Why Google Buying Wiz Is Only Half the Solution
- By Winston Thomas
- January 05, 2026

Imagine a smoke alarm screaming at every shadow, every flicker of movement, drowning out actual fire signals with a cacophony of false alarms. This is the reality of modern cloud security, according to Bryan Ashley, vice president of product marketing at Aviatrix, and it’s precisely why the USD32 billion acquisition of Wiz by Google (or more accurately, the parent company Alphabet) solves only half the problem.
Sure, Wiz excels at vulnerability scanning. The cloud security startup has become the poster child for identifying threats, building digital twins of enterprise infrastructure to spot weaknesses before attackers do. But the problem isn’t just the detection; even with all-cash deals worth tens of billions, the fundamental gap lies between detection and remediation. And, as Ashley puts it, the gap remains as wide as ever.
“Most enterprise customers are a Wiz customer, a Cloudflare customer, a Palo Alto customer, on and on and on,” Ashley tells CDOTrends during a recent interview. “And yet these breaches still keep happening. So, obviously, there is a gap that’s still there.”
The inside job
The gap Ashley describes is less about technology and more about positioning. Wiz and similar platforms scan infrastructure externally, creating comprehensive vulnerability maps. But when threats materialize and attackers pivot from an initial breach to lateral movement, these external tools become mere spectators.
Consider the recent high-profile attacks that have dominated headlines: Scattered Spider, Silk Typhoon, and the devastating Change Healthcare breach. “A lot of these are points in which the bad guys have been able to infiltrate, but then move laterally within an organization, kind of in that soft center,” Ashley explains. The pattern is consistent: initial penetration followed by “low and slow” lateral movement, with data exfiltration happening quietly while external security tools maintain their vigilant watch on the perimeter.
Aviatrix, which more than 500 of the world’s leading enterprises use, has spent a decade positioning itself precisely in this blind spot. The company began as a cloud networking specialist, addressing the mundane yet critical issues of routing and encryption across multi-cloud environments. But about five years ago, during a customer meeting, a CISO delivered a revelation that would reshape the company’s trajectory: “We love what you guys do, but we’re starting to see these security problems... what I really need is secure cloud networking.”
The in-line enforcement engine
The distinction between detection and enforcement isn’t academic. When Wiz identifies a vulnerable S3 bucket or a misconfigured database, the finding joins thousands of others in security dashboards across the enterprise. The NIST recently introduced a new category called “Likely Exploited Vulnerabilities” (LEV), a tacit admission that the volume of detected threats has reached unmanageable proportions.
Aviatrix operates in-line with multi-cloud network traffic, not just observing but actively enforcing policies and blocking threats as they happen. This includes:
- Inline egress control
- East-west segmentation
- Threat containment during active exploitation
- Runtime inspection and anomaly detection

This inside-out approach is vital with the rise of agentic AI. CEOs view agentic AI as a “massive opportunity for margin” by dramatically reducing headcount. However, this enthusiasm often overlooks significant security implications. Traditional security models, built on human identity and static infrastructure, struggle to accommodate autonomous agents that dynamically create connections and consume data. “Now you have services spinning up other services in real-time,” Ashley observes. “This problem just starts to explode.”
“Bad guys are leveraging AI too,” Ashley adds. Tools designed to streamline operations are being weaponized for more sophisticated and scalable attacks. Furthermore, the concentration of human oversight with AI-driven automation creates new vulnerabilities. “When you make a large organization into a very small organization, everybody becomes a privileged access user,” Ashley notes. “But not everybody is trained for that role.” This confluence of sophisticated threats, fewer human defenders, and increased exposure through automation creates a perfect storm that traditional security models cannot address.
Decoding Google's gambit
Google’s acquisition of Wiz represents a strategic response to the enterprise market dynamics that have consistently favored Microsoft and Amazon. The deal positions Google to offer a comprehensive security suite, leveraging Wiz’s proven success (the company was one of the fastest-growing security vendors) to accelerate Google Cloud’s enterprise adoption.
But the acquisition also raises uncomfortable questions about vendor lock-in. Enterprise security teams have long prized flexibility, playing cloud providers against each other to avoid dependence on any single platform. With Wiz now under Google's umbrella, CISOs face a familiar dilemma: accept potentially superior integrated security or maintain strategic independence.
“I really hope that Google doesn’t go that way [of locking in customers],” Ashley says, though he acknowledges the economic reality. “All the CSPs do it, right? They spent billions and billions on infrastructure, and they’ve got to monetize that somehow.”
While Google promises to maintain Wiz’s multi-cloud capabilities, the very logic of the acquisition suggests that eventual platform consolidation is likely. Why spend USD32 billion on a security company only to help customers secure competing cloud platforms?
Still, Ashley believes no single solution, regardless of its cost, can address the full spectrum of cloud security challenges. The most effective deployments combine specialized tools for specific attack vectors or operational requirements. The existing Aviatrix-Wiz partnership exemplifies this. Rather than competing, the platforms complement each other: Wiz identifies threats, and Aviatrix provides enforcement and remediation.
“Wiz tells you what's wrong. Aviatrix enforces what’s right across clouds, in real-time,” says Ashley. “We’re not replacing Wiz; we’re helping customers go from insight to action. Aviatrix offers the missing enforcement layer in today’s multi-cloud security stack.”
This integration offers a path that doesn’t force enterprises to choose between security effectiveness and vendor independence. “We want to build an ecosystem,” Ashley explains. “We recognize our unique capabilities... but we’re never going to have the threat intelligence that some of these other well-established players are going to have.”
The upcoming security battle
Google’s acquisition of Wiz represents a significant milestone in the evolution of cloud security, but it’s not the final destination. The fundamental challenge — bridging the gap between detection and enforcement requires more than external scanning, regardless of how sophisticated or well-funded the technology may be.
It also means that we need to recognize that a USD32 billion acquisition, impressive as it may be, addresses only half the equation. The other half — the ability to act on those findings in real-time, to stop threats as they move laterally through cloud infrastructure — remains the harder problem to solve.
“Google’s move makes two things clear: Security is a core pillar of cloud strategy, not an add-on, and the race is on to close architectural gaps that posture management alone can’t solve. We believe the next wave of innovation will come from runtime enforcement platforms like Aviatrix that complement CSPM, CNAPP, and identity-based controls with inline, adaptive defense,” says Ashley.
As enterprises grapple with their new cloud security reality, the winners won't be the companies that can detect the most threats, but those that can most effectively bridge the gap between knowing and doing. Google’s bet on Wiz is a strong play for the knowing part. The doing part? That’s still up for grabs.
Image credit: iStockphoto/Alona Horkova
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.