Microsoft Corporation (MSFT) Earnings Call Transcript & Summary

May 2, 2024

NASDAQ US Information Technology Software special 113 min

Earnings Call Speaker Segments

Jan Mickos

attendee
#1

Good morning, everyone, and welcome to the Microsoft Discovery Day, where we're going to today discuss about the topic of modernizing your security operations center. I'm Jan Mickos, Director of Managed Services at Nixu, a DNV Company. And with me today, I have Olli Paasikoski, who is our Security Architect on the Microsoft product, [indiscernible] technology family and related services. I will start off today by presenting on the more strategic level around how the cybersecurity concerns out there have been evolving and how we see them evolving going forward, a bit more on the kind of strategic level of how we are going to develop our services and offerings going forward and what that brings to our customers from a service delivery point of view. After that, much more technically-skilled Olli will take over and go through how we do this on a more practical level for the rest of the 2 hours. That's roughly the agenda today. So more or less 2 hours, then we will spend now then on the topic of modernizing security operations. So I'll start off with the top cybersecurity concerns. And of course, there are many more, but we have 3, ones that we selected here to talk about and of course, the major trend, you could say, is that attacks are on the rise regardless of type really, but here we highlighted ransomware, attacks that are constantly increasing. And you see there a 130% increase of ransomware attacks. And also, you could say that not only the amount of the attacks are on the rise, but also they get more and more complex and skilled in execution also on the threat side and thus also they succeed quite often these days, which, of course, then leads to costs. So there you can see as well that the average cost of recovering from a ransomware attack is currently at roughly $1.85 million. And of course, that varies a lot on -- depending on the case at hand and it can be way more or in best cases, way less as well. And there, of course, the decisive factor is how well you are prepared for that day. Also a clear trend that you can see then is more touching on the skill and the availability of skilled staff and 2 out of 5 security leaders on the survey here say that they are seeing high risk because of the fact that they have a clear shortage of skilled staff. And this, of course, is one reason why service providers like ourselves exist in the market. So we can help you out there as well with providing services without the need to have own staff to everything. Going to take a couple of kind of steps backward really here. So in our view, this all basically started with the invention and execution of adoption of digital transformation. And if you think about digital transformation, of course, the core aspect and value that everyone sees there is to get better productivity by digitalizing processes, services, offerings and so forth. And that's, of course, a great thing for everyone involved. However, from a security standpoint, of course, every digital service you introduced to the soup or component you add to the architecture, it adds complexity inherently. So regardless of whether they are done well or poorly they will all add complexity, nevertheless. And that also -- it increases the attack surface, again, regardless of whether they are well protected or less well protected. It's a kind of clear fact of life that the attack surface as such is increasing, which, of course, then drives also the cyber spend. So on the previous slide, we had the cost of a ransomware attack and recovery from that. But at the same time, the cost of protecting -- proactively protecting against these threats is also on the rise. And that's, of course, why we need then to think about how to tackle this ever-growing attack surface at an affordable way. Nevertheless, risk as a result of all this is also on the rise. And I'll talk a bit more on the following slides on why that is and how to maybe tackle it. It's very much a kind of cross domain trouble as well as highlighted on this slide. This is a very much simplified picture where if you imagine yourself there in the middle, maybe a CSO or a CIO is responsible for cybersecurity within your respective organization. You will, of course, have a number of teams in-house or outsourced who produce these basic IT services that you see here for your organization, be it in workstation or digital workplace solutions or be it networks or LAN, WAN, whatever. Be it on-premise service -- servers within your capacity, within your own data centers or maybe your IT service providers, data center or then in the cloud. Regardless, typically, you have a number of teams that were more or less in silo and responsible for the delivery of these respective services. If you think about it from a security point of view, of course, all of these have tons of security controls that are there to be used to play the kind of risk management game. But you are tasked with the challenge of keeping them all together so that they play in concert. Of course, then when you -- in real life, you probably have not only one service provider to add to the suite, but rather many and they all have their own tasks set out in their agreements and contracts and that they execute on. And of course, this again adds to the complexity. So we really need to have this work together and in concert from a security point of view in order to mitigate that risk. Then what we then basically kind of say is that to do this, it becomes -- of course, there's a lot of technical aspects and with tools from the likes of Microsoft that are already integrated from the security tools. So it's a comprehensive stack of security tools that is pre-integrated, That, of course, helps us a lot and Olli will be talking about that in more detail that how that plays out in practice. But nevertheless, the kind of the process and the agreement level remains. And there, we are talking about a concept called Security Fusion where the aim is actually to raise the bar and the abstraction level to a point where we integrate the processes -- security processes, specifically, that is across this ecosystem of partners and internal teams to get holistic cybersecurity approach and defense, where also we then avoid double cost that is easily introduced from being -- delivering these services within -- from within silos. In addition, of course, to the kind of attack trends, we have other trends going on here. So of course, there's tons of regulation popping up, be it NIST 2 or something else that is or emerging or only in the works yet, but nevertheless, it's ever increasing. And that, of course, again, creates a lot of let's say, requirements for the operation that doesn't really make anything more simple, but rather adds to the complexity again. And you need to, of course, have a then a holistic again approach on how you manage compliance throughout your supply chains and ecosystem as well. In addition to that, of course, every component you add to the architecture, be it your own or partner provided. From a technical point of view, we'll also add vulnerabilities. And thus, we see also huge numbers. I think it was something like 500% annual growth in vulnerabilities on a global scale year-to-year, which is huge. So that we also need to manage in an efficient manner. And of course, most organizations also have legacy when it comes to IT infrastructure and applications and so forth. If you're lucky enough and your relatively new organization and born in the cloud, then you're better off because you maybe have all these pre-integrated tools available to you and less problem with existing legacy. But nevertheless, the applications and services you do develop now maybe in your lines of business as also the IT organization is typically shifting from a centralized IT more to a decentralized IT, where business IT or whatever you call it, within the organization, actually lives in the lines of business and develops their own IT solutions and digital solutions on the fly as well. And of course, what we develop today is tomorrow's legacy as well. So something to keep in mind. So what do we actually need to do to solve this thing? So one of my favorite topic is posture management, security posture management. But it kind of sounds simple enough, but if you think about it in a even slightly more complex environment where we have more than one operator and a service provider and you have several solutions. You have your security posture extends not only over your infrastructure layer, also your business applications and business processes and so forth and all configurations related, et cetera, it becomes a fairly complex thing to get playing out. And this is where I basically state that it's not a technical problem really. It's more of a process -- procedural problem, it becomes kind of an outsourced model, it becomes a contractual and kind of RACI matrix type of problem. So who is really in charge of making sure that the security posture is efficiently managed across our whole business process for instance. And typically, the answer will be you there as the CSO or CIO because everyone else is acting in accordance to their specific mandate, which is typically organized around kind of IT service power, if you like, and not from a cybersecurity perspective at all. Even though the controls are typically contained within the -- within those services, they delivered from these individual towers or silos. You probably have one or more managed services, service providers and there as well, you need to coordinate across the Board. They can help you greatly as ourselves as well with the staffing problem. But at the same time, of course, it's again one new contractual interface towards the other players in the value chain and does adds again to the complexity. And therefore, if you have several, you will have several interfaces. And a lot of more complexity. Vulnerability management, the same thing applies there. So it's kind of one of the oldest and maybe least s*** processes in cybersecurity patch management, but at the same time, that's one of the most efficient ones and at the same time, one of the most neglected ones. So vulnerability management is, of course, not only about patching. It's also about prioritizing, for instance, of what to patch and when and how to manage all the good reasons why you can't patch a certain component at any given time and how do you then mitigate that residual risk, if that's the case and et cetera, et cetera. And that's whole, I would say, process of its own, again, that we can, as an industry, I would say, up to game quite a bit still even though it's been around for quite a while. Of course, you need to be aware of the threats there. So you need relevant and actionable threat intelligence at any given time in order to know what should I be doing and from what should I be protecting my business. And of course, then you need to be able to detect and respond in a timely manner when stuff hits the fan and the purposefully say win because it's assumed from the numbers started as well as more likely that it's a matter of when than if. And of course, all of this, you then need to be able to implement holistically across all of your IT landscape regardless of who is producing it and in what type of a contractual arrangement and so forth. And this, in essence, is what we call Security Fusion at Nixu. So Managed Services from our point of view is -- and if you're going back to the security operations where we started off is, of course, in many ways, we provide a lot of those capabilities as a service. And our vision is to kind of have the Security Fusion as the guiding star for us, and it's at the core of our strategy when we develop our services. And so it goes way beyond the traditional detection response. And we see there's a maturity game as well. So basically having the essentials in place typically understood kind of as key components of any Security Operation Centers, of course, the security monitoring, so the ability to detect, extending that maybe from the very early days to network and endpoint based solutions as well to drive that forward and of course, have the ability to respond. From a maturity point of view, I would call this the old order, old s*** really moment or level of maturity because this is where you actually get visibility to your problems. They won't actually go away and does this is just the first stepping stone on your way in maturing security operations. So of course, then you will be busy and you need to be running faster. And then you have other services, then these are from our service portfolio, just giving you examples on how to then build the maturity there. But then you add elements like the continuous vulnerability management that we talked on. We have the managed XDR service there, so which Olli will be going into a much more detail. We have the Threat Intelligence Service and Continued Security Posture Operations Services as well. That is when you start kind of patching and closing the holes before they turn into security incidents. So the reactive game of the SOC becomes a proactive game. Then of course, in most cases, when this is played out to the full extent, you will realize that, okay, we may be now fixed your cloud-based IT infrastructure to the very last bit and also your workstations and servers are now hard and then they are configured properly and so forth, vulnerabilities are managed and all fine and well. But actually, your crown jewels, they are not -- well, they are on that infrastructure, of course, but they are actually within your business applications or if you're in an industrial industry, you will have an OT, operational technology environment where your actual crowned jewels from a business perspective reside. And then the kind of the risk becomes more that of valid identities and credentials being misused within those applications, and that's the actual business, which then that you will lose, for instance, in intellectual property or something lose availability of your power plant or whatever, depending on the industry. And that, again, calls for a totally different type of set of controls, again, so starting from the -- we have, for instance, something we call the applications SOC, so pretty much the same maturity journey starting over again but from a business process and business transaction point of view. So how would we -- what would we need to be detecting from a business perspective in your ERP system or CRM system and so forth, building the use cases based on that, and then implement it, again, systematically throughout these steps to make certain that you have the ability to detect and respond when this potentially is happening. Then when you have done all of this you're in a quite good place already, of course, then you still have the kind of nation-state sponsored threat actors and other very advanced threat actors and then the realization is that, okay, they actually -- they have all the time in the world and also almost all the resources in the world, and they go really low and slow. Thus, they are really hard to detect and we need to come up with other kind of strategies or tactics to play that game. And that's where then the services like Advanced Threat Hunting and Advanced Defensive Strategies come into play where it becomes more of a hypothesis based, threat intelligence-driven operation where we kind of create hypothesis around what could be going on if -- how could we be able to detect if a nation-state sponsored threat actor would be seeking to steal our intellectual property or sabotage our operations and then basically implement customer controls again throughout the stack to see whenever that is happening. But then the real ultimatum of the security fusion then is, as I said earlier already, it becomes a matter of process integration. So how do we implement all these processes needed to deliver all of these capabilities throughout not only our own organization, but also the full network of your IT service providers and other parties that have a stake in this value chain. And how do you then play that in concert from a security risk management point of view. And that becomes a lot of contractual stuff, roles and responsibilities, processes, process integration and so forth. And then it -- at the best case, it becomes a business enabler rather than just the cost role on the balance sheet. So how does that look in practice? So this is a really much simplified slide that kind of demonstrates the setup really. But if you think about SIAM, Service Integration and Management Setups in traditional IT service delivery perspectives. This is pretty much the same, but from a security point of view. And you, of course, could ask yourself, okay, I have an IT SIAM and they actually have a security function there as well. So why doesn't that cut it. And it's a really good question, but I think the real answer to the question is that because all the service components in the holistic SIAM solution there are -- they are delivering their primary task, which is delivering that specific IT service. They don't have the skills nor the capabilities to actually manage the security of it because it kind of cuts the stack in a 90-degree angle towards their primary task. And that is why you actually need a kind of a separate SIAM setup for the security aspect of it. And then when you look about -- so how to set that up, then we have then simplified it a lot. So you are there as the ultimate owner of your IT security stack. You are there on the top then we, as Nixu would be there in the middle then and what we actually would do then for you is to set up a service management and office maybe, if you like, to run that dose -- that service or process integration across all of your vendors that are directly or indirectly part of delivering your IT services and security components within. And then, of course, it becomes a matter of awareness management and developing skills and resourcing and everything around people. It becomes also a process of vendor management. So aspects like contract management and the service level agreement management and license management, performance management and all of that, that most of you have already a decade ago, kind of written into your contracts when you buy IT services, but very few are actually executing and enforcing on them and managing it systematically. So this, as a discipline is one of the core tasks that this security fusion office then would be delivering there. As well, the security architecture management, it becomes a major part. So of course, if every provider and component in your enterprise architecture is running their own show then it could be highly secure as such, but it becomes expensive and difficult to manage and does the architecture component of this function is trying to align and get everyone using the same capabilities and tools and processes to get that job done. It's, of course, it's a lot about also change management and dependency management but also compliance management and -- but that, of course, gets as well easier if you have already a holistic process to manage your other security requirements across your whole service provider ecosystem, then also governance and compliance matters get more simple and aligned and unified. You will, of course, as well have continuously going on, new improvement projects, and thus, you need someone to manage the security aspects of all the projects and programs going on so a BMO-like function there. And then the actual security operations, so needs to be managed as well. So the SOC or SOCs in plural, it can be as well, you have your threat intelligence, how do this tie into, how is it the threat intel, for instance, becoming actionable and tied into the actual service delivery processes within those respective service provider towers so that they are well aware of the threats that are valid to your organizational relevant, and they know how to -- what to do about it as well. So for key word there being actionable threat intelligence. Same applies for the vulnerability management. So it might very well be that same service provider for there in this picture has a really good reason why they cannot, for instance, patch a certain component there now today, even if the security fusion office would want that to happen, then you need somehow kind of manage how do you then play that, how do you mitigate the residual risk, what compensating controls to implement potentially, for instance, in service provider, freeze services there then. And thus, this is a really good example as well as where it becomes a matter of mandate and contractual obligations and so forth that needs to be managed to really get this happening. So it might be that one service provider needs to do something that is maybe out of the scope of your typical service delivery because another service provider cannot do it there. And to get this happen, you really need to have a strong voice of the owner of the whole thing there and so forth. And these are merely examples again, so could be that you have many more processes that you need to actually integrate across this whole realm there. But with this, I think this kind of concludes quite a lot what I wanted to say about the security fusion here to start off. So again, we need to be able to do this in a more integrated manner to be more cost efficient, so that even though the attack surface continues to grow, the expenditure can be manageable so that all the benefits of all that digitalization doesn't turn into cybersecurity cost. And that's why we have security fusion. And with that then, I want to hand over to Olli. So -- last thing here that I just remembered. We also have in the Q&A section, we actually have a call to action there, there's as a link that if you want to follow up on any of the topics that we discuss here today then just go click that link and some friendly person from our side will reach out and get back to you on that. But with that, over to Olli.

Olli Paasikoski

attendee
#2

My name is Olli Paasikoski and I work as a Microsoft Security Architect at Nixu Corporation. And my background in cybersecurity started about 7 years ago coming from a software development background into working with Microsoft as a technical specialist for cybersecurity solutions. And about 6 months ago, I've transitioned to the Nixu world on the service provider side, and I'm now working on the latest trends and building new security services for our Managed Services portfolio. So our team in -- at Nixu, service development, we help the -- our business areas develop our capabilities such as our 24/7 SOC with Microsoft Solutions. And we improve on existing ones, such as our managed XDR service, our centralized services, and so on. And now looking at the new generative AI applications that we'll be talking about today as well. So I'm very excited about coming here to talk to you about some of the key trends that we are looking at, at the moment. And in fact, to start off, I'll just go into a little bit of a high level that what is Microsoft doing in the world of SOC and how are they, on their part, transforming the technical landscape that we have into these types of operations. So of course, at the start, we need to recognize maybe the footprint and the -- how -- what kind of increased acceleration Microsoft has had as a security player in the market, just the amazing amount of data that is being analyzed on a daily basis by Microsoft to do this, complete these analytics and threat detections on a global scale. We're looking at 65 trillion signals per day. Although I think this might be already a dated figure as it keeps on growing on a monthly basis. Of course, having that back end of this amount of breadth of signals and threat intelligence at your service in the back end, that really helps you keep your organization secure while saving your time and resources as you don't have to build that threat intelligence, baseline yourself and that you got to outsource that and take leverage of a fantastic set of capabilities there behind your security tooling. Jan already talked about a little bit on kind of the challenges of multi-vendor and multiple organizations working together on a single objective in this case, cybersecurity. And the same goes on multi-vendor security solutions. So if we do have a lot of different kinds of technology tools for monitoring and protecting our environment, that, of course, creates friction and complexity, of course, that -- and we can see concrete savings as well from the ability to consolidate our technology stack into one of these platform offerings, such as Microsoft. Of course, other kind of key metrics about Microsoft as a security technology vendor, is that they have a massive amount of a huge partner ecosystem, partners such as ourselves, can help customers make the most out of the technology. And we, of course, it's a very partner-driven model that -- as also Microsoft security partners can leverage and get the best win-win situations between customers and partners. The growth that we can see there, 860,000 customers have already chosen Microsoft Security as they're one of their kind of key components of their security operations technology stack. And it's not a surprise that we can also expect Microsoft to invest more and more into building these technology -- security technology solutions as they become even more important in the future. So a few kind of key platform value propositions that we want to bring into kind of set context on the Microsoft Defender stack and tooling. So in the past, we've kind of been counting on, for example, the traditional log-based detections and maybe looking at the endpoint and the network level security at a very kind of under the lens. Now the reality of today's cybersecurity threat landscape is that it extends through -- it's not only focusing on endpoints or network that goes beyond these kind of traditional boundaries of our perimeter, and we need to start looking at cross domain instead of point solutions for specific threat vectors. So user identities. You might have heard that identity is the new security parameter. So we need to look at the hybrid, especially the hybrid and the service side entities that we have in our company, that is one of the key attack vectors that are under attack today with e-mail based and other identity-based attacks. On the endpoint security side, we're also extending that need to also monitor the OT and IoT devices and infrastructure assets that we'll be talking about later with the Defender for Cloud. Of course, e-mail and collaboration tools still remain a kind of low-hanging fruit for attackers to do that first initial breach. And we're also running a lot of innovative, highly scalable SaaS applications and cloud infrastructure that while give us those great benefits on the optimizing our the enterprise assets that we need to govern. They also pose challenges in the different types of security controls that we need to put in place to protect those kind of because they are a little bit different after all, in the way that they need to be configured against attacks and how -- what kind of attacks can we expect those kinds of assets to be vulnerable to. So as we recognize these key attack vectors, and we want to provide some kind of comprehensive security approach to all these key attack factors. There are some other very kind of key trends into the -- and value propositions that the Microsoft stack has. So first of all, having these different attacker vectors and tools integrated natively helps us create consolidated XDR incidents, which basically means that instead of working on a flat alert queue, our analysts can understand the complete time line of a suspected or event or a security event. And that helps them much quicker, understand the scope and what is happening there. Is this something that we need -- we should be concerned with or going to triage for. Microsoft is also one of the leading developers of automation in the back end of the extended detection and response tooling. So for certain types of events, if we see something suspicious happening on an identity or endpoint level, we have automated workflows to disrupt those suspicious activities at machine scale because after all, we can even if we have a 24/7 SOC operation like ours, running, protecting and monitoring our environment, they still can't be there on the button reacting at second place. And -- but automated pay books can alleviate some of that responsibility. Of course, there's no silver bullet, but that's also becomes even more imperative in the future as also attackers are going to start using a lot more AI and automated workflows to do the -- to generate the attacks. As we have all these different tooling for different attack vectors. It's also imperative that we are able to integrate those into the IT systems such as identity and access management and device management so that the kind of the insights that we get from these cybersecurity tooling, we can actually implement controls on the IT systems level based on those, having that native integration with Microsoft tool, for example, the active directory level or in June, that is very, very powerful and a great value proposition when considering the different -- between different platforms. And that also gives us those -- the last bullet point here on the slide is the built-in preventative controls and posture management. So I believe that Microsoft has had a great place into providing valuable insights because the security solutions are natively integrated into those IT systems that actually have that information available about what is the device state, what are the security policies in place and can provide really actionable, valuable recommendations to improve on those. Great. So we discussed a little bit about extended detection and response. But in fact, there's a lot of more -- there's a lot more technology and tooling coming into the -- emerging into the market at the moment. And you might get even a little bit overwhelmed with the different acronyms and the different kind of tooling and how the different kind of tooling, what kind of roles do they take in your security operations. And for example, with AI and the emergence of generative AI tooling, how does that fit into the existing tool kit that you are using in your organization. So if you could be -- you might have been already looking forward to something a little bit more unified, something integrated that integrates not only a single set of your core security tooling, but also that you can bring in other custom detections and log sources and maybe address both the detection and response and posture management side of the coin in your security operations. So Microsoft thinks it's time for -- they've been developing at this for a while, I believe, this unified security operations platform. So a technical platform that allows us to see to look into many of these most imperative views and tooling that we need in today's cybersecurity operations. So the -- of course, the benefits of having a unified platform would be, of course, the -- an optimized analyst experience. The typical -- in a typical analyst workflow, they start triage. They have to pivot between different perspectives on the suspected attack, for example, from the identity that has produced some kind of alert into the device that they are using, maybe cross-reference that with some external threat intelligence, such as check IP addresses or domains for any suspect metadata. And after the kind of workflow is complete, maybe the actual investigation has produced some actionable posture management information as well, for example, how can we -- how could we -- if it's a false positive, how could we perhaps eliminate such kind of noisy, unnecessary alerts in the future? Especially here on the AI and XDR side, so targeted assistant. We'll talk about -- a little bit more about how SOC might benefit from the AI-powered tooling. But that there's really fantastic new use cases and scenarios where we can get our stock analysts prebuilt, pre-generated insights into the different events happening in the organization. And AI enhanced the existing detection capabilities that we have in place that are -- might have been more static in nature. So if you look at the different components of the listed list there on the top. We have the AI, generative AI, being able to produce insights on a completely new paradigm. We can see how AI has already been used in producing those automated workflows and playbooks based on some events, creating a workflow to combat some threat. We have already discussed how the extended detection and response helps you protect and defend across these workloads. So we are not leaving any gaps behind, and it's kind of quite holistic that it covers both the investigation and response but also has tooling for advanced threat hunting and incident management. Of course, with one XDR platform, we might not be able to cover each and every attack vector and domain that we would we want to. So the SIEM solution gives you that breadth of where the XDR gives you depth into a specific attack vector. We might still need -- or it's probably we will need a SIEM solution to give us that capability to look into signals and into a more broad perspective. So that's why, for example, at our Nixu's SOC, we bring a lot of custom, integrates with a lot of custom on-premises or other customer security tooling to bring those into, in this case, the Microsoft SIEM solution, which is Sentinel, so that we can monitor across everything. So whether that's a crown jewel that Jan was talking about for your company, whether that's on the OT side or production or CRM, we can provide you with that custom detection capability while also leaning on Microsoft XDR into providing those key kind of core detection and protection capability. Microsoft has also provided new integrations and new capabilities in terms of threat intelligence. So especially now with coming up with Copilot for security. There's a new -- the Defender threat intelligence is providing built-in integrations for threat -- Microsoft Threat Intelligence feeds into the tooling itself. And a very also knew the Exposure Management. So here, abbreviated as XSPM. So not only looking at vulnerability or posture management practices, but also in a broader sense, looking at also external -- both internal and external assets and we're cross-referencing that with your ITSM or your vulnerability management stack. So a lot of tooling, a lot of emerging new capabilities. Some of them have been around for long, but there are a lot of modern capabilities being developed for these technologies as well. So why do we see Microsoft as a great candidate for being a key center player in your security operations. Well, as we may be discussed. So it can be argued that, of course, Microsoft has one of the most, if not the most, comprehensive combination of these best-of-breed, what we call best-of-breed tools, and those kind of build that best of platform solution. So when I talk about best-of-breed, so there are -- typically, we look at the recognition on different kind of benchmark or comparisons -- comparative evaluations. And in this case, in the case of security, these are quite typically either done by Forrester or Gartner. And of course, it kind of -- that kind of showcases that if we have 9 security categories, 4 with Forrester and 5 with Gartner, putting Microsoft in the leader category on the quadrant that's kind of showcases that there is a lot of value that we can get through that consolidation of the stack that we're not going to also -- we're not consolidating just because of the price benefits, but we're also getting some actual benefits and quality of tooling and we're not compromising anything on that side. And when it comes to that detection capability, one of the benchmarks that is quite -- are usually quite interesting on an annual basis is the [ MITRE ATT&CK ] evaluations and those were very positive for Microsoft in the latest addition, which was last year. So maybe here repeating maybe about the posture management insights, just that we can derive them natively from those IT systems that we have already in place. So we have the identity metadata, the policy metadata and the device metadata giving us insights that we can then build analytics for and then get kind of prioritized list of posture recommendations for them somebody to evaluate at what are actually important for us. And of course, that's one of the capabilities that we have as a service provider, our responsibilities is to help you prioritize between a long list of security configuration recommendations or perhaps patches that haven't been -- that you haven't been able to deploy. Cloud native SIEM integration, of course, Sentinel as one of the first cloud native SIEM solutions, providing that endless possibility to extend your monitoring and gathering of data into custom data sources and thereby enhancing also the detection scope, of course, it's not enough for us to bring the data in. Otherwise, we might just be creating a -- reveal kind of data graveyard, so to say. But we also actually need to be using those data sources and log sources to make some actual kind of concrete and valuable detections. So I think that's also a very important role for us as a service provider is to help you evaluate the return on investment on connecting some log source into the SIEM solution. And in some cases, you might avail of some in-depth tooling instead of building those custom detections yourself or having your service provider build those detections. So having an XDR tooling kind of alleviates as said, that responsibility because Microsoft or Microsoft research and their product groups are building these very in-depth advanced detections and based on machine learning and AI, for example. Why Microsoft? Again, maybe this spearheading of the Gen AI applications. Definitely, I think most of you have been kind of following the Microsoft collaboration with OpenAI. They've been one of the first to build a completely customized model for GenAI in cybersecurity, taking advantage of all of the other technologies that they have in place and that big data, 65 trillion data model that I discussed earlier, just having that kind of being there at the forefront in this technological advancement is -- and having those -- for those who have already kind of invested in Microsoft, but not only Microsoft security solutions that they get the GenAI based solution that can easily integrate into that stack. So in fact, there's already built-in integrations to over 300 data sources in this unified SecOps platform that I presented earlier with the different pillars which just showcases on that Microsoft is not only a Microsoft technology house anymore that they are -- that actually will just move into this -- oh, here we go. That they support a lot of your other important data platforms, technology, stacks, third-party systems as well. So of course, talking a lot of great things about Microsoft now. What are we doing as Nixu with Microsoft in this partnership? Well, in fact, we've been doing very well in the last years. For example, just last year, we were awarded as the Partner of the Year in End-to-End Security. And one of the kind of key partner programs that Nixu is part of is, the Microsoft managed security service provider partner program, which is -- there's not that many, many around, of course, that are -- that in depth in the Microsoft stack in providing these latest types of security services. And in order to kind of accomplish that kind of partner qualification or status, we, of course, have been able to -- or we've had to demonstrate our know-how and skills and experience in these tooling. So we do hold dozens of these individual security certifications. So these are basically our Microsoft gurus that have taken these certifications and through this work, we've been able to qualify into as a solutions specialist partner for categories such as cloud security, identity and access and threat protection. And also recently, we've just become a member with our managed XDR service. We are now a member of the Microsoft Intelligent Security Association. So you can find our managed XDR service, for example, from the Microsoft marketplace and it's -- that's -- we're in collaboration with MISA on that level. Great. So now that we've kind of spent a lot of time there setting the stage on Microsoft and what is coming -- what is the kind of trends on the Microsoft solution stack. I'd like to delve a little bit deeper into the managed XDR service. So we discussed extended detection and response abbreviated as XDR earlier, cross-domain protection and detection between attack sources. Now that's great on itself. It sounds like something that we really need. But how do we make sure that we get everything out of it. So best of platform, great value proposition, but we might need something to actually make sure that we, as an organization, get everything out of that solution as well. And an end-to-end service kind of makes sense that, that could be it. So a little bit on the kind of background on Nixu as a SOC, Security Operations Center provider and how we've been kind of monitoring the evolution of SOC. So in the kind of -- and Jan already talked to you about the security fusion that we have combining getting a comprehensive approach to that to help our end customers protect and reduce cybersecurity risk. And behind that security Fusion concept, we follow what you could see here as maybe 4 out of 5 or 5 of the NIST cybersecurity framework. So very similarly, of course, we need capabilities to be able to identify what do we have, what are we actually protecting? To identify those gaps and have actionable threat intelligence that we can then reflect on based on the ITSM tools and other data sources that we have to identify what we're actually monitoring. Now if we can effectively identify what we're trying to protect, then we can start establishing and maintaining those 24/7 operations to monitor those assets so that we can continuously and effectively and of course, as quickly as possible, detect and investigate and respond to ongoing threats. Now we could just try to focus on the detection bit. So reacting into suspicious behavior, for example. But is that very effective or even realistic that we can have somebody always there right on time? So nowadays, we also really want to look at the protection bits of the preventive aspects of cybersecurity, and that is the protect bit. So our modern security operations also helping you not only to identify and detect threats, but also to do that preemptive work and proactive work with you to reduce the attack surface and improve the configurations of your security in your security attack vectors. And even if we do everything that we can to prevent these things and we have 24/7 detection capability with the most modern tools than as Jan there explained with the trends of the other market. It's more likely that eventually, over time, that something will happen, and we need to be prepared for that eventuality that we have an incident response or a forensic situation where we need to -- we need the actual recovery capabilities, and we need to be prepared in the process way also how can we deal with that. So combining all of these 4 main pillars into what is our kind of security fusion thought. So another kind of key trend that may be already kind of -- we've kind of built the context for that there is already kind of a clear shift from this best-of-breed environment approach that we just buy the best tools available for a specific attack vector that we are concerned about thus perhaps creating a possible new silo for that information. So there's a clear shift from that best-of-breed into what we would maybe call best-of-platform or platform solutions in general that we then supplement with some -- perhaps some point solutions to get that complete coverage and capability that we're looking for. And, yes, so correlation between domains as discussed, the -- having that ability to kind of externalize the development and of detections and having artificial intelligence and machine learning there to supplement that. That really helps us not to be -- not to have to think of every single thing that we have to detect based on the logs we have available. So reducing the significance and role of the SIEM solutions, while also improving your ability to detect and respond to threats. And another kind of new that a lot of our customers is now kind of in this interim phase of kind of starting to leverage more posture management as part of a kind of integrated process with the SOC. So that as we'll be able to see later, there's a lot of potential in having a dialogue between these 2 capabilities, between the detection and response and the posture on the other hand. And yes, of course, something that we're -- might be working towards on the -- especially on the posture management, is that, okay, now we have great insights into, for example, the user identities from -- or the device information that we have in place because those are already existing capabilities that we have been managing for a while. But now being able to extend that posture management practice into other key attack vectors such as cloud infrastructure or our OT environment, enterprise IoT and other external attack surfaces like public-facing servers. That is something that we're working with a lot of customers with because that's a key kind of pain point that they can identify that they might not have the same visibility there as they have for the key IT or core IT. So yes, so on the technical side, as mentioned, a lot of -- we've been kind of focusing on the endpoint or perhaps the network side and some specific log types like firewall logs and a point logs to detect malicious or suspect behavior. Now with XDR, we are now kind of -- we have a lot much more comprehensive view on these extending into identities and cloud services, infrastructure and more. And faster response times, automated attack disruption built in posture management. Again, these are the kind of capabilities that we are really looking for as the baseline underneath the operations. Now on the other hand, how does that translate into the -- on the service side. So 24/7 detection and response, of course, if we have that in place, we do want to take advantage of the full set of technical capabilities and detections that we have in place, and also think about a little bit outside of the box there, like what are the actual crown jewels and business processes that we really need to protect, so whether that's monitoring or doing posture management on the OT side or whether that's, for example, App SOC that Jan mentioned there to kind of look at the specific custom -- business application that is really to our operations and put a lot of risk to us. We need to -- we want to kind of have as a broad perspective on this as possible. As we do have the -- all of these new posture findings coming from the technology platform in itself, configuration suggestions. Now how do we actually take action on those? And what are the options that we have available to, for example, complete some kind of a posture finding? And how do we prioritize. And so we might want or definitely quite often, we want somebody to give us some kind of advice. And that's why the continuous posture management by -- led by our Nixu expert. That's a key part of our managed XDR service. With those posture findings, they quite often, they lean on or very much aligned with Microsoft Zero Trust model. And so how we're able to kind of produce some modern access controls and it will reduce the risk with implementing Zero Trust as a kind of ideology or framework behind the preventive operations. And with our managed XDR with Microsoft, we always have a managed Sentinel instance always included kind of to help us with moving the -- to kind of manage the actual ticketing, the casing, the kind of actual detection response by the analysts and having that option or capability to also bring in third-party log sources and capabilities to combine it with the stack. So a little bit more on a high level about, you maybe got a little bit of an understanding of maybe some of the components of our managed XDR service. But just to kind of give a little bit more meat into it and context. So as you can see on the gray boxes here, it's again the 4 different operations within the or fusion or list-based how we kind of model these. So First of all, on the left, on the kind of vertical column, we have technology management. So as I mentioned, okay, we can have these amazing capabilities market-leading capabilities like extended detection and response and a modern SIEM solution. But it's also important that we are -- we can be confident that those technologies are well managed, that we get everything the most out of them. So our managed XDR service keeps your security operations team on par and on track on what is emerging from the -- in this case, the Microsoft technology stack and how those would kind of fit if there's any kind of changes or changes that need to be kind of implemented how to -- what is the best time or a way to tackle those. There's a lot of settings involved and even if these are native SaaS or PaaS services that we're talking about, there's still a lot of configuration settings that are available. And it helps to have somebody to kind of track those and make sure that as the time goes on and best practice configurations change, but those are kind of stay on par as well. And of course, there's a lot of detections that need to manage as well in the -- within these tools. So for example, what suppressions or creating new detections based on historical needs, we have a detection engineering capabilities. So that is also part of the technology management practice in the sense. We're then on the kind of identify and protect levels of the service, then we have a lot of preventive work, we call this the Continuous Security Posture Management or CSPM. So within that practice, we identify needs for change. We initiate those changes based on the recommendations that we have, based on the kind of queries that we run and the asset metadata that we can get through that native integration to your systems. And these changes might be implementing preventive controls, policies, or perhaps eliminating some attack surfaces and on your -- in your environment, whether those are on the endpoint side or identity or on the infrastructure side. So those could be, for example, patches or vulnerabilities or simple configuration changes that need to take place to help prevent some type of attack. And then, of course, this would -- the kind of key maybe that most of our customers are looking for is that detection and response capability that is so in depth and so crucial because even if we would -- we have the best posture management practice in the world, it's still perhaps not realistic that we will be able to -- could deter every single alert or an attack. And in fact, it's not, we can say that it is an eventuality that, at some level, there will be a compromise also in your environment. So there, managed XDR, we have those XDR tooling. We have our in-depth security analysts and expert doing 24/7 reactive investigation and mitigation for these types of all the alert types that are involved in the XDR. And those kind of alerts that are not, for one reason or another, not valuable enough for our 24/7 SOC to look into. So they have seen as kind of informative or low severity, not by themselves, interesting enough for triage. We still leave them behind and do periodic investigation on a weekly basis so that we just kind of cover our bases and due diligence and perhaps there are some new detections coming in through the technology vendor, and we want to make sure that those are also investigated by our 24/7 operations. These are the kind of the core components of the managed XDR service. So technology management, posture management and then the reactive SOC, threat detection and response. And of course, then there are other functions to kind of support that, for example, if there is a really severe incident now, we get into the digital forensics phase, a DFIR, an incident response, then we have in-depth experts to lead that for you. And on the other functions here on the right-hand side, so there are a lot of functions that are not maybe core to the managed XDR, but also benefit and kind of collaborate with this. So we have threat intelligence, our Nixu Threat Intelligence pools, continuous vulnerability management to take care of that -- help take care of that patching for you, the actual and advanced threat hunting as well to have kind of scalable threat intelligence-based detections in -- for your vertical and you're custom-made for your needs. So we talked about the alignment and the need for alignment for the protection, detection and response, and that's very important when it comes to XDR and managed XDR services. So there are some clear challenges when it comes to having these different levels of the operations. We have our posture management looking at one perspective of the threat coin and detection and response. Their primary need is to just detect when something suspicious is happening and then investigate and deal with it. And both of these security operations, they then also often rely on the IT and the technology management side of the team. And on the other hand, maybe the technology management team, they have a lot of other things on their plate so they might be the -- they need some hand in what to prioritize and maybe somebody also to chase some imperative changes in case to get those most imperative changes done in time. And that's why we've created within the Managed XDR service, we've created a lot of collaboration between these different functions. So it could be that the managed protection on the management of the security operations is handled by our end customer or one of their IT partners. And we help them prioritize and to implement those changes based on, for example, the posture management work that we do based on the insights that we get. Now sometimes it could be the detection and response team here on the right-hand side that they noticed, that there is, for example, a repeating noisy alerts, which is caused by some configuration in your systems, and they would rather have it fixed at the source rather than making a suppression in the SOC. So they give that feedback to the posture management team that, hey, could you bring this up into and help the customer implement these changes so that we can reduce that risk or kind of eliminate that risk, and we don't need to have those kinds of alerts being investigated by the SOC anymore. And on the other hand, if the posture management team recognizes that now there is a critical vulnerability there is something that we're really concerned about in this vertical, for example, but for some reason or another, we can't implement the patch or the configuration change. For example, we have some legacy solutions and on the OT would be quite typical. Then we can inform the SOC, the detection response, let them know that there is an important threat that they might want to start monitoring that attack vector more closely to fix that issue. So benefits of enhanced cross-domain protection. Hopefully, that kind of clears the benefits and need for why these different, sometimes siloed operations they need to work together. Great. Moving on from the -- well, staying in the managed XDR side, but looking at one single kind of merging need or capability within the XDR stack. And on a solution level, we're talking about Defender for Cloud. And what is the kind of context here? We do see in the data in the research, we see that when we do the postmortem for different security incidents, we quite often see that the boundaries between the traditional kind of IT end user assets that we already monitor and the kind of new emerging infrastructure assets, cloud assets, that those boundaries are quite often the attackers are crossing between those boundaries. And that gives us the need to start also extending that capability to protect and monitor assets outside of our kind of traditional IT systems and looking at, for example, public cloud platform and cloud connected assets that have been previously more difficult to protect and detect for. So here in the time line, we have an example where an end user compromise leads into a few alerts on the end user XDR side, so we might be able to detect that there's some unfamiliar or suspicious activity on the authentication level. But after that, maybe it gets a little bit quiet. There is a 24-hour gap. There's nothing -- maybe this could have been investigated by SOC and they say that, okay, there was some suspect behavior, but we've now flushed the tokens. We have resetted the password. We've done our due diligence and maybe we'll close the ticket here. Now if we have -- now if we would have capability to also monitor the infrastructure side, and we might see that there is also a suspicious classic role assignment, so an elevated role may be added by that same user that was previously compromised. So there is more to the story that we could identify with the core XDR and we might see that there are some -- that are -- some various events that are only are very specific to that domain. So a core quota increase or a suspicious virtual machine quota increase or creating or creation of new compute resources. These are some events that we might not have been detecting or kind of concerned before. So that's what we are trying to effectively achieve is to not only -- or not allow such kind of siloed visibility to happen, that we want to close that cloud coverage gap, especially as we're trying to -- we're moving to a cloud-first strategy, we want to embrace the cloud and take even more cloud services into use. So let's extend our very effective security operations that we have there in the XDR side, let's get it extended to the cloud environment. And the fact is that my misconfigurations are the most common cause for any breaches that we see. Visibility, that comes to kind of the identify and, for example, the technology management service area that we have within our managed XDR. So having those agents in place, having all the different service configured right that allowed us to have that comprehensive visibility, not only on the, for example, the IT system, but extending that to the cloud infrastructure, whether that's Azure or for example, AWS or Google Cloud or other third-party cloud providers. And okay, if we have that visibility, we can take those prioritized risk decisions based on expert-led advice. That's fantastic. But again, maybe not realistic that, that will be enough. So we need also tools and processes and technology to detect when some attacks get past that defense. So again, we don't want to kind of limit ourselves to either detection and response, but combine that with the preventive work. So in fact, what's kind of very interesting and kind of beneficial to us as a service provider to be able to provide you -- to provide this kind of services effectively, is the way that the XDR and the SIEM, how they function together now. So this is how maybe the kind of illustration of how the kind of high-level architecture. So on the top, as we've discussed, we have that SIEM solution Sentinel, providing us with that breadth, enabling us to connect any kind of custom log connector into the setup and then being monitored by Nixu's SOC. In fact, that was what security operations were mostly about just not that long ago as that we have our imperative kind of key log data producing log sources and we create detections based on those. Now nowadays, we talked about the kind of the benefits of XDR. And Microsoft has previously kind of split those capabilities into the IT and end user services, such as identities, endpoints, applications, e-mail, data and cloud applications, end user cloud apps. And those were governed by the Microsoft 365 Defender family of XDR tools. And then we had a completely separate kind of at least in a product or licensing term. We had this Defender for Cloud product area that was then completely focused on protecting your infrastructure assets, such as Sequel and virtual machines and Kubernetes and other Containers and App Services. And this was already amazing because it was kind of -- the first kind of -- it was providing us with those emerging capabilities for cross-domain detections and protections. But now recently, Microsoft has unified these to capabilities for the most part. So we have this new Defender XDR platform and user interfaces available so that our professionals are security. People don't have to pivot between different portals and they can deal with these attacks that are crossing boundaries. As you saw there before, we might have an incident where we have that contains alerts, both on the endpoint side, identity side and maybe even on the cloud infrastructure side. So having that complete picture makes it -- makes us more effective in analyzing and triaging and actually making sense out of these security incidents. And even further, we're now looking at the unified SecOps portal that is now in public preview at the moment. So we're actually bringing that breadth, the Sentinel SIEM. We're bringing that also into the fray combining those so that in the future, as discussed in the -- at the very first slides there, we have this all the capabilities within that one, again, that old single pane of glass term, that all of our security professionals have grown to know. Right. So and then if we think about Nixu Services, how they kind of align with all of these Microsoft security solutions. So here on the dark blue on the top, you have the different Microsoft technologies and you can see how the -- on the bottom, on the more lighter blue, you have our different services. And they, of course, align a little bit differently depending on what your needs are for the managed service. And as an emerging Defender product, Defender for Cloud, we are now moving it. It used to be here on the emerging Defender product side. And because it's all clearly connected to the other XDR. We're actually moving it as part of the managed XDR service or as a component that's available within that. So extending that ability to protect and detect risk and threats in your environment, extending it from the IT and end user systems into the cloud infrastructure as well. So as comprehensive a service that's possible, of course, that's what we're striving for. Some key insights from Defender for Cloud. So if we think about the workload protection when we have implemented these for our end customers, what we quite often see is that Defender for Cloud provides a relatively low amount of higher fidelity XDR incidents. So these are alert types that would have otherwise might have been missed because we might not have those kind of detections in place. And unless we've kind of consciously wanted to build them based on the kind of risk that we have detected. So -- and quite often, these kind of detections, they are based on log sources and analytic sources, that diagnostic logs that are quite noisy and quite expensive to gather. And even across these different kind of workloads that we are then monitoring, detecting for, not all of those detections might be valuable. So we need to kind of look at what kind of -- which of those detections available we are actually want to kind of bring into 24/7 monitoring operations. And some of them could be a little bit difficult to triage unless you know the specific use of that application or infrastructure asset. So you need to kind of know a little bit about the context there. So for example, thinking about key vault, authentication anomaly, well, it depends on what use that key vault is in? Is that some expected behavior if we have a signing coming from a very anomalous location or time or a very large amount of authentication requests coming from a single source? So we need to be able to also very quickly and very effectively communicate with the application owners in the context of workload protection. Often when we do detections on the infrastructure side, these detections turn into quite valuable posture findings. So a very typical one would perhaps be that we have Sequel server, Sequel database, either on-prem or in the cloud. And we get some kind of authentication anomalies that we have authentication attempt coming from a public, coming through the public web, so not through a private endpoint, and it's using some kind of authentication protocol that we might not see, yes, so secure. Now this detection has then kind of become a valuable posture finding that we should then be able to communicate with, well, the posture team and the posture management practice that we have in place, but also probably the application owners because those are -- in the end, those might be the only ones who are able to actually take action and mitigate those kinds of those alerts. So in this case, for example, to transition into a modernized the authentication, the way that application authenticates to the Sequel or create some kind of private endpoint and access management configuration that would eliminate such kind of suspect kind of authentication attempts. On the other hand, on the cloud security posture management. So now that we have new capability we've connected all of our infrastructure assets, either natively within the cloud or we have some kind of agents running then that allow us to connect those assets to the Microsoft Cloud. That then gives us a lot of ability to identify new improvements, configuration changes, vulnerabilities and Microsoft has done a really good work in linking those into different kinds of benchmarks and policy standards that, for example, the one that Jan mentioned earlier was NIST 2 or ISO, that any kind of policy standard that you are working towards that we can also maybe it helps us prioritize those and kind of keep track of the things that we need to move towards in our -- on our list, a long list of patches and configuration changes that we need to implement. As we have all these posture management findings that may require knowledge of the application and there as I said, there might be a lot of them that we need to -- we really need to be able to prioritize and so that's how why we try to as part of the service. We when we work through these posture management findings, we really try to help you understand the real concrete risk that these configurations are may produce and consult you on the available implementation options to see where would be the lowest hanging fruit or kind of best return on investment if we look into making changes into the infrastructure environment, especially in the infrastructure side, there can be a lot of assets that -- and applications that are very difficult to change or -- so we really need to be kind of realistic about and help these owners take action on these findings. Okay. Great. So finally, the last piece that I wanted to talk about today is our experiences with the new GenAI tooling from Microsoft. So Copilots for Security, a lot of hype has been going around this technology. So I think -- you might have thought that, okay, this is going to completely revolutionize the SOC and maybe it will. But of course, it can't. We've already been able to see that it can't -- it's not even meant to replace a security operations or SOC service at all. But of course, as in any Copilot it augments the human experience that is so imperative still in that work. And there were some -- a lot of hype also at Nixu when we are looking at Copilot for security and a lot of interest across the different managed service areas that we have. And these kind of statistics that, well, these are actually Microsoft statistics from some of the more comprehensive surveys that they were able to implement. We -- there's a lot of promises for faster mean time to mitigation, even 26% improvement is what they recorded and, of course, very important that we can actually get more accurate classifications of more accurate investigation more quickly, that makes sense that it's -- that would make an even better stock if we can do things faster and more accurately. But actually, even more perhaps even as -- or at least equally the third point here on the upskilling of the security staff has been proven -- in our evaluation has been proven really, really interesting and valuable because these -- as we -- Jan also mentioned, there's a huge gap in resources and hiring issues within the cybersecurity markets. And as we hire new junior and less experienced employees to do this very challenging line of work, they need all the help they can get. And generative AI by being able to produce them with very deep technical or help them with deep technical skills and activities. It really helps those early in the career that we would otherwise have to really in-depth train and hold their hand at the very start of their career. Given that, okay, you can -- might imagine that our very experienced analyst, Tier 2 and above, they are also quite fast in the mitigation. They've already experienced different types of alerts. They're quite skilled, running queries by their own. They probably can see just looking at a ticket quite often that what is this about? And they might be quite good at making those right -- accurate in getting those right classifications. But we have seen that even those experienced analysts have been seeing more productivity benefit. And that there -- and generally that they're quite excited and can see a lot of potential in the use of Gen AI within their work. So from these statistics, from this kind of standpoint, we started on the early access program with Copilot for Security a few months back, and we've been able to evaluate Copilot for Security as part of our service operations and see how we kind of see -- what we see the product is, how it aligns with our view. And when we had a look at the first use -- the kind of what are the key use cases that we are most interested in. Well, these are the 3 use cases for Copilot for security at the moment. So we can have Copilots to help us prioritize on posture management findings based on risk and threat intelligence reports. So we might ask the Copilot to list to kind of more severe vulnerabilities and posture findings based on the threat intelligence reports that we have in real time from Microsoft and third party with plugs ins. Now that is very interesting as well, and we have a lot of applications, but even more we were interested in the -- to see how Gen AI and Copilot could fit into our incident response and our security reporting. Because these are kind of very core capabilities also that we would want to provide the best tools for. So of course, for incident response, we have the capability of Gen AI to make -- to analyze the events and create great summarizations and descriptions of what was detected a little bit more accessible and easily understood than, for example, some kind of very complex XDR incident graphs or alerts listed in the time line, even those are very much better than kind of a flat alert queue, but there's -- there can be a very complex incidence. And if we have tens or hundreds of assets related to one big incident, then it makes it a lot easier if the Gen AI creates a -- easily understandable description or summarization of that incident. On the other hand, in incident response bit, Copilot can also recommend next steps for the triage or the investigation to take place. It can already provide you -- based on the information that it has, it can provide you with some kind of initial classification that for you to evaluate and approve or -- so that's where the kind of also the -- it's very imperative that we have an experienced analyst there because there could be that maybe the GenAI, as you know, you probably seen that there is a potential for hallucination. So perhaps the XDR or the Copilot, things that an alert is a false positive or a -- and it isn't, it's an actual security incident. Or on the other hand, we have a thing that something is a security incident, a true positive detection and recommend some kind of mitigation actions for us that would have an end user impact, but there's actually there is -- it's not -- it's just -- it happens that it's a false positive. So we need that experienced analysts there and processes, if they're more junior, they need processes and tooling to help them make sure that these kind of potential hallucinations that they don't have a severe effect on the operations. And the last bit here is probably the one of the most interesting to our customers is how can we improve on our security reporting and make it more effective, make it more accurate, more elaborate so that we can exchange information effectively between the SOC and the customer, the ticketing system for example if we have escalations or if in a forensics case, we need to go back into, okay, what was actually analyzed and maybe do a handover of the investigation from one analyst to the next when they change shifts and so forth. There's a lot of benefit if we can have Gen AI produce that security report for the analysts. And to have that somehow we're looking at also into, of course, still have very standardized and validated security reports there. So as I said, we have run our own set of evaluations for our Copilots for security. And one of the key kind of areas that we were -- or use cases that we were interested in at the first point was detection and response. And so in our case, we run these evaluations very qualitatively. So we run a lot of test cases. We had analysts investigate real cases that and see how Copilots could help them investigate. And the reality is one of the kind of notable reality is that, as with any kind of new tooling or technology, Copilot is not any different, that it requires some skills and domain knowledge. So prompt engineering is probably something that you've heard of being my ability to phrase a question to Copilot that helps it understand what I am looking for and produce the right results. That is really imperative when it comes to Copilot for security as well because we don't want to have to ask multiple questions to get the right result or we might have to anyway, but we want to avoid it if possible. And especially when dealing with hallucinations or incomplete or false results, it's usually also -- the problem might be you as the end user is that you're maybe phrasing or asking the wrong questions. So Something that we're also very -- on the one hand, we have to skill -- we have to upskill those analysts to help them understand how to phrase their questions and we can provide them with prebuilt prompts and prompt books that are basically a set of questions for a specific use case or we can help them with programmatic use of Copilot for security. So some kind of API-based or extension to our systems so that we can validate and test those prompts that they are valuable and produce the results that we are actually looking for from Copilots. Now on the other hand, so quickest wins. Obviously, a lot of wins we're talking about are, for example, junior analysts, they might not be have -- immediately out of the gate have the capabilities or skills to create very advanced queries across data tables, for example, at across different, so being able to ask using natural language, you can ask the query type that you need to investigate further. So generating those complex queries and then trying the mouth. Sometimes they don't work right out of the box, but you -- at least you have a good model for it and you can probably see -- and that helps you kind of learn as well when your problem shooting these generated queries. Another very thing that our analysts have been very appreciative of is the native capabilities to analyze the different files and scripts that are going. They can be very abstract or obfuscated even. So that they can have Copilots kind of strip the -- kind of pull out the actual meaning behind a very technical complex script. So -- and that's even for experienced analysts, they would rather have that than having to go through a very long script themselves. So overall, especially junior analysts have been -- they are able to make decisions more confidently, more fastly because they don't have to reinvent the -- produce some of those, for example, queries for themselves and okay, understandably maybe not all of these benefits are so obvious to our experienced analysts because they have already kind of invented these themselves. They have a long list of library of KQL queries, and they can produce these results quite effectively. And in some cases, they don't -- yes, this is quite a kind of maybe may be clear that also that's the feedback that we have been getting. However, I would say that especially the prompt books towards some kind of use cases that we identify where we get the most value out of Copilot for security and the API-based integrations with like, for example, security operations on automation systems or services or other external like Threat Intelligence feeds, those will be key in having us integrate Gen AI and Copilot for security into a more mature advanced SOC operation. So given that kind of our current vision and now we're a month in into general availability, so GA. Absolute value for supporting these and scaling these early encore cybersecurity professionals. We see a lot of benefits there. And there's a lot of potential that we see it becoming more powerful as when we use Copilot for security, we have the option to train. We have the option to give feedback on any kind of hallucinations and those kind of feedbacks are then used to improve on those models that are used in behind that Copilot for security. And yes, as these capabilities improve, as we get access to more skills underneath the Copilot as learn more capabilities are built by Microsoft and third parties and service providers like ourselves, then immense potential there. And yes, so one of the things is still after GA, a little bit. We have some good insights already on the kind of ballpark the -- what the costs would be in production level. But of course, these need to be also evaluated over time, which we're doing, but Microsoft has provided us with some -- already some good monitoring tools at GA to kind of -- so then we can actually kind of argue and kind of look into the return on investment as well and what the actual benefit is for the cost. How can Nixu -- how can we help you as a new organization with Copilot for security? Well, we can help you assess your readiness as we're looking at the kind of SOC maturity and your security operations maturity curve. What is the readiness and the ability to -- for your organization to actually take advantage of those. is it a good fit for your team and in what -- in which roles and responsibilities to make the most out of Copilot and evaluate that potential and return on investment over time. Copilot for security takes advantage of especially Microsoft native technologies like which we have discussed earlier, like Defender XDR Microsoft Sentinel. So we need to be able to -- we need to check that those capabilities are set up properly or that we -- that Copilot for security has actually some kind of valuable data to create those insights from -- that data is valid. And when it comes to Defender XDR, then that data model and that data is actually -- well, it's governed and kept up by Microsoft natively. And in the case of Sentinel, we can produce any kind of data into there. So there's even more kind of risk that we need to make sure that the data is valid and valuable. As Nixu, we can help you. We've been using Copilot for security for a while, so we can help you train skills for us, for example, understanding that prompt engineering, which is so important for the use and build playbooks based on your current setup. What kind of things are you detecting now. And how could we even enrich those detections and playbooks using Gen AI. And we can help you build capabilities such as prompt books that make sense to you and integrate other third-party systems with the extensibility options of Copilots. So towards this, I'm almost at the end of my -- the content today. And I want to leave you with a few things here at the very end. So of course, we hope that you have enjoyed this presentation and description of what we're -- what we at Nixu are working on. You can scan the QR code here to get a copy of one of our fresh future-proof security operations, white papers for a more broad look into security operations. And here is also a call to action. If you want to look into Copilot for security, we can either -- we can have a look into that more in depth, and we can -- we are actually now collaborating also with Microsoft to deliver workshops and practical engagements focusing a lot also on Copilot for security so that you can get actually acquainted to the solution and that you have expert-led advice on how to use it to help you evaluate the kind of new -- all this new capability. Also on the chat -- Q&A chat, I believe that there is a form that you can submit to request any of these kind of follow-ups, whether that's just a call with us to kind of hear more about what we do at Nixu or any of this -- one of these Copilot for security type of follow-ups. So that was it for me as well. And I think for both me and Jan, I would like to thank you a lot for joining this live webinar. It's been a pleasure, and I hope -- I wish you a great rest of the spring and summer. Thank you.

This call discussed

For developers and AI pipelines

Programmatic access to Microsoft Corporation earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.