The Physics of cyber have changed. That’s why we need a new cyber stack.
A stack that can perceive risks across the entire digital estate, reason across vast amounts of context, and take action at machine speed. And we are innovating at every layer of the cyber stack. In July we announced Perception and the work we are doing with agents, the harness, and models.
Today, we are announcing innovation at the signals, sensors, and controls layer. We are bringing threat protection and security operations together with the integrated security operations center (ISOC) in Microsoft Defender.
Security operations and threat protection run as one environment, with shared signals, shared context, and shared controls. And all of this is exposed for agents to reason over and act on, and designed with the practitioner in mind.
Practitioners no longer need to move between multiple systems, multiple data models, and multiple workflows. Instead, practitioners can operate from a unified experience that reduces complexity, lowers cognitive load, and accelerates onboarding and increases efficacy.
By bringing together detection, investigation, disruption, containment, and remediation, organizations can move from reacting to alerts toward continuous protection across their entire estate.
Together, these capabilities are more than product integration. They enable SOC transformation in this era of AI. Learn more from Rob Lefferts:
https://lnkd.in/eS9Vf_ub
Reimagining the SOC for the agentic era in Microsoft Defender | Microsoft Security Blog
Reimagining the SOC for the agentic era in Microsoft Defender | Microsoft Security Blog