Nearly 200 hours a month, recovered from phishing triage. When St. Luke's University Health Network needed real-time visibility across a fragmented security stack, it adopted Security Copilot in Microsoft Defender as the connective tissue linking alerts, access controls, and vulnerabilities. Agentic capabilities now speed threat response and turn incident reporting from hours into minutes. As a Microsoft Security solutions provider, Análise IT can help you apply this approach. Read the story to learn from St. Luke's experience.
How did St. Luke’s use AI to cut security workload by nearly 200 hours a month?
St. Luke’s University Health Network uses Microsoft Security Copilot as an AI layer across its existing security stack (Microsoft Defender, Sentinel, Entra, Purview, Intune). The biggest time savings come from the Phishing Triage Agent in Microsoft Defender.
Before Security Copilot, analysts spent hours each day manually reviewing user-reported suspicious emails and working across multiple portals. Now:
- The Phishing Triage Agent autonomously analyzes and classifies reported emails using language model–based analysis.
- It understands the content and intent of each email and decides whether it’s likely phishing or a false positive.
- It automatically closes thousands of false positive alerts, and provides plain-language explanations for its decisions.
According to St. Luke’s, this single agent is saving nearly 200 hours every month that were previously spent on manual phishing alert triage. That time is now redirected to higher-value work, such as proactive threat hunting and deeper investigations.
In addition, Security Copilot helps the team:
- Create incident reports in minutes instead of hours.
- See all relevant incident data in one place, rather than switching between multiple dashboards.
Together, these changes reduce repetitive work, improve analyst satisfaction, and free the team to focus on real threats instead of routine noise.
What security challenges was St. Luke’s trying to solve with Security Copilot?
St. Luke’s University Health Network operates 15 campuses, 300 outpatient sites, and manages more than 2.5 petabytes of data and patient records in motion. As a healthcare provider, it is in what its CISO calls the number one cyberattack target sector globally.
The team identified several key challenges:
- Fragmented tools and limited visibility – They already used Microsoft Defender, Sentinel, Entra, Purview, and other tools, but these were largely disconnected. Analysts had to jump between portals and tabs to understand what was happening.
- High phishing volume – Phishing was the primary attack vector, followed by DDoS. Analysts were inundated with user-reported suspicious emails, many of which turned out to be false positives.
- Manual, time-consuming triage – Before Security Copilot, it took hours to triage and understand hundreds of alerts per day, slowing response and increasing the risk of missing real threats.
- Difficulty spotting hidden weaknesses – With millions of daily signals, it was hard to pinpoint gaps in coverage or areas where threats might go unnoticed.
Security Copilot helped St. Luke’s address these issues by:
- Acting as an AI-powered connective layer across their security stack, consolidating alerts, access controls, and vulnerabilities into a single, unified view.
- Enabling analysts to correlate threats across endpoints, email, identity, applications, and cloud workloads in real time.
- Using agents such as the Phishing Triage Agent, Conditional Access Optimization Agent, and Vulnerability Remediation Agent to automate routine triage and remediation tasks.
- Embedding AI-driven guidance and recommendations directly into existing workflows, so analysts can make faster, data-driven decisions.
As a result, St. Luke’s moved from reactive, manual triage to a more proactive, AI-first security posture, with better visibility into both active threats and underlying weaknesses in their environment.
How does Security Copilot change day-to-day work for St. Luke’s security team?
Security Copilot has reshaped daily work in St. Luke’s Security Operations Center (SOC) by embedding AI into the flow of existing tools and processes.
Key day-to-day changes include:
- Faster triage in one place – Instead of digging through multiple portals and tabs, analysts now see correlated alerts and context in a single view. Triage that used to take hours now takes minutes.
- Automated phishing handling – The Phishing Triage Agent runs 24/7, autonomously handling and closing thousands of false positives each month and saving nearly 200 hours monthly. Analysts focus on the smaller set of alerts that truly matter.
- Clear, AI-generated explanations – For each email or alert, the agent provides plain-text reasoning for its classification, which helps analysts quickly validate decisions and build trust in the system.
- Rapid incident reporting – For a workforce of more than 23,000 employees and millions of patient records, compliance reporting is critical. Incident reports that once took hours to compile can now be generated in minutes within Defender, then refined and escalated as needed.
- Better understanding of security gaps – Security Copilot helps leaders identify where visibility is lacking and where gaps exist, informing security roadmaps and investment decisions.
Beyond efficiency, St. Luke’s reports:
- Reduced analyst burnout, because repetitive, low-value tasks are automated.
- Improved collaboration, since all incident information is centralized and easier to share.
- A sense that Security Copilot functions like an extra team member or mentor, guiding analysts toward more effective responses and a more mature security posture.
Overall, Security Copilot helps St. Luke’s reimagine its security operations as an AI-first, end-to-end system that unifies tools, improves resilience, and supports clinicians’ ability to deliver uninterrupted care.