Microsoft Security Bootcamp: An April Fools’ Day event that was definitely no joke

Microsoft Security Bootcamp: An April Fools’ Day event that was definitely no joke

On April 1, Microsoft organized a series of lectures for IT professionals focused on information security. The Microsoft Security Bootcamp covered the latest developments in security, security risks, compliance, and tools used for data management and protection.

Legislative Updates and Compliance Manager

The lecture series was opened by Dalibor Kačmář, Director of Technology and Security at Microsoft. He focused on current legislative requirements in the field of cybersecurity, as well as on typical practical shortcomings that organizations face when implementing the new Cybersecurity Act (NZoKB). He also presented solutions that help organizations on their path to compliance. One of these is the Microsoft Compliance Manager tool, which assists with the implementation and adherence to standards and guidelines through automation and pre-built templates.

Zero Trust and Microsoft Purview Data Loss Prevention

The discussion on legislative updates was followed by a presentation on the Zero Trust security concept and the Microsoft Purview Data Loss Prevention (DLP) tool. As the name suggests, the Zero Trust concept is based on the principle of zero trust, where no access is automatically considered trustworthy and must be verified. This distinguishes it from traditional security approaches, which often assumed that traffic within the network is secure. The second part of the presentation focused on the Microsoft Purview DLP tool, which helps organizations protect sensitive data and prevent data leaks.

Jurassic Park as a Metaphor for Data Security

This was followed by a presentation that offered an apt metaphor comparing Jurassic Park to data protection. It highlighted the false assumption of security that we often operate under. We rely on the fact that our perimeter is secure, but spoiler alert: it isn’t!

The topic of risks associated with internal threats was also addressed. A typical internal threat scenario mentioned was departing employees, who sometimes tend to take materials with them, such as templates or pieces of code, that “might come in handy in the future.” Another modern threat is AI agents, which can have access to large amounts of information and, if permissions are misconfigured, unknowingly cause data leaks. Microsoft addresses these issues primarily through the Microsoft Purview platform, which offers tools for internal risk management and data governance.

Security Copilot: The Future of Security AI

The final presentation focused on Microsoft Security Copilot – an AI tool that assists in a wide range of security areas. It can streamline work related to phishing detection, attack analysis, and other scenarios. Its capabilities can be expanded using agents not only from Microsoft but also from third parties. Although the tool is still under development, it already shows enormous potential for the future of cybersecurity. Currently, it is possible to try the tool under an E5 license.

Microsoft Security Bootcamp provided not only an overview of technological innovations but also a forum for discussing current security topics. Participants had the opportunity to share their experiences and gain inspiration on how to protect data more effectively and implement current legislative requirements.