ONAM SECURITY
Choosing a CNAPP · August 2026

You already have a ranked list.
Can you put a number on the top item?

Every serious cloud security platform will rank your findings. The question that decides a budget is what the ranking is denominated in.

Wiz ranks by toxic combinations on its Security Graph — in their own words

“a single list of prioritized issues of toxic combinations of cloud and AI risk that have a high probability of being exploited”

Source: https://www.wiz.io/platform · accessed 2026-08-07

A score ranks findings against each other. A dollar figure ranks them against everything else you fund.

A score answers
Which finding is worse than the others?
A dollar figure answers
Is this worth more than the control we were going to renew?

Onam prices the whole attack path in FAIR/ALE dollars

0–100 $ per path / year

Not a severity label. A defensible figure per path, built on FAIR — the open standard for putting a dollar value on cyber risk, published by The Open Group — expressed as ALE, annualised loss expectancy. The number your board already knows how to weigh.

Fix the choke point, not the row — one change breaks many paths

A chain breaks at any link. A choke point is the one node that sits on the most paths, so a single change ends attacks that three separate tickets never would. Ranked by dollar exposure, across 7 clouds on one graph and one data model.

instance metadata role data one fix here …and every path through it is gone

What we don't do

Onam has no live runtime enforcement. Posture and audit-log detection, read-only, with nothing deployed on the workload. Wiz runs the Wiz Sensor — “Runtime protection from the Wiz Sensor stops threats and provides deep, real-time threat detection” — and does more at runtime than we do. That is a real gap, not a positioning choice. If inline blocking is what you are buying, buy that.

Run the same seven questions against both of us

We publish the checklist that includes our competitors, because a decision you can defend is worth more to us than a deal you regret. Ask Wiz these. Then ask us.

  1. Can it price a finding in dollars your board already understands?
  2. Does it rank across clouds on one scale, or one list per cloud?
  3. Does it show the whole attack path, or the individual finding?
  4. Can it name the one fix that breaks the most paths?
  5. What must you deploy on the workload — and who owns that rollout?
  6. How long from connecting an account to the first real finding?
  7. What does it honestly not do?
Find your true north.
9,853 CSPM posture rules · 7 clouds · 78 compliance frameworks · read-only, agentless
onamsecurity.com — every Wiz statement above is quoted from their own public page, dated. Verify it.