How Drata Maintained MTTR with a Leaner Security Team Using Wiz Defend

What happens when your security team gets leaner, but your response times don’t? Drata maintained steady MTTR through a Security Operations reorganization by using Wiz Defend and the Blue Agent to automate investigation, centralize context, and reduce manual work. The result, security engineers spent less time piecing together alerts and more time making high-value decisions.

Drata

Industry

Technology

Region

North America

Wiz Product

Wiz CloudWiz Defend

Use Cases

CSPMWiz SensorWiz AgentsAI-SPMIAC ScanningCDR
Ready to start?
Get a demo

Drata helps more than 8,500 organizations to automate compliance, reduce risk, and prove their security posture to external stakeholders.  As a company built on trust and helping others to manage and prove their trust posture, maintaining a strong security environment  isn't just important—it's foundational.

When Drata reorganized its Security Operations organization, the team faced a familiar challenge: how to maintain response performance with fewer resources. Rather than adding headcount or expanding tooling, they turned to Wiz Defend and the Blue Agent to help their team work more efficiently without sacrificing visibility or confidence.

The result: Drata maintained consistent Mean Time to Respond (MTTR) throughout the transition while enabling security engineers to focus on higher-value security decisions.

MTTR maintained icon

MTTR maintained

with leaner team

Automatic sync icon

Automatic sync

of threat resolution to case management, removing manual handoff

Slack-based confirmation icon

Slack-based confirmation

eliminates friction from the investigation workflow

Investigations start before security engineers do

At the center of Drata's workflow is the Wiz Blue Agent.

The Blue Agent automatically investigates every threat as soon as it's detected, correlating cloud context, telemetry, and relationships across the Wiz Security Graph. By the time a security engineer opens an alert, they're presented with a verdict, confidence score, and the reasoning behind the decision.

Instead of spending valuable time gathering evidence and building context manually, security engineers can now begin their work with an investigation already in progress. This fundamentally changed how Drata's team approached threat response.

Many organizations experience longer investigation times and slower response performance when teams become leaner. Drata experienced the opposite.

Despite operating with a more focused team structure, MTTR remained steady. Security engineers were able to move quickly because the most time-consuming portion of the investigation process—collecting and correlating context—had already been completed by the Blue Agent. Human effort could be directed toward validation, decision-making, and response rather than information gathering.

With the Blue Agent, investigations start before our security engineers do. The most time-consuming part of the work, collecting and correlating context, is already done by the time someone opens the alert. That let us maintain steady response performance with a more focused team

Josh Stuts, Director, Security and Trust , Drata

Seamless workflows, not additional work

Automation only creates value when it fits naturally into existing processes.

Drata conducts investigations directly within Wiz Defend while automatically syncing outcomes into Jira. Security engineers work where the richest security context exists, and resolution data flows seamlessly into the systems the broader organization already uses.

This eliminates duplicate data entry, reduces manual handoffs, and ensures teams have immediate access to investigation outcomes while enhancing established workflows.

A collaborative approach to product innovation

As a design partner, Drata worked closely with the Wiz product team to help shape features that are now part of its daily workflow, including a Slack confirmation flow.

The collaboration gave Drata an opportunity to bring real-world operational feedback directly into the product development process, while helping Wiz build workflows that better reflect how modern security teams investigate and respond to threats. The result was a solution that reduced friction for Drata's security engineers and delivered value that extends to other Wiz customers facing similar challenges.

Wiz treated us like a true design partner, taking our feedback into consideration and making decisions based on it. We brought real operational friction to the table and watched it turn into features we now use every day. That's the kind of collaboration that actually moves a security program forward.

Josh Stuts, Director, Security and Trust, Drata

Looking ahead

With Wiz Defend serving as the foundation for detection, investigation, and response, the team is looking to the future. As AI-powered security operations continue to evolve, Drata sees significant opportunities to drive even greater efficiency through agentic workflows. The team is watching the space closely as it matures, with a focus on finding new ways to scale security operations without increasing operational burden.

Read more customer stories

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management