Build vs Buy: Why Google Bought Wiz Instead of Building Cloud Security In-House

Written by Erwin Castro — Founder & Editor, The CODEW
The CODEW Build vs Buy Series | August 23, 2026


The CODEW Build vs Buy Series cover


In 2024, Wiz turned down a $23 billion offer from Google. Two years later, on March 11, 2026, Google closed a deal for the same company at $32 billion — nearly triple what Wiz's own investors had valued it at just two years before, and the largest acquisition in Google's 28-year history. For a company with Google's engineering resources and a two-decade head start in cloud infrastructure, that's a striking amount to pay for something it could, in theory, have tried to build itself. The reasons it didn't tell you almost everything about why cloud security has become too fast-moving and too specialized for even the biggest tech companies to build from scratch anymore.

What Google Actually Bought

Wiz sells what's called a cloud-native application protection platform, or CNAPP — a category that consolidates what used to require a dozen separate security tools into one. Instead of running separate point products for vulnerability scanning, misconfiguration detection, identity risk, and runtime protection, Wiz scans an organization's entire cloud footprint — across AWS, Azure, Google Cloud, Oracle Cloud, and Kubernetes — and maps the specific combinations of small issues that actually lead to breaches. It does this agentlessly, without requiring software installed on every workload, which is part of why it grew as fast as it did: enterprises could get meaningful visibility in hours rather than the months a traditional security rollout usually takes.

That combination took Wiz from roughly $100 million to over $1 billion in annual recurring revenue in under six years — one of the fastest paths to a billion dollars in ARR any software company has posted — with half of the Fortune 100 already customers by the time the deal closed.

Why This Wasn't a Build Decision

Google has built plenty of security tooling internally, and it also bought its way into the category before with Mandiant in 2022. So this wasn't a company with no cloud security strategy suddenly panicking. It was a company that had already tried to build and partially buy its way to Wiz's specific capability, and concluded it still needed the real thing.

The core problem with building a Wiz internally is that Wiz's product only works because it's multicloud by design — it protects workloads across AWS and Azure as fluently as it protects Google Cloud. A security product Google built in-house would start from an obvious credibility problem: would enterprises trust Google's own security tool to honestly flag risks in a competitor's cloud, or would they assume it's engineered to make Google Cloud look safer by comparison? Wiz spent years building trust as a neutral third party specifically so it wouldn't have that problem. That kind of trust doesn't transfer if you build the same technology under a cloud vendor's own name from day one.

The Trojan Horse Bet

Here's where the acquisition gets strategically interesting rather than just expensive. If Google locks Wiz down to protect only Google Cloud workloads, it destroys most of the value it just paid for — half the point of Wiz was that enterprises trusted it precisely because it wasn't loyal to any one cloud. So Google has committed to keeping Wiz's brand and its multicloud commitment intact, continuing to support AWS and Azure customers as before.

The bet underneath that decision: give customers excellent security everywhere, and the tighter native integration with Google Cloud will naturally pull more of their workloads there over time, without Google ever having to force the issue. It's a slower, more patient version of vendor lock-in — winning through better integration rather than through withholding the product from rivals' platforms.

A Year in Regulatory Review — and No Scars

The deal took exactly one year from announcement to close, clearing antitrust review in the U.S., the European Commission, Australia, Israel, Saudi Arabia, South Africa, and Türkiye along the way — unconditionally, with no forced divestitures or behavioral remedies. That's notable given how sensitive regulators have gotten about large platform owners absorbing fast-growing independent companies. The unconditional European clearance in particular was read as a signal that the deal would survive without the kind of strings that have complicated other recent tech mega-deals. Antitrust risk didn't kill this build-vs-buy calculation, but it's the reason the acquisition took a full year rather than closing in weeks.

What It Signals for Everyone Else

For CrowdStrike — which has been building out its own cloud security capability through smaller acquisitions like Bionic and Flow Security — the deal raises the bar considerably. CrowdStrike's core strength remains endpoint detection, not cloud-native security, and now has to compete with a $32 billion, Google-backed multicloud platform in a category it was still building toward. More broadly, the deal put a very public number on what "buy the category leader" actually costs at the top end of the cybersecurity market — and it's a number every other hyperscaler evaluating its own cloud security gaps now has to measure against.

The Takeaway

Google didn't buy Wiz because it lacked security engineers. It bought Wiz because the specific thing that made Wiz valuable — genuine multicloud neutrality, six years of accumulated trust, and a product built from the ground up to work equally well on a competitor's infrastructure — isn't something a cloud vendor can credibly build under its own name, no matter how much engineering talent it throws at the problem. Tripling a rejected offer from two years earlier is an expensive way to learn that lesson, but for the largest acquisition in Google's history, it's a bet that paying up for trust beats trying to manufacture it.

Build vs Buy is The CODEW’s strategic editorial series that examines the trade-offs between developing custom technology and adopting commercial software. Each article provides objective, enterprise-focused analysis to help business and technology leaders make informed investment decisions. From AI platforms and enterprise software to cloud infrastructure, cybersecurity, and developer tools, every decision involves balancing cost, speed, flexibility, scalability, security, and long-term business value. Rather than recommending a one-size-fits-all solution, this series evaluates each scenario based on technical requirements, business goals, available resources, and total cost of ownership.

Build vs Buy: Why Google Bought Wiz Instead of Building Cloud Security In-House Build vs Buy: Why Google Bought Wiz Instead of Building Cloud Security In-House Reviewed by Erwin Castro on Sunday, August 23, 2026 Rating: 5
CRM + marketing automation + payments in one integrated platform. Helps small businesses streamline sales and automate the follow-up work that falls through the cracks. Get Keap