Wiz became a Google company on 11 March 2026, when Google completed the largest acquisition in its history. The transaction, agreed at $32 billion in cash before closing adjustments, placed one of the fastest-growing cloud-security businesses inside one of the world’s largest cloud providers. Wiz retained its brand, and Assaf Rappaport remained its co-founder and chief executive.
The title matters because the business still has an unusually delicate promise to keep. Wiz protects environments running not only on Google Cloud, but also on Amazon Web Services, Microsoft Azure, Oracle Cloud and hybrid infrastructure. Its platform became valuable by giving security teams a common view across competing systems. Now it is owned by one of those competitors.
For Rappaport, the defining leadership question is whether he can use Google’s capital, artificial-intelligence capabilities, threat intelligence and distribution without allowing Wiz to be perceived as an instrument of Google Cloud. The acquisition can make Wiz a more capable security company. It can also weaken the neutrality on which customer trust depends. Both outcomes are plausible, and neither will be decided by a launch announcement.
Google has made explicit commitments. Wiz will remain available across all major clouds, retain its brand and support an open ecosystem of partners. The company is already used by a majority of the Fortune 100 and protects millions of cloud workloads. That installed base gives Rappaport influence inside the combined organisation, but it also increases the cost of any ambiguity. Chief information-security officers will watch product road maps, commercial terms, data handling and integration choices for evidence that one cloud is being favoured.
The immediate opportunity is compelling. AI is accelerating the creation of applications and infrastructure, often faster than security teams can review them. Agents can access data, invoke tools and change systems. Development environments increasingly include generated code, third-party models and rapidly assembled services. Wiz’s graph-based context across code, cloud and runtime can help organisations distinguish theoretical vulnerabilities from attack paths that place important assets at real risk. Google can add compute, models and global threat intelligence to that context.
Rappaport’s challenge is to turn those complementary assets into a coherent security platform while ensuring that every customer remains confident about where its information goes and how it is used.
Neutrality must be operational
Multicloud neutrality is easy to state and difficult to institutionalise. It requires more than maintaining connectors to AWS and Azure. Product coverage must remain equally timely, engineering resources must not drift disproportionately towards Google services and commercial incentives must not penalise customers whose infrastructure is elsewhere. The platform’s risk models need to treat equivalent configurations consistently across providers.
Rappaport should make neutrality measurable. Customers need visibility into release cadence by cloud, the scope of supported services and the treatment of telemetry. Independent assurance over data separation and model training would be more persuasive than broad commitments. Partner governance should include routes for rival providers and security vendors to raise concerns before technical choices become structural disadvantages.
There is a useful tension here. Deeper integration with Google Security Operations, Mandiant threat intelligence and Gemini can improve detection and response. A customer may want one workflow that connects exposure data, live threats and automated remediation. But the same customer may reject that workflow if using it requires moving sensitive data into a cloud it has not selected. Integration must therefore be modular, transparent and designed around customer control.
The Wiz brand gives Rappaport a protective boundary. Maintaining separate product identity can signal that the company serves a broader market than its parent’s infrastructure business. Yet a brand has credibility only if decisions support it. If support quality, pricing or features begin to diverge by cloud, customers will interpret the branding as cosmetic.
The platform must reduce work, not add another console
Enterprise security suffers from tool accumulation. Large organisations may own dozens of products, each producing alerts and dashboards. The strategic case for Wiz rests partly on reducing that complexity by connecting code, configuration, identities, vulnerabilities and runtime activity into a common context. Google’s acquisition adds more capabilities, but it also creates the risk of a sprawling suite that reproduces the fragmentation it is meant to solve.
Rappaport needs a strict product architecture. Each acquisition and integration should strengthen a small number of customer workflows: discover assets, understand material exposure, prevent unsafe deployment, detect active attack and remediate safely. Features that do not improve those workflows should be questioned, regardless of their technical novelty.
Recent Wiz development illustrates the breadth of the ambition. The company has expanded exposure management, introduced AI security agents, built hardened container images and added cloud-cost visibility informed by security context. The logic behind the last category is that waste and risk often share the same underlying problem: poorly understood resources. But moving into cost management also tests product focus. Wiz should enter adjacent categories only where its security graph creates an advantage that customers can recognise.
Automation is another boundary. AI agents can investigate, prioritise and recommend remediation at a speed human teams cannot match. They can also amplify a mistaken assumption across an environment. Security buyers will require controls over what an agent may observe, propose and execute. Rappaport should favour graduated autonomy, where the system earns broader permissions through verified performance and retains an auditable account of every action.
Google’s scale changes the economics
Wiz no longer has to optimise like an independent high-growth software company preparing for a public listing. Google can fund research, global infrastructure and distribution on a different scale. That freedom can accelerate product development and broaden access to smaller organisations that lack large security teams. It can also blur economic accountability.
The acquisition price creates a substantial expectation of strategic return. Alphabet does not separately disclose Wiz revenue, and Rappaport should avoid allowing the absence of standalone reporting to weaken operating discipline. Customer retention, platform adoption, incident outcomes and expansion across workloads remain important. So do the costs of model inference, data processing and global support. Scale is valuable only when it produces better security and attractive economics, not merely more bundled usage.
Commercial bundling deserves particular care. Google can distribute Wiz through existing cloud relationships and procurement channels. That reduces friction, but aggressive bundling could concern regulators, competitors and customers seeking genuine choice. The most durable approach is to make Wiz compelling on its own merits and allow integration to add value rather than conceal price.
Rappaport must also manage talent after a life-changing transaction. The urgency of an independent company can fade when employees join a much larger institution and financial incentives mature. Keeping the founders and technical leaders engaged is necessary but insufficient. Wiz needs a mission, decision rights and career paths that persuade the next layer of leaders that they can still build with speed and consequence.
Security is now part of the AI control plane
The strategic rationale for the deal extends beyond conventional cloud security. As companies deploy generative models and autonomous agents, security moves closer to the design of applications. Teams need to know which model can reach which data, what an agent is authorised to do, how generated code changes the attack surface and whether sensitive information can leave an approved boundary.
Wiz has the contextual foundation to address that problem. Its view of identities, resources, data and paths can help organisations understand not only whether an AI component contains a vulnerability, but what that vulnerability could reach. Google contributes expertise in models and infrastructure. Together, they can create controls that follow an application from code into production and monitor the behaviour of agents after deployment.
Yet AI security carries unusually high claims risk. The market is crowded with products described as intelligent, autonomous or end-to-end. Rappaport should insist on evidence: detection performance against realistic attacks, false-positive rates, response latency and the ability to operate across languages and architectures. Research disclosures should help the wider ecosystem fix systemic flaws, even when doing so produces no immediate sale.
There is also a governance issue in using customer telemetry to improve AI-driven defence. Aggregated threat information can make every customer safer, but sensitive cloud context is among the most valuable data an enterprise possesses. Consent, isolation, retention and model-training rules must be precise. The combined company’s technical capacity makes strong governance more important, not less.
A founder inside a platform
Rappaport’s role is now inherently dual. He remains responsible for Wiz customers and employees while operating inside Google Cloud’s hierarchy. There will be moments when the interests align easily and moments when they do not. Google may prefer deeper native integration; Wiz customers may demand greater independence. Sales teams may seek bundles; partners may seek neutral distribution. Product leaders may want access to Google data; governance teams may impose boundaries.
His effectiveness will depend on whether he can convert the acquisition commitments into durable decision mechanisms. That means securing budget for non-Google integrations, maintaining a leadership team with authority and escalating conflicts before customer trust is affected. It also means accepting the discipline of a larger company where regulatory, privacy and reliability concerns appropriately slow some decisions.
The founder mythology of speed at all costs is poorly suited to security. Customers want innovation, but they also want continuity, predictable support and controls that survive organisational change. Rappaport’s task is not to preserve every habit of a start-up. It is to preserve the qualities that mattered: clarity of product, closeness to customers and a willingness to simplify complex risk.
The proof will be in customer choice
The Google transaction gives Wiz a rare chance to define the security layer for multicloud and AI infrastructure. It brings resources few independent vendors could match and a parent whose own cloud ambitions create natural distribution. The structural tension is equally rare: a neutral control point now belongs to a participant in the market it observes.
The clearest evidence of success will not be a revenue disclosure or a list of integrations. It will be whether enterprises continue choosing Wiz when their primary infrastructure is on AWS, Azure or Oracle; whether partners continue sharing data and building connections; and whether security teams believe the platform helps them act without locking them into Google Cloud.
Rappaport sold Wiz at an extraordinary valuation because the company had become strategically important. His work after the sale is to prove that strategic ownership does not diminish strategic independence. If he can make Google’s scale serve an open platform, the acquisition may strengthen competition by making multicloud security more effective. If neutrality erodes, the price paid will be measured not only in customer departures, but in the trust that made Wiz worth buying.