Normal view

There are new articles available, click to refresh the page.
Before yesterdayMicrosoft Security Blog

​​Better security starts with better questions

29 July 2026 at 12:00

As organizations move beyond AI experimentation, success will depend on how effectively they combine intelligence and trust. The same systems that amplify knowledge, accelerate decisions, and unlock new outcomes must also protect data, govern AI, and build resilience. In this next phase of transformation, security is not separate from innovation—it is an enabler that helps make responsible innovation possible at a faster pace. That starts with asking better questions—the kind that help organizations turn intelligence into action and trust into a foundation for progress. 

AI is changing how security decisions are made. Defenders now have access to more signals, insights, and analytical power than ever before. But better security does not start with more information. It starts with asking the right questions: What are we trying to protect? What risks matter most? What conditions need to be true? And what decisions do we need to make with confidence? 

That clarity matters because security is shaped by more than technology. The challenges organizations face rarely exist in isolation. They emerge across people, processes, technology, data, identities, and governance. Understanding those connections is what allows security teams to use platforms, AI, and automation to make better decisions under real-world conditions. 

Security as a systems challenge 

Security has never been a single-layer challenge. Vulnerabilities can emerge across code, data, identities, and integrations, while exposure is often created at the intersections between them. Designing for security requires a systems mindset—understanding how these elements work together, where failure can occur, and what safeguards are needed so no single layer carries the burden alone. That is why defense in depth remains essential: layered controls, ongoing monitoring, mitigations, and risk management across the AI lifecycle help organizations reduce exposure while continuing to adapt. 

Agentic AI in cybersecurity

Explore actionable takeaways ↗

This is especially important as AI becomes more embedded in how organizations operate. AI can help teams analyze vast amounts of information, identify patterns, and surface recommendations at a scale that was previously unthinkable. Those AI outputs still require oversight, governance, and human judgment, with clear accountability for how AI-generated insights are validated and used. But insight only creates value when it is grounded in the right context and connected to action. 

AI-generated insights still require validation, oversight, and resilience planning because AI systems can produce incomplete or inaccurate outputs.

Clarity creates better decisions 

The most important security decisions start with a clear view of the risk, the level of control or visibility required, and the outcome the system is designed to achieve. When we optimize for capability over context, we miss how security decisions are actually made: through signals, expertise, validation, and judgment. This becomes even more important as AI expands what is possible. Better analysis can surface more insights, but better decisions still depend on understanding what matters most and applying the right context. That matters most when conditions are changing quickly, and teams need to act before every answer is certain. 

Threat intelligence offers a useful example. Defenders operate in environments defined by ambiguity, incomplete information, and rapidly changing conditions. Success rarely comes from a single source or signal. It comes from combining multiple forms of intelligence, applying expertise, validating assumptions, and connecting insights in ways that strengthen assurance.  

The lesson extends beyond threat intelligence. Different security objectives require different combinations of signals, analysis, and human judgment. Resilient decisions come from bringing those elements together thoughtfully, rather than relying on a single source of truth or assuming technology alone can provide the answer. 

Designing for better outcomes  

As AI becomes more embedded in security operations, the quality of our outcomes depends on how clearly we define the objectives we are trying to achieve. Security leaders create the most value when they identify the risks that matter most, the conditions that need to be true, and the systems required to support better decisions. 

Then we design for those outcomes through the right mix of controls, safeguards, and decision-making processes. This shows up not just in architecture, but in how teams establish guardrails, validate assumptions, and respond to the unexpected. The aim is not to make security harder for defenders. It is to make the work easier to execute, supported by platforms, tooling, and AI that help deliver greater speed, accuracy, and confidence. 

The systems we are building today do not exist in isolation. They interact with people, shape decisions, and operate at a scale that can amplify both strengths and weaknesses. Our responsibility extends beyond technology choices. We have to help organizations design systems they can understand, govern, and rely on with confidence as complexity grows. 

Trust is not something we can take for granted, and that does not change in the era of AI. It is built through deliberate choices: the controls we establish, the visibility we create, the assumptions we validate, and the safeguards we put in place. As AI becomes more embedded in how organizations operate, security leaders have a responsibility to help build confidence in the systems people rely on every day. 

Building trustworthy AI systems requires governance, security, privacy protections, transparency, and accountability across the full technology stack, aligned to responsible AI principles and standards.

The risk is not simply that we choose the wrong tool, model, or platform. The greater risk is believing that one answer can solve a complex, evolving problem. AI can help teams make sense of complexity, but it does not eliminate the need for judgment. If anything, it raises the importance of defining the right outcomes and designing systems that make the right actions easier to take. 

Better security starts with better questions, and with the clarity to act on them. The organizations that succeed will apply AI thoughtfully, define outcomes clearly, and combine analytical power with the expertise, judgment, and adaptability needed to build more resilient systems in the age of AI. 

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post ​​Better security starts with better questions appeared first on Microsoft Security Blog.

​​Better security starts with better questions

29 July 2026 at 12:00

As organizations move beyond AI experimentation, success will depend on how effectively they combine intelligence and trust. The same systems that amplify knowledge, accelerate decisions, and unlock new outcomes must also protect data, govern AI, and build resilience. In this next phase of transformation, security is not separate from innovation—it is an enabler that helps make responsible innovation possible at a faster pace. That starts with asking better questions—the kind that help organizations turn intelligence into action and trust into a foundation for progress. 

AI is changing how security decisions are made. Defenders now have access to more signals, insights, and analytical power than ever before. But better security does not start with more information. It starts with asking the right questions: What are we trying to protect? What risks matter most? What conditions need to be true? And what decisions do we need to make with confidence? 

That clarity matters because security is shaped by more than technology. The challenges organizations face rarely exist in isolation. They emerge across people, processes, technology, data, identities, and governance. Understanding those connections is what allows security teams to use platforms, AI, and automation to make better decisions under real-world conditions. 

Security as a systems challenge 

Security has never been a single-layer challenge. Vulnerabilities can emerge across code, data, identities, and integrations, while exposure is often created at the intersections between them. Designing for security requires a systems mindset—understanding how these elements work together, where failure can occur, and what safeguards are needed so no single layer carries the burden alone. That is why defense in depth remains essential: layered controls, ongoing monitoring, mitigations, and risk management across the AI lifecycle help organizations reduce exposure while continuing to adapt. 

Agentic AI in cybersecurity

Explore actionable takeaways ↗

This is especially important as AI becomes more embedded in how organizations operate. AI can help teams analyze vast amounts of information, identify patterns, and surface recommendations at a scale that was previously unthinkable. Those AI outputs still require oversight, governance, and human judgment, with clear accountability for how AI-generated insights are validated and used. But insight only creates value when it is grounded in the right context and connected to action. 

AI-generated insights still require validation, oversight, and resilience planning because AI systems can produce incomplete or inaccurate outputs.

Clarity creates better decisions 

The most important security decisions start with a clear view of the risk, the level of control or visibility required, and the outcome the system is designed to achieve. When we optimize for capability over context, we miss how security decisions are actually made: through signals, expertise, validation, and judgment. This becomes even more important as AI expands what is possible. Better analysis can surface more insights, but better decisions still depend on understanding what matters most and applying the right context. That matters most when conditions are changing quickly, and teams need to act before every answer is certain. 

Threat intelligence offers a useful example. Defenders operate in environments defined by ambiguity, incomplete information, and rapidly changing conditions. Success rarely comes from a single source or signal. It comes from combining multiple forms of intelligence, applying expertise, validating assumptions, and connecting insights in ways that strengthen assurance.  

The lesson extends beyond threat intelligence. Different security objectives require different combinations of signals, analysis, and human judgment. Resilient decisions come from bringing those elements together thoughtfully, rather than relying on a single source of truth or assuming technology alone can provide the answer. 

Designing for better outcomes  

As AI becomes more embedded in security operations, the quality of our outcomes depends on how clearly we define the objectives we are trying to achieve. Security leaders create the most value when they identify the risks that matter most, the conditions that need to be true, and the systems required to support better decisions. 

Then we design for those outcomes through the right mix of controls, safeguards, and decision-making processes. This shows up not just in architecture, but in how teams establish guardrails, validate assumptions, and respond to the unexpected. The aim is not to make security harder for defenders. It is to make the work easier to execute, supported by platforms, tooling, and AI that help deliver greater speed, accuracy, and confidence. 

The systems we are building today do not exist in isolation. They interact with people, shape decisions, and operate at a scale that can amplify both strengths and weaknesses. Our responsibility extends beyond technology choices. We have to help organizations design systems they can understand, govern, and rely on with confidence as complexity grows. 

Trust is not something we can take for granted, and that does not change in the era of AI. It is built through deliberate choices: the controls we establish, the visibility we create, the assumptions we validate, and the safeguards we put in place. As AI becomes more embedded in how organizations operate, security leaders have a responsibility to help build confidence in the systems people rely on every day. 

Building trustworthy AI systems requires governance, security, privacy protections, transparency, and accountability across the full technology stack, aligned to responsible AI principles and standards.

The risk is not simply that we choose the wrong tool, model, or platform. The greater risk is believing that one answer can solve a complex, evolving problem. AI can help teams make sense of complexity, but it does not eliminate the need for judgment. If anything, it raises the importance of defining the right outcomes and designing systems that make the right actions easier to take. 

Better security starts with better questions, and with the clarity to act on them. The organizations that succeed will apply AI thoughtfully, define outcomes clearly, and combine analytical power with the expertise, judgment, and adaptability needed to build more resilient systems in the age of AI. 

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post ​​Better security starts with better questions appeared first on Microsoft Security Blog.

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

22 July 2026 at 12:00

Cyber incidents don’t wait—and effective response can’t either. In the age of AI where cyber incidents unfold at machine speed, having the right partnerships in place becomes paramount. While AI is expanding what’s possible, navigating this transformation can be challenging to do alone. That’s why our collaboration with AXA XL is so important—bringing Microsoft Defender Experts Cybersecurity Incident Response services directly to cyber insurance policyholders at the moment it matters most, helping organizations coordinate technical, business, and insurance decisions in parallel rather than in sequence.

This collaboration reflects Microsoft’s continued investment in building an incident response model designed for real-world conditions, where speed, trust, and alignment matter as much as technology.

In a live incident, security, executive, legal, and insurance teams are all acting at once. Without pre-established coordination, those parallel efforts can slow containment and increase risk. Our approach to incident response—and our work with AXA XL—starts by aligning those paths before a crisis begins.

For example, during a ransomware incident, security teams may be actively containing lateral movement while leadership evaluates operational impact, legal teams assess disclosure requirements, and insurers determine coverage pathways—all within the same window of time. When those decisions aren’t aligned, response slows and risk compounds.

Decades of supporting customers through high-stakes cyber incidents have reinforced a clear truth: effective incident response extends beyond technical execution. It requires coordination across teams and partners before the crisis hits. That experience continues to shape how we design Defender Experts Cybersecurity Incident Response—and how we work with partners like AXA XL.

Incident response must extend beyond technology

As a global insurance provider, AXA XL plays a critical role in helping organizations navigate cyber risk and response. Through this collaboration, AXA XL policyholders gain coordinated access to Microsoft’s dedicated incident response teams—combining threat containment, restoration, and recovery with insurance, legal, and regulatory workflows. By aligning AXA XL’s cyber insurance capabilities with Defender Experts Cybersecurity Incident Response, organizations benefit from a more integrated response model while gaining access to incident response teams informed by Microsoft Threat Intelligence and two decades of experience responding to some of the world’s most complex and consequential cyber incidents.

Previously, organizations often brought incident responders and insurers together in the middle of a crisis. With this collaboration, that relationship is already in place, reducing friction, delays, and uncertainty when time is most critical. AXA XL policyholders and Microsoft customers can now bring Defender Experts Cybersecurity Incident Response to the table the moment it matters—creating a clearer, more predictable path from detection to recovery. The outcome is not simply faster response, but confidence: knowing who to call, how response engages, and how recovery is operationalized before the next decision becomes urgent.

The threat of a cybersecurity incident has long been ‘not if, but when,’ and in the wake of AI, the ‘when’ may quickly become ‘how often.’ The risks organizations are tasked with preventing and overcoming relative to cybersecurity and data privacy are growing exponentially. Partnering with experts can make all the difference where resilience in the face of adversity may be your only saving grace. AXA XL’s strategic partnerships with  cyber incident response providers underscore our commitment to expertise, preparedness, and resilience. By drawing on a deep knowledge of internal expertise and external cyber specialists, we empower our insureds to respond swiftly and effectively to prevail when your number is up.”

—Gwenn Cujdik, Incident Response and Cyber Services Lead for North America, AXA XL

This collaboration reflects Microsoft’s continued investment in building an incident response model designed for real-world conditions, where speed, trust, and coordination matter as much as technology.

Incident response engineered for high-stakes moments—and the readiness behind them

What differentiates Microsoft Defender Experts Cybersecurity Incident Response is not only its deep technical expertise, but its direct connection to Microsoft engineering teams and Microsoft Threat Intelligence. Responders bring first-party insight into identity-based attacks, cloud intrusions, and enterprise compromise—insight informed directly by Microsoft’s global telemetry and security engineering teams. This connection enables responders to move quickly—from identifying the root cause of an attack to deploying mitigations informed by global threat signals. When combined with pre-aligned partners like AXA XL, that technical strength becomes even more impactful, allowing organizations to act decisively without navigating uncertainty during a crisis.

That same expertise extends beyond the moment of crisis. Delivered by the same frontline experts, Microsoft Defender Experts Cybersecurity Incident Response proactive services—incident response planning, assessments, simulations, and advisory engagements—help organizations build resilience, strengthening their ability to prevent, withstand, and recover from an incident.

These proactive engagements also help align internal teams and external partners before an incident occurs—clarifying roles, escalation paths, and decision-making processes. This preparation ensures that when an incident does occur, organizations are not starting from zero but executing against a coordinated plan. Resilience can mean the difference between containing an incident with minimal disruption and becoming the next headline.

Raising the bar for trusted incident response

The collaboration reinforces Microsoft’s long-standing commitment to delivering trusted cyber incident response services. It also underscores Microsoft’s intent to integrate directly into the cyber risk insurance ecosystem—working alongside insurers rather than operating adjacent to them during critical response moments. It reflects a shared belief that organizations deserve response capabilities that are proven, accessible, and designed to work together when it matters most.

As cyberthreats continue to evolve, Microsoft remains focused on strengthening this ecosystem—working with global insurance leaders like AXA XL to help organizations prepare for disruption, respond with confidence, and recover with resilience.

Learn more

To learn more about how our teams are working together, and how our collaboration with cyber insurance providers like AXA XL can help you strengthen your cyber resilience, visit the Microsoft Defender Experts Cybersecurity Incident Response webpage

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post Real world incident response: Microsoft and AXA XL strengthen cyber resilience appeared first on Microsoft Security Blog.

Turning threat intelligence into decisive action with Defender Experts

15 July 2026 at 12:00

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. Dashboards are full, alerts keep coming, but the hardest question of the day remains unanswered: of everything happening right now, what actually matters to us, and what do we do about it?

That space between knowing a threat exists and acting on it is the intelligence-to-action gap, and it’s where most breaches are won or lost. It doesn’t close with another feed or another dashboard. It closes with expertise: seasoned defenders who know your environment, interpret what global signal means for your risk, and stay with you from the first indicator to the final response.

Today we’re announcing a new service, Microsoft Defender Experts Threat Intelligence, and we are expanding Microsoft Defender Experts MDR to include new third-party and multi-cloud coverage. Together, these human-led offerings are designed to close the intelligence-to-action gap at the two moments that decide the outcome: before a campaign reaches you, and as it moves through your environment.

Upstream: See the campaign before it reaches you

The earlier you see a campaign forming, the more options you have, and the cheaper every decision becomes. Yet most threat intelligence still arrives as raw feeds or static reports: high in volume, low in context, and disconnected from what’s exposed in your estate. Teams end up with more to read and no more clarity on what to do about it.

Microsoft Defender Experts Threat Intelligence is a new, expert-delivered service that closes that distance. Built on Microsoft’s visibility across endpoints, identity, cloud, and evolving attacker activity, it gives your team periodic, curated insight into the threats most likely to target you. Designated Microsoft experts interpret the global landscape through the lens of your industry, geography, and environment, then translate it into clear, prioritized guidance your team can act on.

As campaigns evolve, experts continuously refine that guidance with newly observed infrastructure, tactics, and targeting patterns, helping your team adjust hunting, hardening, and response activities. The insight is tailored for both leadership and defenders, providing executive-ready context alongside technical recommendations so the entire organization can act from a shared understanding of the threat landscape. The goal is simple: help you reduce risk before an attack reaches your environment, not explain what happened after the fact.

In practice, your team receives:

  • Early-warning alerts on emerging campaigns relevant to you
  • Campaign-evolution updates as activity unfolds
  • Contextualized intelligence tied to your risk profile
  • Recurring briefings from your designated expert, rotating across geopolitical, industry, and global perspectives, on a scheduled basis

In your environment: Follow the threat everywhere it moves

Modern attacks rarely stay in one place. They cross from email to endpoint to identity to cloud, and increasingly traverse disparate security tools. Even when organizations have visibility into those environments, connecting multi-vendor and multi-domain signals into a coherent attack story remains a challenge.

That’s the gap we’re closing on the response side: Microsoft Defender Experts MDR (formerly Microsoft Defender Experts for XDR) is expanding with new third-party and multi-cloud coverage powered by Microsoft Sentinel. Defender Experts MDR provides a fully managed detection and response service that reduces noise, adds expert context, and drives action. With support for leading non-Microsoft sources across cloud, identity, email, network, and endpoint environments, our experts can follow attacks wherever they move, not just where Microsoft products operate.

The service is backed by Microsoft’s vast threat intelligence, and combines expert-authored detections and analytics, investigation and response automation, and ongoing operational guidance to help customers strengthen security outcomes across their environment.

In practice, customers gain:

  • 24/7 monitoring and investigation by Microsoft experts who distil high‑volume telemetry into high‑confidence, prioritized incidents that dramatically reduce analyst fatigue and accelerate response.
  • Cross-platform threat analysis that correlates signals across Microsoft and non-Microsoft environments to deliver a single incident narrative with actionable, vendor‑aware guidance.
  • Ongoing recommendations to optimize security operations, from detection tuning and data integration to content management in Sentinel.
  • Business-aligned summaries of top risks, posture gaps, and recommended improvements across the security estate.

This expanded coverage is available through Microsoft Defender Experts MDR Plan 2. Everything available today as Defender Experts for XDR carries forward unchanged as Microsoft Defender Experts MDR Plan 1, while Plan 2 extends that same expert-led triage, investigation, and response beyond Microsoft’s own estate.

See it live at Black Hat USA

Every one of today’s announcements aims at the same outcome: shrinking the distance between a signal arriving and a decision being made. That’s the measure that matters in the end—not alerts triaged, but decisions made faster and with more confidence.

Come see it at Black Hat. Join our session Mind the Gap: Turning Threat Intelligence into Decisive Action with Expert-Led Defense, where Wes Malaby, General Manager of Customer Success at Microsoft Security, will demonstrate how expert-led intelligence and defense can change the trajectory of a threat campaign from the earliest warning signs through response and remediation. After the session, stop by the Microsoft Security booth to connect with our experts and learn how these services fit into your broader security strategy, or attend our reception on August 5 for a more conversational environment.

The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog.

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

22 July 2026 at 12:00

Cyber incidents don’t wait—and effective response can’t either. In the age of AI where cyber incidents unfold at machine speed, having the right partnerships in place becomes paramount. While AI is expanding what’s possible, navigating this transformation can be challenging to do alone. That’s why our collaboration with AXA XL is so important—bringing Microsoft Defender Experts Cybersecurity Incident Response services directly to cyber insurance policyholders at the moment it matters most, helping organizations coordinate technical, business, and insurance decisions in parallel rather than in sequence.

This collaboration reflects Microsoft’s continued investment in building an incident response model designed for real-world conditions, where speed, trust, and alignment matter as much as technology.

In a live incident, security, executive, legal, and insurance teams are all acting at once. Without pre-established coordination, those parallel efforts can slow containment and increase risk. Our approach to incident response—and our work with AXA XL—starts by aligning those paths before a crisis begins.

For example, during a ransomware incident, security teams may be actively containing lateral movement while leadership evaluates operational impact, legal teams assess disclosure requirements, and insurers determine coverage pathways—all within the same window of time. When those decisions aren’t aligned, response slows and risk compounds.

Decades of supporting customers through high-stakes cyber incidents have reinforced a clear truth: effective incident response extends beyond technical execution. It requires coordination across teams and partners before the crisis hits. That experience continues to shape how we design Defender Experts Cybersecurity Incident Response—and how we work with partners like AXA XL.

Incident response must extend beyond technology

As a global insurance provider, AXA XL plays a critical role in helping organizations navigate cyber risk and response. Through this collaboration, AXA XL policyholders gain coordinated access to Microsoft’s dedicated incident response teams—combining threat containment, restoration, and recovery with insurance, legal, and regulatory workflows. By aligning AXA XL’s cyber insurance capabilities with Defender Experts Cybersecurity Incident Response, organizations benefit from a more integrated response model while gaining access to incident response teams informed by Microsoft Threat Intelligence and two decades of experience responding to some of the world’s most complex and consequential cyber incidents.

Previously, organizations often brought incident responders and insurers together in the middle of a crisis. With this collaboration, that relationship is already in place, reducing friction, delays, and uncertainty when time is most critical. AXA XL policyholders and Microsoft customers can now bring Defender Experts Cybersecurity Incident Response to the table the moment it matters—creating a clearer, more predictable path from detection to recovery. The outcome is not simply faster response, but confidence: knowing who to call, how response engages, and how recovery is operationalized before the next decision becomes urgent.

The threat of a cybersecurity incident has long been ‘not if, but when,’ and in the wake of AI, the ‘when’ may quickly become ‘how often.’ The risks organizations are tasked with preventing and overcoming relative to cybersecurity and data privacy are growing exponentially. Partnering with experts can make all the difference where resilience in the face of adversity may be your only saving grace. AXA XL’s strategic partnerships with  cyber incident response providers underscore our commitment to expertise, preparedness, and resilience. By drawing on a deep knowledge of internal expertise and external cyber specialists, we empower our insureds to respond swiftly and effectively to prevail when your number is up.”

—Gwenn Cujdik, Incident Response and Cyber Services Lead for North America, AXA XL

This collaboration reflects Microsoft’s continued investment in building an incident response model designed for real-world conditions, where speed, trust, and coordination matter as much as technology.

Incident response engineered for high-stakes moments—and the readiness behind them

What differentiates Microsoft Defender Experts Cybersecurity Incident Response is not only its deep technical expertise, but its direct connection to Microsoft engineering teams and Microsoft Threat Intelligence. Responders bring first-party insight into identity-based attacks, cloud intrusions, and enterprise compromise—insight informed directly by Microsoft’s global telemetry and security engineering teams. This connection enables responders to move quickly—from identifying the root cause of an attack to deploying mitigations informed by global threat signals. When combined with pre-aligned partners like AXA XL, that technical strength becomes even more impactful, allowing organizations to act decisively without navigating uncertainty during a crisis.

That same expertise extends beyond the moment of crisis. Delivered by the same frontline experts, Microsoft Defender Experts Cybersecurity Incident Response proactive services—incident response planning, assessments, simulations, and advisory engagements—help organizations build resilience, strengthening their ability to prevent, withstand, and recover from an incident.

These proactive engagements also help align internal teams and external partners before an incident occurs—clarifying roles, escalation paths, and decision-making processes. This preparation ensures that when an incident does occur, organizations are not starting from zero but executing against a coordinated plan. Resilience can mean the difference between containing an incident with minimal disruption and becoming the next headline.

Raising the bar for trusted incident response

The collaboration reinforces Microsoft’s long-standing commitment to delivering trusted cyber incident response services. It also underscores Microsoft’s intent to integrate directly into the cyber risk insurance ecosystem—working alongside insurers rather than operating adjacent to them during critical response moments. It reflects a shared belief that organizations deserve response capabilities that are proven, accessible, and designed to work together when it matters most.

As cyberthreats continue to evolve, Microsoft remains focused on strengthening this ecosystem—working with global insurance leaders like AXA XL to help organizations prepare for disruption, respond with confidence, and recover with resilience.

Learn more

To learn more about how our teams are working together, and how our collaboration with cyber insurance providers like AXA XL can help you strengthen your cyber resilience, visit the Microsoft Defender Experts Cybersecurity Incident Response webpage

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post Real world incident response: Microsoft and AXA XL strengthen cyber resilience appeared first on Microsoft Security Blog.

Turning threat intelligence into decisive action with Defender Experts

15 July 2026 at 12:00

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. Dashboards are full, alerts keep coming, but the hardest question of the day remains unanswered: of everything happening right now, what actually matters to us, and what do we do about it?

That space between knowing a threat exists and acting on it is the intelligence-to-action gap, and it’s where most breaches are won or lost. It doesn’t close with another feed or another dashboard. It closes with expertise: seasoned defenders who know your environment, interpret what global signal means for your risk, and stay with you from the first indicator to the final response.

Today we’re announcing a new service, Microsoft Defender Experts Threat Intelligence, and we are expanding Microsoft Defender Experts MDR to include new third-party and multi-cloud coverage. Together, these human-led offerings are designed to close the intelligence-to-action gap at the two moments that decide the outcome: before a campaign reaches you, and as it moves through your environment.

Upstream: See the campaign before it reaches you

The earlier you see a campaign forming, the more options you have, and the cheaper every decision becomes. Yet most threat intelligence still arrives as raw feeds or static reports: high in volume, low in context, and disconnected from what’s exposed in your estate. Teams end up with more to read and no more clarity on what to do about it.

Microsoft Defender Experts Threat Intelligence is a new, expert-delivered service that closes that distance. Built on Microsoft’s visibility across endpoints, identity, cloud, and evolving attacker activity, it gives your team periodic, curated insight into the threats most likely to target you. Designated Microsoft experts interpret the global landscape through the lens of your industry, geography, and environment, then translate it into clear, prioritized guidance your team can act on.

As campaigns evolve, experts continuously refine that guidance with newly observed infrastructure, tactics, and targeting patterns, helping your team adjust hunting, hardening, and response activities. The insight is tailored for both leadership and defenders, providing executive-ready context alongside technical recommendations so the entire organization can act from a shared understanding of the threat landscape. The goal is simple: help you reduce risk before an attack reaches your environment, not explain what happened after the fact.

In practice, your team receives:

  • Early-warning alerts on emerging campaigns relevant to you
  • Campaign-evolution updates as activity unfolds
  • Contextualized intelligence tied to your risk profile
  • Recurring briefings from your designated expert, rotating across geopolitical, industry, and global perspectives, on a scheduled basis

In your environment: Follow the threat everywhere it moves

Modern attacks rarely stay in one place. They cross from email to endpoint to identity to cloud, and increasingly traverse disparate security tools. Even when organizations have visibility into those environments, connecting multi-vendor and multi-domain signals into a coherent attack story remains a challenge.

That’s the gap we’re closing on the response side: Microsoft Defender Experts MDR (formerly Microsoft Defender Experts for XDR) is expanding with new third-party and multi-cloud coverage powered by Microsoft Sentinel. Defender Experts MDR provides a fully managed detection and response service that reduces noise, adds expert context, and drives action. With support for leading non-Microsoft sources across cloud, identity, email, network, and endpoint environments, our experts can follow attacks wherever they move, not just where Microsoft products operate.

The service is backed by Microsoft’s vast threat intelligence, and combines expert-authored detections and analytics, investigation and response automation, and ongoing operational guidance to help customers strengthen security outcomes across their environment.

In practice, customers gain:

  • 24/7 monitoring and investigation by Microsoft experts who distil high‑volume telemetry into high‑confidence, prioritized incidents that dramatically reduce analyst fatigue and accelerate response.
  • Cross-platform threat analysis that correlates signals across Microsoft and non-Microsoft environments to deliver a single incident narrative with actionable, vendor‑aware guidance.
  • Ongoing recommendations to optimize security operations, from detection tuning and data integration to content management in Sentinel.
  • Business-aligned summaries of top risks, posture gaps, and recommended improvements across the security estate.

This expanded coverage is available through Microsoft Defender Experts MDR Plan 2. Everything available today as Defender Experts for XDR carries forward unchanged as Microsoft Defender Experts MDR Plan 1, while Plan 2 extends that same expert-led triage, investigation, and response beyond Microsoft’s own estate.

See it live at Black Hat USA

Every one of today’s announcements aims at the same outcome: shrinking the distance between a signal arriving and a decision being made. That’s the measure that matters in the end—not alerts triaged, but decisions made faster and with more confidence.

Come see it at Black Hat. Join our session Mind the Gap: Turning Threat Intelligence into Decisive Action with Expert-Led Defense, where Wes Malaby, General Manager of Customer Success at Microsoft Security, will demonstrate how expert-led intelligence and defense can change the trajectory of a threat campaign from the earliest warning signs through response and remediation. After the session, stop by the Microsoft Security booth to connect with our experts and learn how these services fit into your broader security strategy, or attend our reception on August 5 for a more conversational environment.

The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog.

❌
❌