St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents
Security teams often struggle with a lack of unified visibility across their tools, which delays the detection and neutralization of threats. St. Luke's addressed this challenge by implementing Microsoft Security Copilot to integrate its security stack. This integration drastically reduced the time spent on phishing triage, saving the organization nearly 200 hours every month. Watch the video to learn how they achieved these results.
How is St. Luke’s using AI-powered Security Copilot?
St. Luke’s University Health Network uses Microsoft’s Security Copilot in Microsoft Defender as the central layer that connects its entire security stack. Instead of working in separate tools for alerts, access controls, and vulnerabilities, their team now relies on Security Copilot as the “connective tissue” that brings all of this data together.
In practice, that means Security Copilot:
- Aggregates alerts from across their environment into a single, AI-assisted view.
- Correlates access control events with potential threats.
- Surfaces vulnerabilities in context, so analysts can see what matters most.
This AI-powered, agentic approach helps St. Luke’s reimagine how their security team works, moving from manual, tool-by-tool investigation to a more guided, consolidated workflow.
What measurable impact has Security Copilot had at St. Luke’s?
St. Luke’s reports a clear, measurable benefit from using Security Copilot: they save nearly 200 hours every month in their security operations.
Those time savings come from:
- Reducing manual investigation across multiple tools.
- Speeding up triage and response by using a consolidated, AI-guided view.
- Automating parts of analysis that previously required repetitive human effort.
By reclaiming close to 200 hours per month, the security team can focus more on higher-value work such as proactive threat hunting, improving policies, and strengthening overall security posture.
How does Security Copilot fit with Microsoft Defender and Sentinel?
At St. Luke’s, Security Copilot in Microsoft Defender acts as an AI-powered layer on top of their existing Microsoft security tools, including Microsoft Defender and Microsoft Sentinel.
In this setup:
- Microsoft Defender provides endpoint and threat protection signals.
- Microsoft Sentinel aggregates and analyzes security data across the organization.
- Security Copilot connects these signals and insights, giving analysts a consolidated, AI-driven view of alerts, access controls, and vulnerabilities.
This combination helps St. Luke’s reshape how their security operations center works—moving from fragmented data across tools to a more integrated, AI-assisted experience that supports faster, more informed decisions.
St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents
published by CX Consulting (Pty) Ltd
CX Consulting was established in 2020 by Pieter vd Walt. With the ever increasing threat of cyber attacks and cyber crime, organisations are often at a loss at what to do. New software vulnerabilities are found daily, web application attacks leave websites vulnerable and viruses become increasingly silent and stealthy. Often, the simplest things such as weak passwords and uneducated staff can be the cause of an entire company infrastructure being compromised. Our aim is to make your company or organisation as unattractive to cybercriminals as possible - and keeping your sensitive financial and client data safe. This is done in a variety of ways including attack and penetration testing, vulnerability assessments, user awareness campaigns, and keeping your company constantly safe with a month-to-month service level agreement. We also consult and provide managed IT services to support medium sized firms with their IT infrastructure. We are a premium IT service provider focused on medium sized businesses. We no longer focus on the break & fix model as our aim is to prevent and minimize downtime.