Microsoft Perception: Adding agents and retooling AI's costs
With Project Perception, Microsoft offers a multi-agent path for finding and fixing vulnerabilities. And the company has ideas on containing AI security costs.
Microsoft made a couple of significant announcements that are worth watching: Project Perception, which provides a multi-agent approach to cybersecurity, and a custom model for security tasks that changes the cost curve for AI-driven security.
Project Perception is an agentic security system that brings together DevOps and SecOps to continuously identify, evaluate, mitigate and respond to security vulnerabilities. Merging these with DevSecOps practices should optimize remediation efficiency, taking big chunks of risk off the table. The DevSecOps approach enables the SecOps team to identify vulnerabilities and take mitigation actions -- deploying detection for vulnerability exploitation, virtual patching to mitigate, etc. -- while DevOps achieves visibility to understand the vulnerability and implement a permanent fix. Perception provides a unified approach with different surfaces for different teams. At an analyst roundtable event in San Francisco, Hayete Gallot, executive vice president at Microsoft Security, indicated that the multi-agent approach could be applied to other cybersecurity problems.
A subtext of the Microsoft announcement was affordability with a multimodel approach to AI. Some tasks need a frontier model while other tasks can use something cheaper. And Microsoft provided some benchmarking substantiation.
Microsoft unveiled MAI-Cyber-1-Flash, a cybersecurity-specialized AI model designed for software vulnerability analysis inside MDASH, Microsoft's multi-agent vulnerability identification and remediation harness. MAI-Cyber-1-Flash shone in the CyberGym benchmark compared to Gemini, GPT and Mythos, but the big news was its cost-effectiveness. Microsoft pointed to MAI-Cyber-1-Flash within MDASH costing 50% of leading models.
The Microsoft announcements dovetail with research from Omdia, a division of Informa TechTarget. In "The Dream is Real: An Autonomous Security Operations Center is Within Reach," published in July, we found that the biggest expected benefits from AI investments in SecOps were improved overall security posture (18%) and freeing up staff for more proactive security functions (18%).
Pricing for Perception, which enters public preview this week, has not been announced. Microsoft indicated the pricing would be based on consumption, which scales with the value provided. The company has its persistent eye on the AI affordability challenge -- the tokenomics -- with the multimodel approach, and I expect there will be an ongoing focus on delivering optimal price and performance.
Todd Thiemann is a senior analyst covering identity access management and data security for Omdia. He has more than 20 years of experience in cybersecurity marketing and strategy.
Omdia is a division of Informa TechTarget. Its analysts have business relationships with technology vendors.