Microsoft Security Copilot, an AI-powered security solution designed to assist security operations teams by automating threat detection and response processes
AI is showing up everywhere - copilots, agents, custom apps, and third-party tools. This new dashboard gives security leaders a unified view to view…
Library Management in the Microsoft Defender portal is a new way to centrally manage the scripts and files your SOC uses in Live Response.
Most of what I share here is about security, governance, and control. But if we want those conversations to be useful (and not turn…
AI is no longer “nice to have” in security operations. It’s quickly becoming the only practical way to keep up with attacker speed, alert…
💡 Building a SOC-as-a-Service (SOCaaS) is not just about tools. It’s about designing a repeatable operating model that delivers consistent outcomes across customers, industries, and environments. Many SOCaaS discussions start too deep, too fast. Recently I’ve been asked for a simpler way to frame the Microsoft-aligned approach upfront. This infographic is a bird’s-eye view to…
Part 3 is addressing the inevitable next question: how do we govern AI itself so copilots and agents don’t become the newest - and…
Microsoft Security Copilot is now included in Microsoft 365 E5, what this means for customers? A simple scenario matrix is here to answer this…
"Are we ready for the inevitable?". Part 2 is my practical answer: a human-in-control model where built-in intelligence across the Microsoft security stack and…
CCS framework helps you protect, manage, and measure Microsoft 365 Copilot and agents - tying outcomes to controls, clarifying ownership, and sequencing a safe…
Part 1 of a multi-part series: how unified SIEM+XDR, AI, and agents shift security to human-on-the-loop operations—automatic disruption, graph-based triage, and governed action.