AI in Security Operations: Practical Use Cases for Security Teams

In this session, Jonathan Reed (Microsoft) explored how AI can help modern security teams address an increasingly complex threat landscape. He outlined common challenges facing SOCs, including tool sprawl, a growing number of threat actors, and the global cybersecurity talent shortage. Jonathan explained why generic large language models fall short for security use cases and how Microsoft Security Copilot is purpose-built with a security-specific LLM, real-time threat intelligence, and integrations across Microsoft and third‑party tools. Through a live demonstration, Jonathan showed how Security Copilot uses natural language prompts, promptbooks, plugins, and automated agents to accelerate incident response, generate security health reports, and support guided investigations—all while keeping customer data within strict boundaries. The session concluded with Q&A, including discussion on managing shadow IT risks related to AI and LLM usage in enterprise environments.