St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents
Security teams often struggle with a lack of unified visibility across their tools, which delays the detection and neutralization of threats. St. Luke's addressed this challenge by implementing Microsoft Security Copilot to integrate its security stack. This integration drastically reduced the time spent on phishing triage, saving the organization nearly 200 hours every month. Watch the video to learn how they achieved these results.
How is St. Luke’s using AI-powered Security Copilot?
St. Luke’s University Health Network uses Microsoft’s Security Copilot in Microsoft Defender as the “connective tissue” across its security stack. Instead of working in separate tools for alerts, access controls, and vulnerabilities, their security team now has a single, AI-powered view that consolidates this information.
In practice, this means Security Copilot agents help analysts:
- Correlate alerts from different systems into one place
- See access control issues alongside threat activity
- Identify and prioritize vulnerabilities more quickly
By bringing these elements together, St. Luke’s is reimagining how its security operations center works, moving from fragmented tools to a more integrated, AI-assisted workflow.
What measurable impact has Security Copilot had at St. Luke’s?
St. Luke’s reports a clear time savings from using AI-powered Security Copilot agents. According to their data, the organization saves nearly 200 hours every month in security operations work.
This time savings comes from:
- Faster investigation of security alerts
- Reduced manual correlation across multiple tools
- Quicker identification of access and vulnerability issues
Those ~200 hours per month can be redirected to higher-value security tasks, such as proactive threat hunting, improving security policies, and strengthening overall resilience.
How does Security Copilot change the security workflow?
For St. Luke’s, Security Copilot helps reshape the security workflow by acting as an AI-powered assistant that sits across their existing tools. Instead of pivoting between separate systems for:
- Security alerts
- Access control data
- Vulnerability information
analysts can work from a consolidated, AI-driven view. The Copilot agents help summarize activity, surface what matters most, and guide next steps.
This rethinks the traditional, tool-centric approach to security operations and supports a more streamlined, insight-driven way of working—while still leveraging the organization’s existing Microsoft Defender and Microsoft Sentinel investments.
St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents
published by Summit V
Securing, Defending, & Building Cyber Resilience