNAPP category. The market is no longer tolerating a split between visibility tools and protection tools; the expectation is now a unified platform that covers "code to cloud" and "prevention to detection."
## Technical Implications
Wiz is utilizing **eBPF (Extended Berkeley Packet Filter)** technology, which allows for deep kernel-level observability without the stability risks or performance overhead associated with traditional kernel modules. Their integration of **Forensics AI** to analyze move-action timelines represents a shift toward automated incident response in high-velocity cloud environments.
## Strategic Analysis
- **Market Positioning:** Wiz is positioning itself as the "operating system for cloud security," moving from a reactive reporting tool to an active defensive layer.
- **Competitive Advantage:** The "Wiz Security Graph" remains their crown jewel. By adding runtime data to the graph, they can prove that their alerts are not just theoretical risks but active exploits, significantly reducing alert fatigue.
- **Challenges:** Deployment friction remains an obstacle. Even "lightweight" sensors require more management than agentless connectors, and Wiz must prove their sensor doesn't impact critical production performance or stability.
## Industry Reactions
- **Analyst Opinions:** Industry analysts generally view this as a necessary evolution for Wiz to justify its high valuation and maintain its lead in the CNAPP space.
- **Expert Commentary:** Cybersecurity experts note that the inclusion of Windows and Serverless support makes Wiz a viable enterprise-wide solution rather than just a tool for specialized cloud teams.
## Future Outlook
Expect Wiz to continue pushing into **AI Security (AI-SPM)**. Mention of "Wiz MCP" and "AI Security Agents" suggests the company plans to use runtime data to secure the large language models (LLMs) and AI workloads that enterprises are currently rushing to deploy.
## For Security Professionals
Practitioners should note that Wiz discovered **1 in 6 environments** contained high-severity attack paths that were only visible once runtime context was added. This highlights a critical gap for teams relying solely on agentless snapshots. Security leaders should evaluate whether their current stack provides forensics for containers that may only exist for minutes.