Google To Acquire CNAPP Specialist Unicorn Wiz for USD32B
- By Forrester Analysts
- March 20, 2025

Google has announced definite plans to acquire cloud-native application protection platform (CNAPP) vendor Wiz for USD32 billion, which is the largest-ever acquisition in cybersecurity, surpassing the USD28 billion that Cisco paid for Splunk in 2024. This is also Google’s largest-ever acquisition and, based on Forrester’s estimates of Wiz’s annual revenue, represents an astronomically high, approximately 45–50x estimated multiplier of Wiz’s annual revenue. Wiz has been making financial headlines since last summer, stemming from rumors in July 2024 that Google would acquire Wiz for USD23 billion, as well as Wiz’s acquisition of Gem Security along with talk that Wiz would acquire Lacework, a deal that fell through (Fortinet later acquired Lacework).
This acquisition highlights the following:
- In light of Google’s track record with past security acquisitions, Google can successfully integrate Wiz. When evaluating Googe Cloud’s previous security acquisitions, the track record is strong. Google’s 2022 acquisition of Mandiant has proven to be a key component of Google’s cybersecurity product strategy, infusing Google Security Operations with Mandiant’s threat intelligence and analytics. Google has also retained many of Mandiant’s most prominent security leaders, which is a positive sign. Similarly, the 2022 Siemplify acquisition was productive for Google Security Operations — it recently fully integrated Siemplify into the platform as a full-fledged security orchestration, automation, and response offering. The success of Wiz’s acquisition will also depend on: 1) Google’s ability to navigate today’s current volatile economic environment; 2) its ability to “save some cash” to remain in the AI race with AWS and Azure; and 3) whether Google operates Wiz separately or embeds them into Google Cloud’s security portfolio.
- Multicloud CNAPP is indispensable for cloud infrastructure security offerings. While Google Cloud Platform (GCP) has successfully developed CNAPP capabilities (cloud security posture management and cloud workload protection) for its own platform’s native security, these tools have predominantly focused only on protecting GCP endpoints/assets. After Microsoft’s 2021 early acquisition of CloudKnox and development of Defender for Cloud (a multicloud CNAPP tool competing with Palo Alto Networks and others), Google is now feeling the pressure to offer a true, multicloud-capable CNAPP tool, given that so many organizations are multicloud today. Forrester expects, post-acquisition, most current CNAPP capabilities in GCP (such as cloud security posture management (CSPM), cloud infrastructure entitlement management (CIEM), and agentless cloud workload protection (CWP)) will be replaced by Wiz’s offering and remain with multicloud support. Multicloud security capabilities will accelerate Google Cloud’s entry into many enterprises.
- App security synergies provide additional opportunities for cloud providers. While Wiz is primarily focused on CNAPP, the firm’s product offerings bleed into the application security space. Recently, Wiz expanded into app security, including software composition analysis, infrastructure as code (IaC), and secrets scanning; software bills of materials; and continuous integration and continuous delivery security posture management. These moves position Wiz to compete with application security testing vendors and other CNAPP vendors that have “shifted left.” Google has also begun extending its API management product, Apigee, into broader API security use cases. While there are still gaps to fill, such as static application security testing, dynamic application security testing, and API attack detection, adding Wiz to the Cloud Armor, reCAPTCHA, and Apigee offerings moves Google closer to being a holistic cloud application security provider.
- The acquisition will provide competitive pressures and drive consolidation for independent CNAPP suite vendors. Fortinet, Palo Alto Networks, Sysdig, Rapid7, Trend Micro, and others now face fierce competition from cloud infrastructure providers (Google and Microsoft). This planned acquisition, plus Microsoft’s continued investments in CNAPP and app security, will drive independent CNAPP providers to innovate and seek differentiation in comparison to the cloud infrastructure providers and could lead to further consolidation within the CNAPP space. Cloud customers must consider whether these independent CNAPP vendors have sufficient capabilities to maintain themselves as a trusted third-party platform that mitigates reliance on a single cloud provider — a pattern that has benefited vendors in the observability and AIOps space, for example.
- Other CNAPP vendors must integrate cloud detection and response. Wiz’s cloud detection and response offering, Wiz Defend (formerly Gem Security), takes a different approach to cloud detection and response. Instead of relying on built-in detection capabilities in its own cloud protection tools exclusively, Wiz Defend offers a unified tool solely for detection and response that takes in alerts and data from other tools (identity tools, Google Cloud audit logs, Azure activity logs, AWS CloudTrail logs, etc.) and does detection engineering on them. This reduces alert volumes from the cloud at a critical time — clients are struggling with cloud alert volumes more than ever given the disparate products. With this acquisition, it puts pressure on other vendors to consolidate their CNAPP and cloud detection and response (CDR) offerings in a similar way and provide explicit CDR capabilities in their CNAPP solution: a big win for security operations teams.
- Wiz’s cluster optimization and cost considerations raise questions about Google’s cloud management ambitions. Although traditionally a CNAPP solution, Wiz — driven by customer requirements — developed a Cost Optimization framework, with Cloud Configuration Rules being its latest capability. It optimizes Kubernetes costs in Amazon’s Elastic Kubernetes Service by identifying cluster optimization opportunities. Though this capability starts with AWS, Wiz earlier had stated plans to extend its next generation of Wiz Cloud Cost to other public clouds. Since Google Cloud has its cost management capabilities, the question remains whether Wiz Cloud Cost will be deprecated or folded into Google’s native management suite, or perhaps Google will continue its FinOps ambitions and expand to ingesting and managing its competitors’ cloud costs.
- AWS will need to react to these CNAPP trends. While Amazon Web Services has been providing GuardDuty and Config, these solutions are not as strong as other CNAPP solutions in areas of best practices, compliance template breadth and depth, and, more importantly, multicloud coverage. While AWS WAF (web application firewall) supports hybrid and multicloud deployments, many Forrester clients tell us that they still limit AWS WAF to the AWS environment. To respond to Google’s acquisition of Wiz, AWS will need to beef up its productized, multicloud CNAPP offering (with coverage for CSPM, CIEM, agent-based and agentless CWP, container security, and IaC scanning). If AWS chooses to go the buy vs. build route, likely CNAPP acquisition targets would include smaller players such as Aqua Security, Orca Security, and Sysdig.
The original article is here.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/cagkansayin
Forrester Analysts
Andras Cser is Forrester’s vice president and principal analyst. He serves security and risk (S&R) professionals. He is a leading expert on identity and access management (IAM); risk-based, biometric, and multifactor/passwordless authentication; user account provisioning; entitlement management; federation; and privileged identity management.
Allie Mellen is Forrester’s principal analyst. She covers security operations, nation-state threats, and the use of automation, machine learning, and AI in security tools. She is a computer engineer by trade and has held various engineering roles in her career, including doing research at MIT, running her engineering consultancy, and being a hacker before finally becoming a security practitioner.
Janet Worthington is Forrester’s senior analyst. She covers product security, proactive security design, securing new development methods, security testing in the software delivery lifecycle, and collaboration between security, development, and product management.
Sandy Carielli is Forrester’s principal analyst. Sandy advises security and risk professionals on application and product security, with a particular emphasis on the collaboration among security and risk, product management, application development, operations, and business teams. Her research covers topics such as proactive security design, protecting modern and emerging application architectures, protection of applications in production environments, and embedding security throughout the product lifecycle.
Lee Sustar is Forrester’s principal analyst. He serves IT infrastructure and operations professionals. His research focuses on public cloud, containers, modernization, cloud strategy, cloud operations, and the wider transition to cloud-native computing and practices. He assists enterprises in creating pragmatic cloud strategies and developing execution roadmaps.
Tracy Woo is Forrester’s principal analyst. She leads Forrester’s research on FinOps, hybrid cloud management, IT financial management (ITFM), technology business management (TBM), and industry cloud in the financial services, retail, and healthcare industries.