Auckland Transport speeds incident response and reduces alert fatigue with Microsoft Security Copilot agents
Use case typeCustomer service agentUpdated Jan 1, 2025
Auckland Transport modernized its security operations after a ransomware attack exposed visibility gaps across its network. The transport agency used Microsoft Security Copilot with Microsoft Defender and Microsoft Sentinel to consolidate signals, summarize threat intelligence, and guide analysts through incident investigations.
- Organization
- Auckland Transport
- Industry
- Public Sector
- Location
- New Zealand
- Published
- January 2025
Reported outcomes
Strategic outcomes
Speed & agilityFaster incident triageEmployee experienceReduced alert fatigue for analystsOther strategic outcomeImproved junior analyst ramp-up
Why do we believe this deployment?Customer identity, provider attribution, maturity, and source checks
- Customer
- Auckland Transport
- Provider
- Microsoft
- Maturity
- Exploring
- Linked source
- Microsoft Customer Stories
Began exploring Security Copilot agents such as Threat Intelligence Briefing Agent, Phishing Triage Agent, and Conditional Access Optimization Agent to automate more investigative legwork
Customer identity supportedSource describes one deploymentMaturity supported
Primary read
Use case focus
Showing 2 of 2
- 1Customer service agent
- 2Workflow automation
- A 2023 ransomware attack exposed visibility gaps and control gaps across Auckland Transport's complex security environment.
- The SOC faced alert fatigue and inconsistencies in incident handling across many systems and analysts.
- Adopted Microsoft Defender and Microsoft Sentinel as the standardized security foundation.
- Integrated Microsoft Security Copilot to streamline incident triage, summarize threat intelligence, and guide investigative steps.
- Began exploring Security Copilot agents such as Threat Intelligence Briefing Agent, Phishing Triage Agent, and Conditional Access Optimization Agent to automate more investigative legwork.
- Incident triage was streamlined and repetitive work reduced.
- Analysts resolved alerts faster, reduced alert fatigue, and improved consistency across incident reports.
- Junior analysts were able to ramp up faster and the team focused more on higher-value security work.
Sources & evidence1
Evidence: Medium55/100Evidence strength
- Customer explicitly identified
- Deployment status explicitly supported
- Primary source available
- Technical implementation details available
Type: Customer StoryPublished: Jan 1, 2025Publisher: MicrosoftEvidence: PrimaryConfidence: High
AI-generated summary. Verify important details with the linked sources before relying on this case.
Explore related AI use cases
Customer evidence
Provider evidence
Browse the catalog
Was this useful?
Community
Comments
No published comments yet.