AI News Feed
Market watch
Cybersecurity

Microsoft Launches ISOC for AI Agents as Oracle Pushes Security to the Data Layer

Microsoft launched the Integrated Security Operations Center in Defender for AI agents on Sept. 23, while Oracle detailed database-layer controls that keep authorization beneath applications and agents.

Rob Lefferts, corporate vice president of Microsoft Threat Protection, wrote in a company blog post that work once requiring entire teams now requires a single operator and an agent framework, and that defenders fall behind when protection and day-to-day operations run as separate systems and analysts have to piece incidents together by hand across several tools. In ISOC, agents receive the same signals, context and controls as a human analyst, with core security workflows wired in by default so an agent can investigate an incident and act on it without a separate operating model.

According to Microsoft's documentation, several Sentinel features, including case management and workbooks, work in the Defender portal without any setup, as does a feature that writes automation playbooks from plain-language instructions. User and entity behavior analytics and the ability to bring in data from Azure and third-party sources require extra setup, including creating a dedicated ISOC workspace linked to an Azure subscription. Microsoft says more than 500 connectors are available for outside sources and warns that ingestion charges may apply.

The ISOC public preview opens to customers with Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 licenses; organizations already running an active Microsoft Sentinel workspace are excluded for now. Defender data is kept for 30 days at no extra charge during the preview, and Microsoft has not disclosed pricing. A Tech Community ask-me-anything session on the service is scheduled for Oct. 6. The service builds on Project Perception, introduced in July, and MAI-Cyber-1-Flash, Microsoft's first security model developed in-house. Project Perception agents still need human approval for high-stakes actions, an approach Lefferts summed up as "strategy stays human."

Oracle executives, speaking with theCUBE during Oracle's "AI Cyberattacks Are Escalating: How to Secure Your Data Now" event, said database security controls are moving inside the database itself as AI agents gain broader access to sensitive enterprise data. theCUBE is SiliconANGLE Media's livestreaming studio and a paid media partner for the event.

Juan Loaiza, executive vice president of Oracle Database Technologies, said AI is "literally superhuman" at finding security vulnerabilities and at "how fast it does it and how many it does." He said Oracle is using multiple models to examine its own code while urging customers to keep database environments current, adding that after decades of work by security teams the models were still finding hundreds of security issues.

Loaiza said Oracle Deep Data Security enforces authorization at the row, column and cell level based on user identity and runtime context, so an agent can only see a single user's data even if an application is compromised or a prompt is manipulated. The trust layer, he said, has to move "as low as possible." Vipin Samar, senior vice president of Database Security at Oracle, said at the same event that the company cannot depend on agents to enforce their own security, and that access should be limited to what the user is authorized to get no matter which agent or swarm of agents a request arrives through.

A demonstration showed an indirect prompt bypassing application guardrails and exposing salary data; once access restrictions were enforced inside the database, the same prompt could no longer retrieve the protected information. David Knox, vice president of Database Security product management at Oracle, said he wants a design that is consistent and constant regardless of why something bad happened, with a provable way to guard the data. Samar and Knox described tools for managing database fleets. Oracle Data Safe provides cloud-based security assessment and monitoring, while Oracle Database Security Central gives customers a unified view of users, sensitive data, configurations and policies. Knox said Oracle intercepts a query as it executes and runs it through all of the security capabilities. Oracle's Zero Data Loss Recovery Appliance protects database transactions in real time, validates backup integrity and supports rapid restoration, and Loaiza said organizations have to be prepared for what happens the minute after they learn they have been breached.

At theCUBE Research's AI ROI in Contact Center Summit, executives from Cisco Systems, Five9, Zoom Communications, Talkdesk and Converged Technology Professionals argued that the customer service industry should abandon containment and deflection as primary measures. Vinod Muthukrishnan, vice president and general manager of Webex Customer Experience at Cisco, said an AI agent that can fill a slot or complete a transaction is not agentic, describing agentic instead as "much more of a framework of tools, products and processes." Pedro Andrade, vice president of AI at Talkdesk, described what the company calls customer experience automation as an operating model shift that coordinates a hybrid workforce of AI and human employees, not a tool purchase. According to Talkdesk research, roughly 74% of enterprises already have generative AI in place.

Talkdesk segmented its survey base by maturity, and organizations it calls CXA leaders reported roughly 22% net promoter score gains against 5% for the tier below. Cost per contact improved 57% versus 48%. Andrade said savings alone understate the value of AI and that the metric that must change is the time from opening a problem until it is closed, back office included. Ram Rajagopalan, head of product for AI at Zoom CX, said Zoom pairs a post-call survey with what it calls implied resolution, using a large language model to grade the outcome, and does not count frustrated customers who drop off as resolved. Joe Rittenhouse, co-CEO of Converged Technology Professionals, said customers are often surprised by costs and that metered, conversational and outcome-based pricing are not interchangeable.