Google Closes $32B Wiz Deal and Unveils Sweeping AI Security Tools at RSAC 2026
Google has officially closed its $32 billion acquisition of cloud security firm Wiz — the largest in the company's history — and unveiled a broad suite of AI-powered security tools at RSAC 2026, spanning agentic SOC automation, dark web threat intelligence and advanced cloud protection capabilities.

Google completes $32 billion acquisition of Wiz and launches AI-powered security operations, threat intelligence and cloud protection tools at RSAC 2026
Google has completed its $32 billion acquisition of Wiz, formally bringing the cloud security platform into Google Cloud's security division in what is both the largest acquisition in Google's history and the biggest-ever purchase of a venture-backed startup. Wiz will join Google Cloud while maintaining its brand and its commitment to securing customers across all cloud environments — including AWS, Microsoft Azure and Oracle Cloud.
The deal closed alongside a broad set of security product announcements at RSAC 2026, covering AI-powered security operations, threat intelligence and cloud protection — a statement of intent as Google positions itself as the defining platform for enterprise security in the AI era.
Thomas Kurian, CEO of Google Cloud, framed the combined offering plainly: "We want to make security a catalyst for innovation, not a barrier. With this acquisition, we will deliver a unified security platform that simplifies the complex task of protecting multicloud environments in the AI era."
Mandiant's M-Trends 2026: Attacks at Machine Speed
Alongside the Wiz announcement, Mandiant — which Google owns — published its M-Trends 2026 report, drawing on more than 500,000 hours of incident investigations conducted across 2025. The findings paint a stark picture of how fast the threat landscape is moving.
The time between initial access and hand-off to a secondary threat group has collapsed from more than eight hours in 2022 to just 22 seconds in 2025 Total Assure — a shift Mandiant attributes to closer collaboration between initial access brokers and downstream criminal operators, with some hand-offs now fully automated. Global median dwell time also rose to 14 days from 11 days, reflecting growing attacker sophistication in evading defences.
A separate AI risk and resilience report from Mandiant Consulting and the Google Threat Intelligence Group described a shift from attackers experimenting with AI toward deploying more adaptive tools and autonomous agents capable of rewriting their own code in real time. The report also spotlighted the growing challenge of shadow AI — employees and teams using AI tools outside formal governance processes, creating blind spots that security teams struggle to monitor.
Agentic SOC: AI Takes the Analyst's Chair
Google also announced new agent-based automation for Google Security Operations, now available in preview. The centrepiece is a Triage and Investigation agent designed to autonomously investigate alerts, gather evidence and deliver verdicts — significantly reducing time spent on false positives and routine alert handling. The agent has already investigated hundreds of thousands of alerts across organisations of different sizes and sectors, helping customers operate more effectively.
Customers will also be able to build their own enterprise-ready security agents, with support for remote Model Context Protocol (MCP) server connections — removing the need for organisations to host their own client infrastructure.
David Gruber, Principal Analyst for Cybersecurity at Omdia, highlighted the scale of market momentum behind the shift: "Few would argue that the progress made in the past 12 to 18 months to put AI to work to improve security operations is remarkable. New research from Omdia shows that 89% of CISOs are pushing to accelerate the adoption of agentic security. Over half of cybersecurity practitioners believe that agentic AI offers a bigger advantage to cybersecurity defenders over the adversary."
Dark Web Intelligence and Threat Relevance
Google has also added dark web intelligence to Google Threat Intelligence, using AI agents and analyst input to sift large volumes of underground data and surface threats relevant to a specific organisation. The capability is designed to cut the high volume of irrelevant alerts that consume threat intelligence teams — and can build detailed profiles of organisations, detecting issues such as compromised access involving subsidiaries, even when threat actors deliberately avoid naming their victims.
Michael Kosak, Director of Threat Intelligence at LastPass, illustrated the problem with existing tools: "In previous roles, I've leveraged several dark web tools and found they averaged over 90% false positives. The new dark web intelligence flips this, filtering noise and connecting dots that no human analyst could see in time."
Cloud and Network Security Updates
Google outlined a series of further changes across its cloud and network security portfolio. In Security Command Centre, AI Protection now integrates with Vertex AI Agent Engine to detect threats targeting AI agents — including unauthorised access and data exfiltration attempts. Model Armour now extends to Google MCP servers, adding controls for prompt injection, sensitive data leakage and tool poisoning.
Sensitive Data Protection has gained AI-based classifications for medical and financial data, as well as object detection for items such as faces and passports. Security Command Centre will also add external exposure management in preview, giving users an outside-in view of their Google Cloud attack surface and surfacing network paths linked to exposed vulnerabilities.
In network security, Google announced general availability for in-band Network Security Integration, preview status for regional firewall policies in Cloud NGFW, and new central policy controls in Cloud Armour. Chrome Enterprise Premium also received updates including browser cache encryption for non-corporate devices and extended clipboard protections across Citrix virtual applications and web-based environments.
The announcements arrive as Google cited Cloud Security Alliance survey data showing that 72% of organisations lack confidence in their ability to execute a secure AI strategy — a gap the company is clearly positioning its expanded portfolio to close.
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.