Will this be the Alphabet Cloud Security Fabric?
On March 18th, 2025, Google announced that it had signed a definitive agreement to acquire Wiz, Inc., a cloud security platform for $32 billion in an all-cash transaction. Once closed, Wiz will join Google Cloud. This is a major development that demonstrates the importance of cyber security in the age of generative AI. Businesses and society itself have become highly dependent on services delivered from the cloud. Cyber-attacks are an existential threat to these services and cloud security solutions are essential for cyber resilience. Recent incidents demonstrate how ransomware attacks and even mistakes can disrupt public services including healthcare. This union represents a pivotal moment in the worldwide marketplace for cloud security.
Why is this important?
The use of cloud services has accelerated digitalization through rapid application development and GenAI is both reducing the development effort needed to create new apps and enhancing their capabilities. This together with regulations around data protection and cyber resilience has created a strong market for cloud security solutions. Based on our current research, the Cloud Security market size was last estimated at $11.43B with an annual growth rate of 20%.
Wiz is recognized as a leading vendor in the Cloud Security Native Application Protection Platform (CNAPP) market in our Leadership Сompass report Cloud Native Application Protection Platforms. The price agreed by Google demonstrates the value that they place on both this market and Wiz.
Why is cloud security different?
The responsibilities for security and compliance are shared between the Cloud Service Provider (CSP) and the cloud customer and it is up to the customer to ensure that they use the cloud in a secure and compliant manner. While most customer use more than one cloud each cloud service provides its own proprietary tools security and APIs.
The dynamic nature of cloud services creates new security challenges that need a dynamic approach to cyber governance. The cloud is code, static controls and a separation of responsibilities between security and development does not work. Security in the cloud needs an integrated approach from cloud to code.
Furthermore, the rise of machine learning (ML) and artificial intelligence (AI), particularly generative AI (GenAI), introduces both challenges and opportunities. While adversaries increasingly leverage these technologies, ML and GenAI can also enhance cyber resilience when integrated effectively into security solutions.
To survive in a world of increasing cyber threats, organizations must go beyond merely preventing these threats from impacting their digital infrastructure—they must also enhance their capabilities to respond to and recover from cyber incidents rapidly and effectively.
Cloud Security Alphabet Soup
In response to these challenges a wide range of point solutions have appeared on the market intended to help to secure the way in which cloud services are used. While these tools are aligned with the security threats and risks that are relevant to the cloud they are often not integrated. These have created an alphabet soup of acronyms which include Cloud Infrastructure Entitlement Management (CIEM), Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWP), Kubernetes Posture Management (KSPM), Cloud Detection and Response (CDR) and others.

Alphabet Cloud Security Fabric
What is needed is a cloud security fabric that covers all the capabilities needed by the customer to secure their use of all of their multi-cloud services. Wiz provides a CNAPP solution that integrates the above capabilities for IaaS. This is a step towards a complete cloud security fabric. The Wiz platform capabilities also cover multiple cloud environments, architectural layers, and third-party integrations providing the additional context needed to achieve cloud security.
Opinion – more questions than answer
Google’s agreement to acquire Wiz at such a staggering price underscores the importance of cloud security but leaves more questions than answers. Organizations do not buy cloud services primarily because of their security capabilities but they do expect to be able to use them securely. CSPs complicate things for customers by making their security capabilities proprietary. Most organizations now use multiple cloud services and need a consistent security fabric that does not lock them in.
It is promising that Google has acquired a cloud agnostic CNAPP but it might be tricky if they use this to lock customers into their cloud.
So does Google’s acquisition of Wiz mark a step in the right direction? Will Wiz remain multi-cloud, or will it become tightly integrated into Google’s ecosystem? How will this impact organizations using Wiz to secure their AWS and Azure cloud? What will this mean for Wiz’s existing partners such as Check Point? What does this mean for all the niche cloud security vendors with point solutions?
We would love your thoughts on - is Google’s acquisition of Wiz a step toward true cloud security fabric, or will it become just another example of vendor lock-in?
Please let us know what you think.
To find out more about this, join us at EIC, Europe's leading event for the future of digital identities and cybersecurity from May 6 - 9, 2025, in Berlin, Germany!