Nearly 200 hours a month, recovered from phishing triage. When St. Luke's University Health Network needed real-time visibility across a fragmented security stack, it adopted Security Copilot in Microsoft Defender as the connective tissue linking alerts, access controls, and vulnerabilities. Agentic capabilities now speed threat response and turn incident reporting from hours into minutes. As a Microsoft Security solutions provider, Bembry Business Solutions can help you apply this approach. Read the story to learn from St. Luke's experience.
How is St. Luke’s using AI to save time in security operations?
St. Luke’s University Health Network uses Microsoft Security Copilot as an AI layer across its existing security stack (including Microsoft Defender, Sentinel, Entra, Purview, and Intune) to streamline and automate key security workflows.
Key time savings and efficiencies:- ~200 hours saved every month in phishing alert triage, thanks to the Phishing Triage Agent in Microsoft Defender.
- Incident reports that previously took hours to compile are now generated in minutes directly within Defender.
- Analysts no longer need to jump between multiple portals and tabs; Security Copilot consolidates alerts, access controls, and vulnerabilities into a single, unified view.
By autonomously handling and closing thousands of false positive phishing alerts, Security Copilot agents free the Security Operations Center (SOC) team from repetitive triage work. This lets analysts focus on higher-value activities such as proactive threat hunting and strategic improvements to St. Luke’s security posture.
What security challenges was St. Luke’s trying to solve with Security Copilot?
St. Luke’s operates
15 campuses,
300 outpatient sites, and manages more than
2.5 petabytes of data and patient records in motion. As a healthcare provider, it is in one of the most frequently targeted sectors for cyberattacks.
Main challenges:- High-risk threat landscape: Healthcare is described as the number one cyberattack target, with phishing and DDoS attacks posing major risks to patient care and operations.
- Fragmented tools: Although St. Luke’s already used Microsoft Defender, Sentinel, Entra, Purview, and other tools, they were largely disconnected, making it hard to get unified, real-time visibility.
- Alert overload: Analysts were inundated with user-reported suspicious emails and hundreds of alerts per day, much of which turned out to be false positives.
- Manual processes: Triage, investigation, and incident reporting were time-consuming and required navigating multiple dashboards.
How Security Copilot helps:- Acts as the “connective tissue” across the security stack, correlating signals from endpoints, email, identity, applications, and cloud workloads.
- Provides AI-powered, real-time visibility into alerts, access controls, and vulnerabilities.
- Uses agents (such as the Phishing Triage Agent, Conditional Access Optimization Agent, and Vulnerability Remediation Agent) to automate triage and remediation tasks.
- Delivers plain-language explanations for decisions, helping analysts quickly understand why an email or alert is classified as malicious or benign.
Overall, Security Copilot helps St. Luke’s reimagine its security operations from reactive and fragmented to more proactive, unified, and data-driven.
How do Security Copilot agents change the work of St. Luke’s security team?
Security Copilot agents have reshaped how St. Luke’s security team spends its time and how it collaborates.
Shift from reactive to proactive work:- The Phishing Triage Agent autonomously handles and closes thousands of false positive phishing alerts, saving nearly 200 hours per month.
- Analysts no longer need to double-check every incident; they’ve gained confidence in the agent’s classification accuracy and use its detailed explanations for context.
- With routine triage largely automated, the team can focus on proactive threat hunting and addressing higher-risk issues.
Embedded AI guidance in the flow of work:- Security Copilot provides AI-fueled guidance directly in existing tools, helping analysts identify gaps, understand where they are “not seeing things,” and prioritize remediation.
- Incident reporting is largely automated: Security Copilot generates clear, sequential incident reports that can be quickly copied, enriched with context, and escalated to leadership or forensics.
Impact on team experience and collaboration:- By reducing repetitive, manual tasks, Security Copilot contributes to lower analyst burnout and higher job satisfaction.
- All relevant incident information is available in one place, improving collaboration and speeding up decision-making.
- Leaders at St. Luke’s describe Security Copilot as almost like having an extra team member or mentor, helping the security function grow and mature.
For St. Luke’s, these agents are the foundation of an AI-first, self-improving security ecosystem that supports both operational resilience and better use of the team’s expertise.