Distribuée
AWS Advisory
← All insights

Ecosystem

Wiz vs AWS Security Hub + GuardDuty: what a third-party CSPM really adds

GuardDuty and Security Hub cover threat detection and AWS posture natively. Wiz, bought by Google for $32B in 2026, promises more — at what cost, for which SMB, on what criteria?

· 7 min · #wiz#security-hub#guardduty#cspm#cnapp#ecosystem#security

On March 11, 2026, Google closed its acquisition of Wiz for $32 billion — the largest cybersecurity acquisition in history, and the largest acquisition Google has ever made. Wiz remains multi-cloud and keeps scanning AWS accounts for its existing customers. But the deal reopened a question a lot of French SMBs running production on AWS keep asking: should you pay for a third-party CSPM/CNAPP like Wiz, or is GuardDuty + Security Hub — already bundled into the AWS ecosystem — enough?

Short answer: it depends on the size of your attack surface and what you actually expect from a security tool — isolated event detection, or attack-path understanding. The long answer is worth detailing: what each tool actually does, what it really costs, and at what stage switching pays off.

Three tools, three different jobs

The first point of confusion: GuardDuty and Security Hub don’t do the same thing, and Wiz doesn’t exactly replace both at once.

Amazon GuardDuty is a behavioral threat detector. It continuously analyzes CloudTrail logs (management events), VPC Flow Logs, DNS logs, and — through separately enabled “protection plans” — S3 activity, EKS audit logs, Lambda invocations, RDS connections. It looks for signs of an attack in progress: an EC2 instance port-scanning outbound, an API call from a Tor exit node, an attempted S3 exfiltration. That’s intrusion detection, not configuration auditing.

AWS Security Hub CSPM (relaunched under that name in 2025, with CIS AWS Foundations Benchmark v5.0 support since October 2025) does the opposite: it continuously evaluates your resources against best-practice frameworks (CIS, NIST, PCI-DSS, its own AWS Foundational Security Best Practices), aggregates findings from GuardDuty, Inspector, Macie, Config and third-party partners, and centralizes everything into a single multi-account dashboard. That’s posture, not real-time detection.

Wiz is an agentless, multi-cloud CNAPP (Cloud Native Application Protection Platform) covering AWS, Azure, GCP, OCI and Kubernetes. Its structural difference: instead of treating each finding in isolation, Wiz builds a Security Graph — a graph model (historically built on Amazon Neptune, incidentally) that links resources, identities, vulnerabilities and network exposure to surface toxic combinations: a publicly exposed instance, carrying an unpatched critical vulnerability, holding an over-privileged IAM role with access to your customer data bucket. Each element on its own is a “medium” finding. Together, it’s a critical attack path — exactly what Security Hub, which treats findings as a flat list, doesn’t natively prioritize.

The real differentiator: a flat finding list vs a risk graph

On paper, Security Hub already aggregates GuardDuty + Inspector + Macie + Config. The problem isn’t signal volume, it’s correlation. An SMB DevSecOps team (2-5 people, often wearing the security hat on top of everything else) receiving 200 “High” findings a month in Security Hub has neither the time nor the tooling to manually reconstruct attack paths between them. Wiz does that correlation work automatically and prioritizes on real exploitability, not isolated CVE severity.

The other structural difference is collection: AWS-native tools read directly from control-plane APIs, with no scan latency and no IAM permissions to provision beyond standard AWS service roles. Wiz, being agentless, relies on periodic scans and configuration snapshots — which introduces a delay (typically a few hours) between a configuration change and its detection, and requires setting up cross-account roles and dedicated connectors during initial configuration.

What it actually costs

Cost comparison: GuardDuty + Security Hub vs Wiz for an AWS SMB

GuardDuty and Security Hub pricing is public and consumption-based:

  • GuardDuty: foundational detection billed by usage — roughly $4 per million CloudTrail management events (up to 500M), $1-$1.50/GB of analyzed VPC Flow Logs, $1 per million DNS queries. Optional protection plans (S3, EKS, Malware Protection, RDS, Lambda) are billed separately — for example $0.80/M for S3 Protection, $0.09/GB for S3 malware scanning (reduced rate since February 2025).
  • Security Hub CSPM: $0.0010 per check for the first 100,000 checks/month, tapering down (then $0.0008, then $0.0005/check), plus $0.00003 per ingested finding beyond the free 10,000/month.

For an SMB of 50-150 people with a single AWS account or a handful of accounts under AWS Organizations, the combined GuardDuty + Security Hub bill typically lands between $300 and $1,500/month depending on resource count and enabled protection plans — roughly $3,600 to $18,000/year. These are official AWS rates, valid anywhere GuardDuty/Security Hub are available.

Wiz doesn’t publish an official per-workload price list — pricing is quote-based. Market data observed on AWS Marketplace puts the Wiz Essential tier around $24,000/year for 100 workloads, and Advanced around $38,000/year. For larger volumes (hundreds to a few thousand resources), market reports mention a range of $15-25 per resource per month. Treat these as market-observed ballpark figures, not a quote — always request a priced proposal from Wiz for your exact scope.

Concretely: for an SMB under 100 cloud resources, Wiz costs structurally more than the native combination, often by a factor of 2 to 5. That gap narrows — and can flip in perceived value — as the number of resources, accounts and clouds grows, and especially as the human time spent triaging unprioritized findings becomes the real hidden cost of the native stack.

When GuardDuty + Security Hub are enough

  • You’re AWS-only, with no Azure or GCP footprint to monitor in parallel.
  • Your estate is under 100-150 active resources (accounts, VPCs, instances, Lambda functions, EKS clusters).
  • You already have a team able to manually triage and correlate findings, or a finding volume low enough that manual triage stays manageable (typically after an initial post-audit cleanup).
  • Your immediate priority is compliance (SOC2, ISO 27001, upcoming AI Act controls) rather than hunting sophisticated attack paths — Security Hub natively covers CIS, PCI-DSS and AWS frameworks.
  • The security budget needs to stay proportionate: at this stage, a CNAPP at $24-38K/year often exceeds the rest of the annual IT security budget combined.

When a CNAPP like Wiz becomes worth it

  • You’re multi-cloud (AWS + Azure or GCP), or you know you will be within 12-18 months — Security Hub CSPM now covers Azure at the margin, but remains AWS-first by design.
  • Your finding volume has outgrown human triage capacity — that’s the most reliable signal, more reliable than account count.
  • You run complex Kubernetes/EKS environments where the relationship between configuration, identity and network exposure is no longer readable at a glance.
  • An investor, an enterprise customer, or a SOC2 Type II audit requires proof of attack-path management, not just a checked-box control list.
  • You’ve already run a DevSecOps audit that identified the real bottleneck as prioritization, not detection — that’s exactly what Wiz addresses.

Our read

Most SMBs we audit aren’t short on detection — GuardDuty and Security Hub, properly configured, cover the bulk of the signal. What they’re short on is prioritization and a remediation process. Before signing a five-figure CNAPP contract, the question isn’t “which tool has the best graph,” it’s “are we already getting the full value of what we have.” A DevSecOps audit settles that objectively: full activation of the GuardDuty protection plans relevant to your stack, Security Hub standards configured for your sector, and — only if finding volume genuinely justifies it — a priced recommendation on whether a third-party CNAPP makes sense.

Conclusion

Google’s acquisition of Wiz confirms that the CNAPP market is structurally consolidating around hyperscalers — which could, over time, bring risk-graph capabilities closer to the native tools themselves. In the meantime, for an AWS SMB under 150 resources, a well-configured GuardDuty + Security Hub combination covers the essentials at a tenth of the cost. The real signal for switching to a third-party CNAPP isn’t the size of your budget — it’s the moment your finding volume outgrows what your team can manually triage and correlate.

Sources: AWS Security Hub pricing, Amazon GuardDuty pricing, AWS Security Hub CSPM — CIS v5.0 support, Google completes Wiz acquisition — official announcement.

Found this useful? Share it.

Go further

A topic, a project, a question?

Distribuée supports demanding SMBs on AWS audit, FinOps and security.

Book 15 min