The launch of integrated security operations center (ISOC) capabilities in Microsoft Defender ‘is one of those game changers that I think can actually shift the game board a little bit,’ Lefferts tells CRN.
Microsoft’s debut Wednesday of new capabilities in Microsoft Defender for security operations teams is aimed at helping defenders recapture the AI advantage over attackers—with the potential to “actually shift the game board a little bit” in favor of the defense, Microsoft security executive Rob Lefferts told CRN.
The launch of integrated security operations center (ISOC) in Defender provides “more of a data-driven view of what’s going on in your estate and what’s going on in the landscape, and [can] tie that together to help teams prioritize,” said Lefferts, corporate vice president for threat protection at Microsoft. “Even with agents to go faster, nobody is going to get everything done. But getting the important things done is really the name of the game.”
[Related: Microsoft’s Project Perception Gives Partners New Security AI Tools]
While organizations have spent the past months and even years tracking the rise of AI-powered threats, he said, many still are not moving quickly enough to prepare for the likelihood that attackers will soon have access to frontier AI-level capabilities—on par with models such as Anthropic’s Claude Mythos and OpenAI’s GPT Cyber models.
“I think people have been very interested in moving and wanting to move. I’m not sure they are moving fast enough in practice yet,” Lefferts said. “And that’s especially true for the organizations that don’t have a strong security focus.”
The introduction of ISOC capabilities in Defender, however, provides “the foundation that you need” to take concrete steps to shore up defenses against AI-accelerated attacks, he said.
At the same time, ISOC—which combines Microsoft Sentinel SIEM capabilities with Defender’s threat protection and XDR capabilities—should go a long way toward “helping partners [to protect] all the customers who don’t have all the extra bandwidth to go study the latest techniques” being utilized by threat actors, Lefferts said.
Ultimately, “with AI, whoever’s got the most data and the best context, wins—and we want to make sure that that is the defensive team,” he said.
What follows is more of CRN’s interview with Lefferts.
What are the key things to know about ISOC?
The way I think about it [is], it’s almost this “everything old is new again”—only it’s new 100 or 1,000 times faster. We’ve talked for years about unification of tools and the 60 to 80 tools that the analyst has to chair-swivel between. But cybersecurity is different. And the world of AI makes it fundamentally different. And I think, unfortunately, attackers are doing a great job of showing us what “different” looks like, and going really fast—starting with the China nation-state actor using Anthropic in order to drive attacks against customers. That has just escalated as we expected it to, because it’s such a productivity win for them. And so, now we see things like JadePuffer, which is a fully automated AI ransomware attack and exploitation. And we expect that to only continue. And so, the fact of the matter is, clearly, defenders need to be going just as fast, if not faster. And we need the tools to really deliver on that. Microsoft—and the industry—has been pivoting hard toward, how do we think about agentic workflows and systems to drive defenders and to accelerate what they can do, and be the Iron Man suit to make them super powered and all these great things. But the truth is that those frameworks will inherit the fragmentation that we give them. And to the extent that we have separate pieces of data and separate tools and separate sets of insights, it will be more work for those agents to deliver value. And this really matters because, actually, I’m very optimistic about what AI can do for security. This is one of those game changers that I think can actually shift the game board a little bit.
How in particular do you see AI as changing the traditional dynamic between attackers and defenders?
The traditional [situation where] defenders have to know everything perfectly, attackers have to know just one thing pretty well, or kind of well—that’s the old game board. And it was clearly slanted to the advantage of the attackers. But with AI, whoever’s got the most data and the best context, wins—and we want to make sure that that is the defensive team. And it should be true. But if the foundation and the infrastructure and the toolset is getting in the way, then it won’t be true. Integrated SOC is all about making sure that it actually comes through and we deliver that solid foundation for agentic security. Fundamentally [this is] bringing together concepts across security teams—and especially within the SOC—around SIEM [security information and event management] and all of XDR [extended detection and response] into one framework, so you really do have this unified threat protection framework. And people and agents can work together from the same foundation.
In the months since Mythos was disclosed, do you feel like people have been educating themselves about how best to get ready for this shift, and now they’re ready for something like what you’re offering?
I get to talk to CISOs and customers from around the planet on how they’re thinking about their own security and their own stance. And I would say, they have been in a state of heightened awareness for 18 months-plus. And they have been learning frenetically, and watching every single step in the landscape. It’s largely been a question about, what do we do? Because, taken to its most extreme, what it says is, all of those things that you’ve been struggling to do for 30 years in security—zero trust, “assume breach,” patch all your devices, know all your vulnerabilities, complete visibility monitoring—do all of that, within the next six months, or you’re going to get owned. And that’s sort of the most terrifying version of it. What’s coming true is more of a direction on concrete steps you can take. And that is a big part of what we’re trying to do here. I think the fundamental thesis is, to get to that agentic security future, you shouldn’t have to rip out everything that you’ve got. You shouldn’t have to start over from scratch. And you shouldn’t force your future to be fragmented and layering across a lot of different [systems]. So from our point of view, the investments with Sentinel and Defender are the building blocks. And because you’ve taken those steps for that foundation, we’re now tying them together and making them comprehensive—and no more split, dichotomy [or] schism between the two. As a concrete example, all of the Sentinel features for SIEM—which includes advanced SIEM features like user entity behavioral analytics and SOAR [security orchestration, automation and response] and case management—those are all now just part of the integrated SOC. And they work equally well over data that is coming from native Defender tools, as well as any data that you’ve ingested into the ISOC. It’s the superset of both—which is exactly what customers need.
It’s a very interesting point that these are not things that people have been successful at—some of these things are things people have struggled with for a very long time. But also, to your point, AI can actually take care of a lot of the manual stuff that was maybe part of why these things have been hard?
That’s right. It can help take care of the manual stuff, and it can help with data-driven prioritization. One of the fascinating behaviors that I’ve watched over the years is the tendency for security teams to be most concerned about the last way they got breached—or, what they heard from their friends in the industry and how they got breached. And so, it becomes very backward-looking. What we can actually offer now is much more of a data-driven view of what’s going on in your estate and what’s going on in the landscape, and tie that together to help teams prioritize. Even with agents to go faster, nobody is going to get everything done. But getting the important things done is really the name of the game.
What’s the opportunity for partners with this?
Of course, Defender and Sentinel have been very highly partner-oriented—not only big API surface areas, but a lot of built-in capabilities that help run across multiple tenants and things of that nature. All of that continues to be true for ISOC. But the point now is just, it should be easier. It should actually really help the partners in terms of not having to span across different tools to go back and forth between SIEM and XDR. They can get customers set up in one environment and then just run it from there.
Overall, do you feel like people have been moving fast enough on these issues?
I think people have been very interested in moving and wanting to move. I’m not sure they are moving fast enough in practice yet. And that’s especially true for the organizations that don’t have a strong security focus. So the two things I’m hoping that we can unleash with this are, one, here’s a concrete thing that you can go do. Try out ISOC. Play with it. This is the foundation that you need. Then the second thing is, helping partners light it up—and this will come in the fullness of time—helping partners light it up for all the customers who don’t have all the extra bandwidth to go study the latest techniques of the JadePuffer automated ransomware, but they’re worried about what is going to happen.





