Jang Kwang-woon, security strategy adviser at Microsoft Korea

[DigitalToday reporter Chi-gyu Hwang] "Security teams must shift from organisations that process tasks to organisations accountable for outcomes."

Jang Kwang-woon (장광운), security strategy adviser at Microsoft Korea, presented outcome-based operations as a security strategy against AI-driven automated attacks in a keynote speech at the Industry Summit held on Tuesday at the COEX Grand Ballroom in Seoul.

He said security teams need to change their approach so agents handle execution and people are responsible for outcomes.

Jang said that as AI-driven attacks accelerate, security work has grown beyond what people can handle. A Microsoft 2025 report said 41 percent of security alerts are left uninvestigated. The average cost of damage from data breaches reached 6 billion won, and only 14 percent of organisations were confident they had the necessary capabilities. "Hiring 10 to 20 percent more security staff cannot solve these problems, and it is not enough just to introduce AI agents," Jang said.

Assigning a separate agent to each individual task, such as reviewing prompt injection, patching and checking access alerts, speeds up work. It can raise what a person handled from 10 a day to 20 to 30. But Jang said this approach does not actually strengthen security capabilities.

"Introducing AI in security is not the goal in itself. The real goal is to stop attacks that come in at AI speed," Jang said. He again stressed that attaching agents to fragmented tasks has limits in achieving that goal.

The solution is to change the unit of work itself. He said people should be responsible for achieving goals rather than processing tasks one by one, while agents handle execution.

Microsoft has implemented this process as "Project Perception" and is already providing it to customers. The company said Project Perception gathers security alerts from cloud services and work devices into one place. AI finds the links among the alerts to identify the attack, and agents cover the response while people approve key actions.

ㆍMS to unveil vulnerability detection tool "Project Perception" such as "Mythos" in July... "to offer it cheaply"

In Project Perception, agents work like a single team. A red-team agent checks attack paths like a hacker and finds critical risks and vulnerabilities. A blue-team agent uses those results to create detection rules and analyse the extent of damage. A green-team agent then takes that on to patch vulnerabilities across company assets. Agents automatically pass results among themselves in a structured flow. "All of these elements must interlock to build a defence system suited to the AI era," Jang said.

Jang demonstrated the process with Defender, Microsoft’s integrated security solution. A security officer asks, based on an attacker profile, or threat intelligence, "Are our assets safe?" The agent then draws up an execution plan, and the officer reviews the plan and decides whether to proceed. A person also reviews the reports generated at each stage. Important tasks such as asset scans require approval before execution. At the end, the agent summarises and recommends necessary actions. It is work that would take days to weeks if done directly by a person.

In outcome-based security, people’s roles also change. "Security operators must become orchestrators who design and command an agent-based work system," Jang said. He said individual managers for areas such as data security and cloud security should evolve into strategic advisers who assess threats from a strategic perspective and link them to business outcomes. He also said team members should view security from a team leader’s perspective, and team leaders from a chief information security officer, or CISO, perspective.

From the managers’ point of view, such change is not easy. "Experts with 10 to 20 years of experience have built up a lot of knowledge and skills in their own areas. To move out of that and into strategic work, they need to change their perspective," Jang said. He said organisations must also think together about how to evaluate performance in strategic work that is hard to quantify. "Ironically, completing frontier transformation ultimately has to be done by people," he said. "The direction ahead is to define what to do with the time saved through automation, what the essence of the work is, and to establish an evaluation system."

Keyword

#Microsoft #Project Perception #Defender #CISO #Industry Summit
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.