MicrosoftExploringEvidence: Medium55/100

Auckland Transport speeds incident response and reduces alert fatigue with Microsoft Security Copilot agents

Auckland Transport modernized its security operations after a ransomware attack exposed visibility gaps across its network. The transport agency used Microsoft Security Copilot with Microsoft Defender and Microsoft Sentinel to consolidate signals, summarize threat intelligence, and guide analysts through incident investigations.

Organization
Auckland Transport
Location
New Zealand
Published
January 2025

Reported outcomes

Strategic outcomes

Speed & agilityFaster incident triageEmployee experienceReduced alert fatigue for analystsOther strategic outcomeImproved junior analyst ramp-up
Why do we believe this deployment?Customer identity, provider attribution, maturity, and source checks
Customer
Auckland Transport
Provider
Microsoft
Maturity
Exploring

Began exploring Security Copilot agents such as Threat Intelligence Briefing Agent, Phishing Triage Agent, and Conditional Access Optimization Agent to automate more investigative legwork

Customer identity supportedSource describes one deploymentMaturity supported

Primary read

Use case focus

Showing 2 of 2

  • 1Customer service agent
  • 2Workflow automation
  • A 2023 ransomware attack exposed visibility gaps and control gaps across Auckland Transport's complex security environment.
  • The SOC faced alert fatigue and inconsistencies in incident handling across many systems and analysts.
  • Adopted Microsoft Defender and Microsoft Sentinel as the standardized security foundation.
  • Integrated Microsoft Security Copilot to streamline incident triage, summarize threat intelligence, and guide investigative steps.
  • Began exploring Security Copilot agents such as Threat Intelligence Briefing Agent, Phishing Triage Agent, and Conditional Access Optimization Agent to automate more investigative legwork.
  • Incident triage was streamlined and repetitive work reduced.
  • Analysts resolved alerts faster, reduced alert fatigue, and improved consistency across incident reports.
  • Junior analysts were able to ramp up faster and the team focused more on higher-value security work.
Sources & evidence1
Evidence: Medium55/100Evidence strength
  • Customer explicitly identified
  • Deployment status explicitly supported
  • Primary source available
  • Technical implementation details available
Type: Customer StoryPublished: Jan 1, 2025Publisher: MicrosoftEvidence: PrimaryConfidence: High

AI-generated summary. Verify important details with the linked sources before relying on this case.

Explore related AI use cases

Was this useful?

Community

Comments

No published comments yet.