For the first time, the attacker can lose
"And this is the first time in my career in security where it's actually possible, or even probable, that the attacker might lose the game in the end."
Taesoo Kim said this in an interview that Microsoft published when announcing Project Perception. Kim won DARPA's AI Cyber Challenge with Team Atlanta last year and has been VP of Security Research at Microsoft for six months, where he leads the new Microsoft Security FORGE Labs. He said it about his own field and not about one product. Anyone who has followed the past year knows how remarkable such a statement is.
Because the past year mainly went in the other direction. In February, someone called Odido's helpdesk in fluent Dutch, pretended to be internal IT and persuaded an employee to log in to a fake page. The police confirmed that part. According to the account of the attackers themselves, it then went through the CRM system to an export of the data of more than six million people. No zero-day: a convincing voice and an account with too many rights.
In the same period, the cost of finding real vulnerabilities collapsed. In the finals of DARPA's AI Cyber Challenge, the participating systems found eighteen real, non-artificially planted vulnerabilities and provided eleven patches. Tim Becker, a researcher at Theori, told The Verge that work that took him weeks or months to complete now takes hours. And in July, during an internal evaluation, OpenAI models gained access to the internet via a zero-day and compromised Hugging Face, which published the intrusion itself.
Technically, these three have little to do with each other. What they share is pace and scale on the attack side. Earlier this month ,we wrote that those who rely entirely on human speed are structurally behind. Since last week, there has been an answer to this.
The Cyber Stack as a layered system, with the red, blue and green agents working right through it.
What Microsoft announced
On July 27, Microsoft introduced Project Perception, a security system that works with autonomously acting AI agents. The reason, in the words of Hayete Gallot, the executive vice president who leads Microsoft Security: the physics of cybersecurity is changing, and the approach that worked against human attackers is not keeping pace in a world of AI and agents.
What follows below is how Microsoft describes the system. Perception coordinates three types of agents, and the colors represent really different roles.
-
Red agents continuously examine the attack paths visible in the available security context, exposing gaps in your detection coverage.
-
Blue agents triage notifications, reconstruct what happened, and determine what is actual risk.
-
Repair and harden green agents: analyze security postures, validate exposure, prioritize and implement remediation actions.
Together they form a loop. Red finds, blue judges, green recovers, and that changes what red finds next time. Man should stay in that loop for the decisions that matter.
Underneath those agents is a stack of six layers.
How AI is reshaping both attack and defence
The six layers of the Cyber Stack, from signals to actuators.
Signals and sensors provide a view of the environment. Security context makes a representation of what an agent can reason about. Models provide the reasoning, a harness (the orchestration layer) controls models and agents, the agents do the work in security workflows, and actuators convert a decision into a change in the environment. The latter layer is the least discussed and perhaps the most difficult. Repair is only possible if someone owns the buttons. This includes enforcement points such as Conditional Access, isolating a device, revoking tokens, or data loss prevention (DLP) policies. Microsoft has those kinds of buttons in its own stack, and that's exactly why this type of loop can land there, according to Microsoft.
Two names were added. MAI-Cyber-1-Flash is the first model that Microsoft built specifically for security. That's in MDASH, a team of agents that scans code for vulnerabilities, and MDASH is one of the sources that feeds Perception. According to Microsoft, that combination achieves 96 percent on the CyberGym benchmark, twelve points above Mythos, at about half the cost of the MDASH configuration that Microsoft already has on the market. These are numbers about this one workflow, finding and fixing vulnerabilities in code.
Why this is changing the rules of the game
The three processes below already existed separately. What changes is that they will be in one closed cycle, at a frequency that has rarely been possible in practice.
Defense searches continuously instead of periodically. If you work from a list of known vulnerabilities, you search in a smaller space than the attacker searches. A red officer who runs day and night comes closer to that space, insofar as it is visible in the security context. What falls outside of that remains out of the picture: unmanaged assets, suppliers, the phone.
The distance between knowing and writing poetry is getting shorter. I find this the most interesting part. Most security programs are good at finding vulnerabilities and bad at closing them, because a finding becomes a ticket and that ticket becomes a sprint. A cycle in which green follows on from what blue judged can shorten that distance considerably.
What such a cycle is not for: it does not reach into an export that is already running. The Odido scenario with which this piece opens requires prevention in the path itself and accounts without redundant privileges. Finding, assessing and repairing reduces the chance that such a path is still there. An ongoing exfiltration does not stop it. Fortunately, that can already be covered with Microsoft Purview.
Mustafa Suleyman wrote at the announcement that token fees are now the real constraint for defenders. An attack is a burst of hours or days against one target. Defending is continuous, over everything you have, without an end date. The same price per action then results in very different bills. Microsoft's answer is routing: a cheap specialized model does the volume, the expensive model only the difficult rest. Cheaper models help the attacker just as much, of course. DARPA calculated that an assignment in the final cost an average of about 152 dollars, and that shows how fast things are moving in that direction. The difference is that the defender now has a way to carry the volume.
Next level security
Why Wortell is already involved in this
Wortell is the only Dutch partner participating in the design partner program around Perception. We test the system in the field while it is still in development, and our findings go directly to Microsoft's product team. This saves time for our customers: we are already learning what this kind of defense requires from an environment before it is generally available.
What this means for your organization
First, look at what Perception is all about.
From signals and sensors, via security context, to the red, blue and green agents.
The signal sources include Microsoft Defender for Endpoint, Entra ID, Microsoft Sentinel, Microsoft Purview, and Microsoft Azure; User and entity behavioral analysis, Exposure Management, and threat intelligence.
So Perception is not a new platform that you put next to it. It's the same data that you already collect today for detection and threat hunting, in a form that agents can use. Those who have already consolidated their security strategy on Microsoft Defender XDR and Sentinel have the foundation that these types of agents count on.
For our Managed eXtended Detection and Response (MxDR) customers, this is concrete. Your environment provides that telemetry, and the consolidation work we have done together is now the prerequisite. For those who have not yet taken that step, the conclusion is just as concrete. Onboarding to MxDR controls 24/7 detection and response from our Cyber Defense Center while providing the telemetry layer that these types of agents work on.
Where this is going
The first is that man does not disappear from the picture. Tim Russell, Cybersecurity Director at Nationwide Building Society, one of the first organizations to work with Perception, puts it this way: "This technology helps to amplify their skill sets, not to replace them." We know this shift from our own MxDR service. There, we already respond to more than 80 percent of attacks automatically within seconds, and that has not replaced an analyst. It shifted their work to the cases where judgment counts and to building the process itself. Agents accelerate that movement. It's the same movement.
The second is that speed without accountability has little value. The Cybersecurity Act, with which the Netherlands introduces the European NIS2 Directive and which will enter into force on 15 August, lays down a duty of care, a duty of notification and administrative responsibility. It's not just about whether you have tooling, but whether you can substantiate your measures and incident handling. An officer who adjusts something in your environment makes that question sharper. That is why a service that records what has been seen, decided and done for each incident counts, whether it was done by an analyst or by an agent.
Kim can be optimistic about the outcome. What he describes is still a race. What changes is that the side that owns the buttons in the environment can participate for the first time with the same means.
Three questions to ask yourself
-
How long does it take us between finding a weak spot and closing it? And do we know that, or do we think so?
-
Is our detection on one consolidated foundation, or still divided over separate tools?
-
Can we explain to the management and supervisor what happened in the last incident, and on the basis of what evidence?
The answers say a lot about the resilience of your organization. Do you want to know what defense with AI agents means for your environment, and whether that telemetry foundation is already in place? Our security specialists are happy to think along with you. We start with factual insight into where you are now.