Key Takeaways
- Wiz Inc. engaged Forward Global US Inc. on August 28 to advocate for CISA funding and agentless Advanced Cloud Protection tools.
- The lobbying push comes as CISA’s workforce contracts while federal cloud and AI security requirements become stricter.
- Google’s ownership gives Wiz Inc. greater policy visibility in a cloud security market shifting toward integrated protection platforms.
Wiz Inc. is expanding its presence in Washington as federal agencies face a widening gap between cloud security obligations and the government’s capacity to support them.
Forward Global US Inc. registered Wiz Inc. as a lobbying client on August 28. The engagement covers efforts to increase funding for the Cybersecurity and Infrastructure Security Agency, including funding that could support the deployment of agentless Advanced Cloud Protection tools. That description closely matches the type of cloud visibility and risk management technology sold by Wiz Inc.
Three lobbyists are listed on the registration. A managing partner at Forward Global US Inc. has filed 62 lobbying disclosures across multiple clients since joining the firm. The other two lobbyists have seven and four filings, respectively.
CISA began 2025 with approximately 3,700 employees, but its workforce has since fallen to between 2,200 and 2,600 (source). At the same time, CISA has issued directives requiring federal agencies to improve the security of cloud environments. Agencies face expanding security directives as the central source of federal cybersecurity expertise contracts.
Additional funding for cloud protection can serve both a public need and Wiz Inc.’s commercial interests. While those goals are not inherently in conflict, procurement teams and policymakers will likely scrutinize how programs are structured, which technical requirements are adopted, and whether agencies retain meaningful vendor choice.
Wiz Inc.’s federal policy work predates its new lobbying registration. Its earlier activity covered science and technology matters, particularly legislation involving cloud computing and artificial intelligence. Wiz Inc. also advocated for cybersecurity funding in Department of Homeland Security appropriations, including CISA programs associated with H.R. 4213, the Department of Homeland Security Appropriations Act for 2026. The measure had not been enacted as of April 2026, although the FY2026 DHS Appropriations Act included $2.6 billion for CISA.
Another proposal, H.R. 5079, would broaden the definition of cyber threats to include ransomware and prepositioning attacks. It would also modernize threat information sharing between federal agencies and non-federal organizations. The bill had been introduced but had not advanced further as of the most recent filings.
Meanwhile, defense policy is raising the compliance bar. The FY2026 National Defense Authorization Act, signed as P.L. 119-60, requires the State Department to develop guidelines for tracking commercial cloud enclave use and establishes security requirements for AI systems operating on cloud infrastructure. It also prohibits Department of Defense contractors from using AI developed by DeepSeek, a Chinese-owned company.
Agentless protection allows security teams to inspect cloud configurations, identities, workloads, and potential attack paths without installing software agents on every individual resource. That approach can reduce deployment friction across sprawling multi-cloud estates, although agencies still need governance, access controls, and processes for responding to findings.
Federal buyers will also view products through established security models. NIST SP 800-207 describes Zero Trust Architecture, including resource-focused access decisions and ongoing evaluation rather than reliance on network location. ISO ISO/IEC 27017 provides cloud-specific guidance for information security controls. Neither standard endorses a particular vendor, but both influence the requirements that cloud security products are expected to support.
Wiz Inc. now approaches this debate from a different corporate position. Google’s reported $32 billion all-cash acquisition in 2025 moved Wiz Inc. from a startup vendor to a Google cloud security subsidiary, while preserving its relevance across cloud-native application protection and cloud security posture management.
That said, the larger issue extends beyond one procurement category. Nation-state activity, ransomware, and threats to critical infrastructure are increasing pressure on federal agencies, states, and private organizations. With CISA operating with fewer employees, private cybersecurity vendors could assume a larger role in implementing federal policy. Wiz Inc.’s lobbying campaign shows how quickly cloud security strategy, appropriations, and commercial competition are converging.
⬇️