惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
博客园_首页
博客园 - 【当耐特】
V
Visual Studio Blog
博客园 - 叶小钗
月光博客
月光博客
美团技术团队
J
Java Code Geeks
小众软件
小众软件
Y
Y Combinator Blog
博客园 - Franky
Martin Fowler
Martin Fowler
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
阮一峰的网络日志
阮一峰的网络日志
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
云风的 BLOG
云风的 BLOG

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Introducing Posture Issues: Transform Security Findings i...
Bandhna Bedi, Eyal Golombek, Shashank Golla · 2025-11-12 · via Wiz Blog | RSS feed

Cloud environments can generate millions of security findings, from critical vulnerabilities and exposed secrets to sensitive data risks. Wiz already helps organizations cut through that noise with Risk Issues, which correlate toxic combinations across risk domains to reveal the most critical attack paths in your cloud. 

Risk Issues highlight the most urgent risks in your environment and help cloud security teams prioritize and fix the issues that matter most. This focus on Risk Issues has enabled security teams to focus on what matters most, making zero critical issues a reality, a milestone already achieved by 50% of Wiz customers today.

Today, we are introducing Posture Issues for your vulnerability management and data security teams. This new capability is built for the other side of the security challenge: findings that aren’t immediately exploitable but still need to be addressed to maintain a strong security posture over time. Unlike Risk Issues, which span multiple domains, Posture Issues group findings within a single domain, such as vulnerabilities, secrets, or data. By consolidating many findings into a single actionable Issue, Posture Issues give security teams a structured way to align with internal programs, meet compliance requirements and SLAs faster, tackle backlogs at scale, and measure long-term progress in security posture.

Posture Issues: A Framework for Managing Security Debt

For teams focused on continuous security, whether managing vulnerabilities or remediating data and secrets, the challenge lies in handling the volume of findings needed to maintain compliance and strong security hygiene. The unstructured volume of these findings makes it hard to maintain and measure real security maturity. While cloud security teams are focused on handling the most urgent risks in your environment (Risk Issues), a backlog of CVEs, data, or secrets remains to be fixed. This creates technical debt and leaves vulnerability management and data security teams struggling to prioritize and take action on this backlog to maintain their compliance or hygiene status. 

The Hidden Cost of Posture Debt

Every unpatched CVE, non-critical misconfiguration, or policy gap that isn’t part of a toxic combination of risk rolls into a growing backlog - your organization's security debt. That debt creates three major workflow challenges for your security teams:

  1. Compliance gridlock: Meeting compliance requirements and SLAs often means tackling thousands of low-to-medium findings. Without structure, validating and remediating for this long tail becomes a manual, time-consuming process that slows audits and drains team capacity.

  2. Unmanageable volume: After addressing critical Risk Issues, teams still face a flood of findings. When everything is lumped into one list, it makes it hard to prioritize those findings and show real progress on security hygiene.

  3. Remediation Consolidation Gap: Many teams struggle to pinpoint a single fix that resolves multiple related findings. Without grouping findings by the actual remediation step, they face fragmented noise instead of clear priorities, making it hard to know what’s done and what still needs attention.

Reclaiming the Backlog: A New Workflow for Security Maintenance

Posture Issues gives security teams a framework for disciplined, strategic maintenance:

  • Structured remediation path: Secrets, vulnerabilities, and data findings that aren’t immediately exploitable are organized with Posture Policies. This turns a noisy list into focused, manageable projects that can be assigned, tracked, and worked through efficiently.

  • SLAs and compliance made visible: By promoting Findings into Posture Issues through Posture Policies, your remediation teams can associate remediation activity directly to SLAs and audit requirements, as defined by your Posture Policies. The result is clear, auditable proof of long-term security hygiene and a much simpler path to demonstrating compliance.

  • Customizable prioritization of the backlog: Use Posture Policies to define your own prioritization logic. For example, you can automatically generate Posture Issues for all vulnerabilities with a CVSS score of 8 or higher that have a fix and a public exploit in production environments, and require they be patched within 14 days. This helps teams manage their backlog intelligently, align work with business priorities, and measure progress against them.

Posture Issues in Action

Posture Issues are driven by Posture Policies. These policies define how findings in a specific risk domain, like vulnerabilities, are grouped and promoted into Posture Issues. Wiz provides ready-to-use policies, and customers can adjust or create their own to match their needs.

Let’s See Posture Issues in Action:

264 Vulnerability Findings are grouped together by a Posture Policy related to a Windows OS patch.

Get Ready to Strengthen your Long-Term Security

The launch of Posture Issues is a step forward in the overall security of an organization. It gives teams a sustainable workflow to build and maintain security maturity: 

  1. Achieve a Zero Criticals Baseline: Use Risk Issues to remediate all immediate, high-risk attack paths and eliminate toxic combinations. Celebrate this milestone by joining Wiz’s Zero Critical Club.

  2. Continuously harden posture: Once Zero Criticals Risk Issues are achieved, Posture Issues provide a clear way to tackle the long tail of findings and begin the continuous process of security hygiene, hardening your cloud, and staying on track with compliance targets.

This structured approach moves teams from reacting to Issues to operationalizing long-term resilience. Wiz Cloud Advanced customers can now explore Posture Issues and take a more structured, sustainable approach to security hygiene. 

Ready to address your long term security posture? Wiz Cloud Advanced customers can start using the new capabilities in the Wiz Platform. Learn more about Posture Issues (login required).