Drata helps more than 8,500 organizations to automate compliance, reduce risk, and prove their security posture to external stakeholders. As a company built on trust and helping others to manage and prove their trust posture, maintaining a strong security environment isn't just important—it's foundational.
When Drata reorganized its Security Operations organization, the team faced a familiar challenge: how to maintain response performance with fewer resources. Rather than adding headcount or expanding tooling, they turned to Wiz Defend and the Blue Agent to help their team work more efficiently without sacrificing visibility or confidence.
The result: Drata maintained consistent Mean Time to Respond (MTTR) throughout the transition while enabling security engineers to focus on higher-value security decisions.
MTTR maintained
with leaner team
Automatic sync
of threat resolution to case management, removing manual handoff
Slack-based confirmation
eliminates friction from the investigation workflow
Investigations start before security engineers do
At the center of Drata's workflow is the Wiz Blue Agent.
The Blue Agent automatically investigates every threat as soon as it's detected, correlating cloud context, telemetry, and relationships across the Wiz Security Graph. By the time a security engineer opens an alert, they're presented with a verdict, confidence score, and the reasoning behind the decision.
Instead of spending valuable time gathering evidence and building context manually, security engineers can now begin their work with an investigation already in progress. This fundamentally changed how Drata's team approached threat response.
Many organizations experience longer investigation times and slower response performance when teams become leaner. Drata experienced the opposite.
Despite operating with a more focused team structure, MTTR remained steady. Security engineers were able to move quickly because the most time-consuming portion of the investigation process—collecting and correlating context—had already been completed by the Blue Agent. Human effort could be directed toward validation, decision-making, and response rather than information gathering.
With the Blue Agent, investigations start before our security engineers do. The most time-consuming part of the work, collecting and correlating context, is already done by the time someone opens the alert. That let us maintain steady response performance with a more focused team
Josh Stuts, Director, Security and Trust , Drata
Seamless workflows, not additional work
Automation only creates value when it fits naturally into existing processes.
Drata conducts investigations directly within Wiz Defend while automatically syncing outcomes into Jira. Security engineers work where the richest security context exists, and resolution data flows seamlessly into the systems the broader organization already uses.
This eliminates duplicate data entry, reduces manual handoffs, and ensures teams have immediate access to investigation outcomes while enhancing established workflows.
A collaborative approach to product innovation
As a design partner, Drata worked closely with the Wiz product team to help shape features that are now part of its daily workflow, including a Slack confirmation flow.
The collaboration gave Drata an opportunity to bring real-world operational feedback directly into the product development process, while helping Wiz build workflows that better reflect how modern security teams investigate and respond to threats. The result was a solution that reduced friction for Drata's security engineers and delivered value that extends to other Wiz customers facing similar challenges.
Wiz treated us like a true design partner, taking our feedback into consideration and making decisions based on it. We brought real operational friction to the table and watched it turn into features we now use every day. That's the kind of collaboration that actually moves a security program forward.
Josh Stuts, Director, Security and Trust, Drata
Looking ahead
With Wiz Defend serving as the foundation for detection, investigation, and response, the team is looking to the future. As AI-powered security operations continue to evolve, Drata sees significant opportunities to drive even greater efficiency through agentic workflows. The team is watching the space closely as it matures, with a focus on finding new ways to scale security operations without increasing operational burden.