How Drata Maintained MTTR with a Leaner Security Team Using Wiz Defend

What happens when your security team gets leaner, but your response times don’t? Drata maintained steady MTTR through a Security Operations reorganization by using Wiz Defend and the Blue Agent to automate investigation, centralize context, and reduce manual work. The result, security engineers spent less time piecing together alerts and more time making high-value decisions.

Drata

산업

기술

부위

북아메리카

위즈 제품

Wiz CloudWiz Defend

사용 사례

CSPMWiz SensorWiz AgentsAI-SPMIAC ScanningCDR
시작할 준비가 되셨나요?
데모 신청하기

Drata helps more than 8,500 organizations to automate compliance, reduce risk, and prove their security posture to external stakeholders.  As a company built on trust and helping others to manage and prove their trust posture, maintaining a strong security environment  isn't just important—it's foundational.

When Drata reorganized its Security Operations organization, the team faced a familiar challenge: how to maintain response performance with fewer resources. Rather than adding headcount or expanding tooling, they turned to Wiz Defend and the Blue Agent to help their team work more efficiently without sacrificing visibility or confidence.

The result: Drata maintained consistent Mean Time to Respond (MTTR) throughout the transition while enabling security engineers to focus on higher-value security decisions.

MTTR maintained icon

MTTR maintained

with leaner team

Automatic sync icon

Automatic sync

of threat resolution to case management, removing manual handoff

Slack-based confirmation icon

Slack-based confirmation

eliminates friction from the investigation workflow

Investigations start before security engineers do

At the center of Drata's workflow is the Wiz Blue Agent.

The Blue Agent automatically investigates every threat as soon as it's detected, correlating cloud context, telemetry, and relationships across the Wiz Security Graph. By the time a security engineer opens an alert, they're presented with a verdict, confidence score, and the reasoning behind the decision.

Instead of spending valuable time gathering evidence and building context manually, security engineers can now begin their work with an investigation already in progress. This fundamentally changed how Drata's team approached threat response.

Many organizations experience longer investigation times and slower response performance when teams become leaner. Drata experienced the opposite.

Despite operating with a more focused team structure, MTTR remained steady. Security engineers were able to move quickly because the most time-consuming portion of the investigation process—collecting and correlating context—had already been completed by the Blue Agent. Human effort could be directed toward validation, decision-making, and response rather than information gathering.

With the Blue Agent, investigations start before our security engineers do. The most time-consuming part of the work, collecting and correlating context, is already done by the time someone opens the alert. That let us maintain steady response performance with a more focused team

Josh Stuts, Director, Security and Trust, Drata

Seamless workflows, not additional work

Automation only creates value when it fits naturally into existing processes.

Drata conducts investigations directly within Wiz Defend while automatically syncing outcomes into Jira. Security engineers work where the richest security context exists, and resolution data flows seamlessly into the systems the broader organization already uses.

This eliminates duplicate data entry, reduces manual handoffs, and ensures teams have immediate access to investigation outcomes while enhancing established workflows.

A collaborative approach to product innovation

As a design partner, Drata worked closely with the Wiz product team to help shape features that are now part of its daily workflow, including a Slack confirmation flow.

The collaboration gave Drata an opportunity to bring real-world operational feedback directly into the product development process, while helping Wiz build workflows that better reflect how modern security teams investigate and respond to threats. The result was a solution that reduced friction for Drata's security engineers and delivered value that extends to other Wiz customers facing similar challenges.

Wiz treated us like a true design partner, taking our feedback into consideration and making decisions based on it. We brought real operational friction to the table and watched it turn into features we now use every day. That's the kind of collaboration that actually moves a security program forward.

Josh Stuts, Director, Security and Trust, Drata

Looking ahead

With Wiz Defend serving as the foundation for detection, investigation, and response, the team is looking to the future. As AI-powered security operations continue to evolve, Drata sees significant opportunities to drive even greater efficiency through agentic workflows. The team is watching the space closely as it matures, with a focus on finding new ways to scale security operations without increasing operational burden.

더 많은 고객 사례 보기

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자