> Lots of early funding ($480M+ within a year of emerging from stealth )
> By May 2023, ARR reached $200M, and by February 2024, it was $350M
There is little substance about how the invested money was absorbed and how that absorption led to such an ARR. Did it pay for integrations and hand holding for each contract? Or was it used to bluntly bribe the CISOs to use their product?
Some kind of additional leverage and/or connections were certainly used.
The open dirty secret of infosec is that outside of authentication systems, the products and services sold do not actually work. Usability and real world functionality are not box-tick items in feature matrix comparison. It is enough that a security[tm] product does something technically correct to get a green tick in the relevant feature list row.
As a result the products are not commonly sold to their end users. They are sold to C-suite, and inflicted upon their victims. And how do C-suite choose what vendor to throw their money at? DDQ/RFx templates. I wish I was joking.
The other dirty secret of infosec is that everyone does their vendor/client/etc. vetting with bingo sheets full of meaningless, context-free questions that try to enumerate SYMPTOMS of different kinds of breach scenarios - they do not attempt to look at root causes, and they certainly do not consider threat models. These bingo sheet templates are used by everyone: vendor teams, insurers, auditors, you name it.
And now we finally get to how Wiz pulling connections intersects with the above. A fair number of the bingo sheet templates come with pre-populated dropdown choices. The choices usually include no more than 8 options, including "Other". The implication is very clear: "if you use one of these known & approved vendor products, then we are fine with it".
Wiz got their offering included in the bingo sheet templates in approximately 18 months from launching publicly. That has provided them with constant advertising from the countless infosec questionnaires thrown around the various industries and the implied checkmark of being pre-approved as a vendor of choice. Given the landscape and the general quality of competing vendors, your product needs to be merely not-shit to stand out and get traction through the various back channels.
Now, from personal exposure I can say that Wiz's product (or at least those I have been faced with) are still better[ß] than their competition. A recent security scan report from a client using Wiz had only ~85% of false positives. The average FP rate for other vendors tends to be 95% or even higher.
ß: security products must be the only segment where vast majority of results being false positives is considered both acceptable and normal. In any other field a product that routinely gets >90% of its answers wrong would be consigned to rubbish heap.
my experience as well. better product, and a very aggressive sales team which is something you missed. they were very willing to cut any deal at all, to get the sale. win-win IMO, and exactly the VC 101 playbook.
> By May 2023, ARR reached $200M, and by February 2024, it was $350M
There is little substance about how the invested money was absorbed and how that absorption led to such an ARR. Did it pay for integrations and hand holding for each contract? Or was it used to bluntly bribe the CISOs to use their product?