“Genie in a Bottle”: How a Global Media Org Replaced a Decade of Manual Security Reporting and Asset Audits with Onyxia’s AI Agent
“
“This is a game changer. I can say to the agent, ‘I see these types of things, and I want you to write a report,’ — and it’s done. That’s the magic, or genie in the bottle: we take the data we have today and get it into something that will really work for us and our organization.”
Senior Director of Infrastructure & Security
Global Media & Education Organization
Key Outcomes and Benefits
400+ Hours Saved
Annually on manual metrics collection and weekly asset analysis
1000 Assets
Audited instantly to protect against a Chrome zero-day
Under 1 Minute
From plain-language question to polished, shareable graph
About the Client
The customer is a mission-driven global nonprofit spanning media, education, and public engagement.
Managing complex digital infrastructure, ranging from global web properties and grant systems to a range of specialized internal systems, the organization is supported by a lean cybersecurity and infrastructure team securing critical assets across a diverse technology environment.
The Challenge: A Decade of Manual Metrics, and No Way to Simply Ask
For close to ten years, the cybersecurity team built its KPIs by hand. The practice began around 2016, when leadership first asked for measurable performance data. Blocked viruses and password audits were easy enough to count. Vulnerability metrics, mean time to recovery, mean time to repair, assessment findings, and stack-wide tool coverage were not. Every quarter, the organization’s lean security team logged into console after console, pulled numbers, and rebuilt the same spreadsheets.
"It would take about two weeks for us to do it each quarter," said the Senior Manager of Security Engineering. "At least."
The harder problem was executive visibility. Infrastructure and security work is invisible precisely when it is working. "All of my teams are hardly seen," the Senior Director of Infrastructure and Security explained. "We're the wizards behind the curtain. It's hard to explain exactly what we do to some of the C-level execs — but it's not hard for us to get rejected when we ask for money."
When he raised it with the CFO, the mandate came back clear: senior leadership and the board needed trended security metrics they could act on.
Many of the platforms on the market, however, were clunky and time-consuming. On one platform, producing a single board-ready chart meant constructing it with query searches. "You had to be fluent in JQL to make it look good," the team recalled. "It was bulky, and the graphs weren't pretty." What they wanted was simpler: describe the answer you need, and have it appear.
Agentic Cyber Governance: Asking for the Answer Instead of Building It
From Request to Report, in the Time It Takes to Ask
Onyxia's AI agent, Nexa, is what the team calls the genie in a bottle — and the reason a decade-old reporting routine ended.
A recent Chrome zero-day showed why speed matters. With roughly 1,000 desktops in a browser-first environment, remediation progress had to be visible in hours, not at quarter's end. Rather than compiling it by hand, the Senior Manager asked for it.
"I ask Nexa to build me a graph over whatever timeframe, and a minute later I've got a graph," he said. "Then I say: tell me the computers that still need to be hit, and separate them into Macs and PCs, because they're different teams. I copy that into an email and send it to them.” One request produced both the executive view and the operational worklist, already split by the team that owns it.
Reporting upward changed just as sharply. When the CTIO asked for program metrics in a specific slide format, the team used Onyxia's AI agent, Nexa, to populate the custom deck with live organizational data and returned it almost immediately. "That's the kind of thing we're actually looking for," said the Senior Director. "We saw this type of graph, so how do we get the data we have today into something that really works for our organization?"
Effective Asset Management: From Four CSV Exports to a Single Question
The same shift, from building answers to asking for them, reshaped daily asset management. Asked about Onyxia's asset coverage analyzer, the Senior Manager called it "entirely a win."
"Before, I would export CSVs from four different systems, and I got good at building VLOOKUPs in Excel," he said. "Now I can just ask which Macs are missing endpoint protection, or which machines don't have the vulnerability management agent — the three components every machine should have."
The automated cross-system audit produces a steadily shrinking exception list for the desktop teams and gives hours back every week. A security engineer pointed to the same ease across the platform: "It's very easy to understand and navigate, from the landing page to the dashboards to interacting with the agent. It gives you room to save time and achieve a lot more in a very short period."
Integrations That Work on the First Try
Connecting Onyxia to a stack that includes Rapid7, Sophos, Jamf Cloud, Okta, Google Workspace and Microsoft Intune took days, not quarters — with no external integrator and no professional services engagement.
"I blinked, and we were onboarded," shared the Senior Manager. "I get a couple of keys or tokens, and the integrations are almost instantaneous — and they work, in ways other vendors don't."
"I had the token, and once you put it in there, it was done," added the Senior Director. Value followed just as fast: "As soon as we had more than one platform ingesting data, I was seeing value immediately."
Continuous KPI Data
Onyxia's underlying KPI library updates continuously, replacing static quarterly snapshots with real-time operational intelligence.
Beyond reporting, these metrics help prioritize day-to-day engineering efforts. "It surfaces the computers they need to target and the remediations that are most important — the ones that are going to give me the biggest bang for the buck, making sure they're not chasing their tails fixing stuff that isn't as impactful," said the Senior Manager.
From the Agent to the Boardroom: Business Alignment & Executive Impact
Mapped to NIST CSF 2.0 and PCI requirements, Onyxia gives security leadership a direct way to demonstrate governance to executive stakeholders. "I can print off a chart and say: here's how our program is going, here's where we have tools, so you're getting a return on your investment — and here's where we see a weakness and may need more," said the Senior Director.
Automated weekly reports keep that picture current between board cycles. After one walkthrough, the CTIO saw the path immediately: "He said, I can get that information into the right type of slide, give this to the board, and they'll understand it. It's going to make our life a whole lot easier — to give something to our board members this year, so they can see the program is advancing, and here's the proof."
Next, the team plans to use Onyxia's security stack map and spend trend views to tie risk exposure directly to budget conversations with the CFO.
A Strategic Partnership for Security Maturity
The team holds a standing working session with its dedicated Onyxia technical lead — less status check than collaboration, surfacing new capabilities and refining integrations.
Asked what they would tell peer security leaders evaluating Onyxia, the Senior Manager was direct: "Buy it now."
The Senior Director framed it as an investment in maturity: "Make the investment in showing how your information security program aligns with the business. This is the best way to show that — through your risk exposure, through budget, and through how you line up with compliance."