Wiz Scan for Good is a new application-based programme offering authorised AI-assisted security assessments to public services, critical infrastructure, nonprofits and other under-resourced organisations. Wiz says its Red Agent can explore public attack paths, but experienced researchers must validate every potential finding before private disclosure.

How Wiz Scan for Good is supposed to work

Organisations apply with a domain or application they own or are authorised to submit. Wiz says accepted targets enter a dedicated environment for two weeks of deterministic attack-surface monitoring and assessment by its AI-powered Red Agent. The programme is focused on externally reachable services rather than unrestricted access to internal systems.

That authorisation boundary is essential. Offensive security automation can move quickly from observing a public signal to testing permissions, identities and application behaviour. Wiz says deeper work happens only under an approved vulnerability-disclosure route, bug-bounty programme or explicit permission. Every candidate issue receives human review, and serious findings are privately reported so the owner can remediate before technical details are shared.

Wiz Scan for Good control loopA three-step flow from authorized scanning through human validation to private remediation.Authorised scopeApproved public surfaceHuman validationMinimal impact proofPrivate remediationOwner notified first

The disclosed results need careful attribution

Wiz reports that the programme helped remediate hundreds of public exposures. It describes cases involving an administrator key that could reach 8.8 million archive files, missing controls around a hospital alert channel, a vulnerable appointment-booking service, exposed data concerning roughly 5,000 elderly residents and administrator sessions at a rail operator.

Those examples show what Wiz says its programme found; they are not independently audited incident counts. Nextgov/FCW reported the same cases and explicitly attributed them to Wiz. Techzine and The Quantum Dispatch separately covered the launch and the human-review structure. Because the affected entities remain unnamed, outside verification of every technical detail is not possible. This package therefore does not infer compromise, exploitation or victim negligence.

Control points in Scan for Good
Stage Stated control Why it matters
Intake Applicant authority and programme terms Prevents testing arbitrary targets
Assessment Deterministic scans plus AI exploration Separates known signals from hypotheses
Validation Experienced researcher review Limits false reports and excessive access
Disclosure Private owner notification Creates remediation time before publication

Why the human gate is the product

AI-assisted security products are often marketed through speed. For public-interest systems, speed without stopping rules can increase harm. A model may pursue an attack path farther than necessary, touch sensitive records or mistake a generated hypothesis for a verified vulnerability. Wiz’s public design says researchers should prove only the minimum impact needed and stop when the finding is established.

That approach parallels Google PageBreak’s deterministic validation loop, though the environments differ. PageBreak tests a company’s own applications; Scan for Good operates across participating organisations. It also connects to Microsoft Defender ISOC’s human-and-agent operating model: automation expands coverage while people retain authority over material decisions.

What participating organisations should demand

Applicants should obtain a written scope listing domains, excluded systems, test windows, permitted techniques, data-handling rules and emergency contacts. They should understand whether cloud providers and third-party services also need permission. A public website owned by one organisation may call infrastructure governed by another.

They should also ask how evidence is stored, who can access it, when it is deleted and whether sensitive material is used to improve models. Remediation reports should distinguish a directly observed exposure from a possible attack path, show the minimum evidence collected and identify which claim came from deterministic scanning, model reasoning or a human test.

Limits of the public evidence

The programme announcement says Google DeepMind supplied Gemini models and CISA offered collaboration and guidance. It does not specify CISA’s operational role in each assessment. Nor does it show a controlled comparison proving that the AI finds more valid issues than expert researchers using conventional tools. The early case list demonstrates claimed reach, not a universal performance benchmark.

Public-interest organisations should therefore judge the programme on governance as well as findings: consent, minimal testing, human validation, timely notification and useful remediation. The best outcome is not a dramatic count. It is a serious risk removed without creating a second incident during the assessment.

Turning findings into durable fixes

Each report should identify the control that failed, not only the exposed endpoint. A leaked credential may require repository-history cleanup, secret rotation and narrower permissions. A missing access check may point to inconsistent authorisation middleware. Fixing one route without removing the underlying failure can leave equivalent paths open.

Public-sector and nonprofit teams should assign an owner and deadline to each confirmed finding, then verify remediation from the same external perspective. High-impact issues may require notification to regulators, service partners or affected people, but that decision depends on observed access and local law. An exposure found during authorised testing is not automatically a reportable breach.

Anonymised lessons should help defenders without exposing the participant. Useful publication explains the weakness class, defensive control and validation boundary while avoiding details that recreate an attack path against systems still being upgraded.

Metrics that reveal whether the programme works

Participants should track confirmed findings per tested asset, false-report rate, time from validation to owner notification, time to remediation and the share of fixes that survive retesting. Raw issue counts can reward noisy scanning. A smaller set of reproducible, material findings may create more public value.

The programme should also record how often the AI proposed a path that researchers rejected, how much sensitive data was touched during proof, and whether an equivalent deterministic check could detect recurrence. These measures turn responsible-testing promises into controls that can be audited.

Governance after the assessment

The participating organisation remains responsible for its systems and decisions. It should document which recommendations it accepted, which it deferred and what compensating controls cover the gap. A free or subsidised assessment does not transfer accountability to the scanner, model provider or government adviser.

Procurement teams should review liability, confidentiality and intellectual-property terms before testing begins. Security leaders should ensure normal incident-response channels remain active during the engagement and that the assessment does not bypass change control. If researchers encounter evidence of an active intrusion, both parties need a pre-agreed escalation path that can pause testing and preserve evidence.

Successful programmes should leave more than a closed ticket. They should improve asset ownership, credential hygiene, public-interface inventories and recurring tests so the same weakness class is detected earlier next time. That institutional learning is the durable benefit of Wiz Scan for Good.

Authorised testing and Private remediationA two-column comparison of Scope and minimal proof with Human review and retest.Two control questionsAuthorised testingScope and minimal proofPrivate remediationHuman review and retest

FAQs

What is Wiz Scan for Good?

It is an application-based initiative for authorised public-surface and AI-assisted security assessments of eligible organisations.

Does AI disclose vulnerabilities automatically?

No. Wiz says researchers validate candidates and report serious findings privately.

Can anyone submit a target?

No. The applicant must represent or be authorised by the organisation and accept the programme terms.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.