How Paramount Helped Shape the Blue Agent They Trust

How do you build confidence in AI for security operations? Paramount Skydance did it through partnership. By sharing continuous feedback and validating every investigation, the team helped improve the Blue Agent while accelerating investigations and strengthening collaboration across teams.

Paramount

Industrie

Medien

Region

Globale

Wiz-Produkt

Wiz CloudWiz DefendWiz Code

Anwendungsfälle

CSPMCDRWiz Agents
Bereit für den Start?
Demo anfordern

For most security teams, trust in AI isn't something that appears overnight.

It's earned.

At Paramount Skydance, that trust came through collaboration — through honest feedback, direct conversations with engineers, and a shared commitment to making cloud threat detection work in one of the most complex environments in media.

Paramount Skydance is a global media and entertainment company serving audiences across 180+ countries. Mid-integration following a significant merger, its cloud environment is both large and fast-moving — workloads consolidating across multiple providers, infrastructure evolving in step with the business, and a SOC team responsible for maintaining visibility through all of it.

As an early adopter of Wiz Defend and the Blue Agent, Paramount's security operations team didn't just use the product — they helped shape it.

The Challenge: Building Confidence in Cloud Detection

Paramount operates a global, follow-the-sun SOC with analysts across North America, EMEA, and APAC. The team brings deep expertise across identity, endpoint, and network security, but cloud security presents unique challenges for every modern SOC.

At the same time, Paramount was navigating significant change across its cloud estate. Workloads were moving, applications were being deployed, and infrastructure was evolving rapidly as part of broader business transformation initiatives.

In environments like these, distinguishing between legitimate operational activity and potential threats requires deep understanding of organizational context.

"We were relying on Wiz to help guide us through cloud security issues in a landscape that was changing constantly," said Julia Werner, SOC Manager at Paramount.

The team knew AI could play a meaningful role in accelerating investigations—but only if analysts could trust the conclusions it produced.

A Partnership Focused on Trust

From the beginning, Paramount approached the Blue Agent as a collaborative effort.

Rather than simply consuming Blue Agent-generated verdicts, the team worked closely with Wiz product managers and engineers to provide detailed feedback on how investigations were being analyzed within their environment. That feedback helped inform product improvements and ensure the Blue Agent could better understand the realities of large-scale cloud operations.

What made the difference was that Wiz took the feedback seriously. They listened, they incorporated it, and we saw those improvements come to fruition.

Julia Werner, SOC Manager, Paramount

The result was not only a better experience for Paramount, but a stronger product overall.

By combining analyst expertise with continuous product iteration, Paramount and Wiz helped establish the trust necessary for AI-assisted investigations to become part of daily operations.

The Blue Agent as Part of Every Investigation

Today, the Blue Agent plays a central role in Paramount's cloud investigation workflow.

Threats are investigated directly within Wiz Defend, where analysts can review captured events, understand attack context, and immediately see the Blue Agent's assessment, reasoning, and confidence level. Analysts review the verdict, validate the supporting evidence, and add any organization-specific context when necessary. 

That context extends well beyond the individual detection. The Blue Agent incorporates knowledge of Paramount's cloud environment to provide richer investigative context automatically. It can identify engineers associated with activity in the logs, summarize their recent actions, provide historical context for internal IP addresses, surface previous detections tied to the same engineer or behavior, and even reference how similar detections were resolved in the past. Instead of manually piecing together that history across multiple tools, analysts begin investigations with organizational context already assembled and enhanced by each subsequent investigation.

For Paramount's team of experienced analysts, the value is not automation for automation's sake. It's having relevant context and investigative reasoning available before an analyst even begins their review. The result is a faster, more consistent investigation process that still preserves human decision-making.

The Blue Agent provides the foundation. Analysts provide the final judgment.

Building Trust Beyond the SOC

One of the most meaningful outcomes extended beyond security operations.

During periods of large-scale cloud migration activity, the SOC frequently needed to engage cloud engineering teams to validate suspicious behavior. As infrastructure changes accelerated, those interactions became more frequent and more difficult to navigate.

Security teams were trying to determine whether activity was malicious. Cloud teams knew much of that activity was planned.

As investigation quality improved and analyst confidence increased, those conversations changed.

The SOC gained greater confidence in what truly required escalation, while cloud teams gained confidence that investigations were grounded in a deeper understanding of their environment.

Socially, the Blue Agent has helped us grow trust between the teams. They've seen the tool improve. They've seen our understanding improve.

Julia Werner, SOC Manager, Paramount

For an organization as large and distributed as Paramount, that trust is more than an operational benefit. It's a force multiplier for security effectiveness.

Making AI Worth the Investment

For Werner, one of the most important measures of any AI system is simple: the value it returns relative to the resources it consumes.

Security teams already face alert fatigue, tool sprawl, and limited analyst time. AI should reduce that burden—not add to it.

As the Blue Agent matured, Paramount saw that balance shift decisively in the right direction.

Instead of requiring analysts to manually assemble investigative context from multiple sources, the Blue Agent surfaces relevant information, explains its reasoning, and helps analysts reach conclusions faster.

The ratio is worth it now…[The Blue Agent is] giving accurate information, it helps us, and it saves time.

Julia Werner, SOC Manager, Paramount

Looking Ahead

As Paramount continues to expand its use of Wiz Defend and the Blue Agent, Werner sees opportunities to further streamline analyst workflows.

One future area of interest is expanding the Blue Agent's ability to recognize expected organizational activity through its growing understanding of Paramount's environment. By incorporating that accumulated context into its investigations, the team sees opportunities to further reduce investigative overhead while keeping analysts focused on the activity that matters most.

The goal isn't simply to automate investigations—it's to make detections increasingly aware of organizational context, allowing analysts to spend more time investigating genuine threats and less time reviewing expected internal activity.

What the Blue Agent is doing right now in Wiz is perfect. That's exactly what I want for a SOC team.

Julia Werner, SOC Manager, Paramount

For Paramount, trust wasn't built through automation alone. It was built through collaboration, transparency, and a shared commitment to improving outcomes.

And in the process, Paramount helped shape the Blue Agent they trust today.

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement