September 2024
Cybercrime now represents an estimated $8 trillion annual cost, making it equivalent to the world’s third-largest economy, right after the US and China. Organisations are increasingly looking to artificial intelligence to strengthen their defences. However, despite advancements, many organisations still struggle with fundamental security measures.
As Nico Sienaert, Senior Security Go-to-Market Lead at Microsoft, states, “Hackers don’t break in, they log in,” highlighting that identity breaches remain common. In fact, 99% of attacks exploit vulnerabilities where patches already exist, revealing a critical gap in basic cybersecurity hygiene. While AI offers potential to enhance security, it also presents new challenges, as Anggarda Prameswari, Security Engineer at Devoteam, notes: “AI can be manipulated; it can hallucinate with false data.”
This article explores solutions like Copilot for Security and how organisations use AI in cybersecurity.
Discover how Devoteam achieved the Microsoft Copilot specialisation.
Today’s Security Landscape
Despite technological advances, cybersecurity experts observe that many organisations still struggle with fundamental security measures. Identity breaches remain among the most common attack vectors. Multi-factor authentication (MFA), while a basic security control, remains inconsistently implemented across organisations.
Anggarda Prameswari confirmed this reality:
“From what I observed from Microsoft Defender, the most frequent alerts are often identity-based attacks. This could start from a simple phishing attempt but laterally move to something bigger like data exploitation, which could end up as ransomware attacks.“
Among these identity threats is a particularly insidious technique: “adversary in the middle.” Adversary in the middle is a type of cyber attack where the attacker intercepts and alters the communication between two parties or more, while keeping everything looking like it’s legitimate. It is dangerous because attackers tamper with your communication without your knowledge, steal your sensitive information and credentials, or even inject malicious content into your systems
This threat is especially problematic for organisations with complex architectures that lack visibility into their environments. “Most companies that have large architectures struggle with these kinds of threats because they are lacking the visibility of what’s happening within the environment,” noted Anggarda Prameswari. In one case, a financial sector client faced major delays in incident response due to fragmented security tools, but after implementing Microsoft Sentinel to unify their security information management, they reduced response time from days to hours.
Even more concerning is that, according to Nico Sienaert, 99% of attacks leveraging vulnerabilities target systems for which patches already exist. This demonstrates that basic cybersecurity hygiene—knowing your digital footprint, implementing MFA, and maintaining patch management—remains a significant challenge.
The Future Threat Landscape
What about future threats? Both experts aligned with findings from the European Union’s Agency for Cybersecurity, which identified supply chain attacks, human error, and skills shortages as the top threats by 2030.
“Supply chain attacks for sure,” said Nico Sienaert. “It’s not for nothing that it’s one of the top requirements in the NIS regulation that’s coming up.“
He also highlighted the persistent challenge of human error and configuration drift. “We are making errors, so we have to look for technology that can help us and make sure we don’t make mistakes”.
Perhaps most alarming is the global shortage of cybersecurity talent, with an estimated 3.5 million unfilled security positions worldwide. This skills gap creates vulnerability that both malicious and defensive AI applications will influence.
AI: A Double-Edged Sword
While AI offers tremendous potential for enhancing cybersecurity, it also introduces new challenges. However, with proper implementation and controls, “AI can help us reduce risks by providing smarter, more intuitive solutions that adapt over time.“
Organisations clearly show interest in AI-driven security solutions, but many are proceeding cautiously. According to Microsoft’s research, 93% of organisations already have some generative AI applications in their environment, yet only 1% of security leaders feel confident in their ability to manage and control these applications securely.
The Rise of AI Security Assistants
Addressing the Shadow AI Challenge
Before organisations can fully leverage AI security assistants, they must contend with the emerging phenomenon of “Shadow AI”—unauthorised AI usage within organisations.
Organisations are often reluctant to fully embrace AI due to legitimate concerns: “What data is accessed? What about model poisoning? What is the outcome of these Gen AI applications?” Nico Sienaert noted. This hesitancy is reflected in Microsoft’s research, which found that while 93% of organisations already have some form of generative AI in their environment, only 1% of security leaders feel confident in managing these tools securely.
Assess your organisation’s AI security maturity to understand your complete journey from risk to resilience.
Anggarda Prameswari highlighted another dimension of this challenge:
“People have actually been using the AI that is publicly available. They will ask questions and then manually incorporate these answers into their work, which is really helpful for them, of course, but it’s also very time-consuming and has security risks because they could potentially expose their sensitive data to public AI.“
How AI and Copilot enhance security
Microsoft’s AI Security Approach
Microsoft’s response to these challenges is its “Copilot for Security” solution—a virtual assistant that helps security professionals work more efficiently while addressing data privacy concerns. Nico Sienaert explains the naming convention:
“It’s not an autopilot, so it will not do everything for you. You’re still in the driver’s seat, you are the pilot, and you have the virtual assistant next to you as a co-pilot.”
According to Nico Sienaert, the goal is “defence at machine speed.” Microsoft’s collaboration with OpenAI has accelerated its AI security capabilities, bringing Copilot branding across its product ecosystem, including M365, GitHub, and even Minecraft.
Early adoption of these tools has shown promising results. Organisations report faster execution of security tasks, improved productivity, and higher quality work. Particularly valuable is AI’s ability to help security professionals create custom queries without specialised query language expertise.
“When you need to build queries, you need to build them from scratch. By having the Copilot for Security, it can build it for you, and you just need to ask it with natural language,” explains Anggarda Prameswari.
This capability allows security teams to automate processes using natural language instructions rather than complex programming.
What is Copilot for Security?
Microsoft Security Copilot (Security Copilot) is a generative AI-powered security solution that helps increase defenders’ efficiency and capabilities to improve security outcomes at machine speed and scale.
Devoteam Cloud Enabler for Security Framework
This capability highlights how AI can empower security teams to streamline operations and enhance their defensive posture. Building on this principle, Devoteam further strengthens AI-enhanced security through its Cloud Enabler for Security Framework.
Devoteam implements AI-enhanced security solutions through its Cloud Enabler for Security Framework. Anggarda Prameswari described it as “a framework that we have developed ourselves within Devoteam to help customers with a structured methodology.”
This framework follows a systematic process:
- Assessment and Advisory: The first step involves understanding an organisation’s unique security challenges and identifying its existing capabilities across key areas such as identity protection, data security, and threat detection.
- Implementation: Based on the assessment findings, Devoteam then helps implement the appropriate Microsoft technologies, creating a tailored security ecosystem.
- Extended Security Team: For organisations with limited internal security resources, Devoteam offers managed services that effectively function as an extension of the client’s security team.
“At Devoteam, we strive to protect organisations with end-to-end security solutions with Microsoft’s latest technologies,” Anggarda Prameswari explained.
“We also maintain close relationships with our customers because we want to help them understand their unique challenges and identify their capabilities within the area of security itself.“
Real-life example: AI Solutions for BYOD Security Challenges
One notable implementation involved educational institutions dealing with complex “bring your own device” policies. When faculty and students use personal devices for school activities, it creates significant security monitoring challenges.
“When these endpoints are not managed well or securely, it could generate false alerts or just a lot of alerts overall,” Anggarda Prameswari noted. By implementing Microsoft Sentinel with more granular control of alerting, Devoteam helped reduce alert fatigue by up to 82%, allowing security teams to focus on genuine threats rather than being overwhelmed by false positives.
This case illustrates how AI-powered security tools can address the increasing complexity of modern network environments, particularly when there’s a blend of managed and unmanaged devices accessing sensitive resources. The ability to intelligently filter alerts represents one of the most immediate benefits of AI in security operations, addressing both the skills gap and the overwhelming volume of security data that analysts must process.
Conclusion: Embracing AI Responsibly
Both experts emphasised the importance of reducing complexity in security environments. Many organisations maintain over 70 different security tools, creating integration challenges and operational inefficiencies.
“Don’t be afraid of Gen AI. Really start to embrace it,” advised Nico Sienaert. “The success of security teams in the future will really be measured on Gen AI to make sure that they can really answer that request of being fast and operating at speed.“
Anggarda Prameswari concurred:
“If you want to be ahead of threats, you need to embrace the latest technologies like AI or Gen AI. It’s not only about adopting AI, but you also need to leverage it effectively to outsmart the threat actors out there.“
Organisations must carefully but deliberately integrate AI into their security operations to keep pace with evolving threats. Working with trusted partners who understand both AI and cybersecurity will be essential in navigating this complex and rapidly changing landscape.

