Icertis cuts SOC incidents by 50% with Defender for Cloud | Microsoft Customer Stories
Security teams managing complex cloud environments often face alert fatigue and limited visibility. This customer story from Icertis shows how Microsoft Defender for Cloud helped reduce SOC incidents by 50 percent while strengthening cloud security operations. Read the story to see how unified protection can improve threat detection and response.
How did Icertis improve SOC efficiency with Microsoft security tools?
Icertis used Microsoft’s unified security stack to
reshape how its SOC operates, especially as it scaled generative AI workloads.
Here’s what changed:
- Defender for Cloud as the CNAPP foundation: Icertis adopted Microsoft Defender for Cloud as its cloud-native application protection platform across more than 300 Azure subscriptions. This gave the team AI posture visibility, attack path analysis, and policy enforcement for Azure OpenAI–based workloads.
- Security Copilot agents for investigations: Custom Security Copilot agents summarize high-priority alerts and correlate signals across Microsoft security and compliance tools. This reduced manual triage time from 60 minutes to 15 minutes per alert—a 75% reduction.
- Incident and response improvements:
- SOC incident volume dropped by 50%.
- Mean time to resolution improved from 40 minutes to 25 minutes.
- Alert triage time was cut by up to 80%.
- Practical impact: In a phishing case, Security Copilot helped the team quickly identify a malicious domain, revoke sessions, enforce multifactor authentication, and reset passwords within minutes.
By combining Defender for Cloud, Security Copilot, Microsoft Sentinel, and other tools, Icertis scaled its regulated business without adding headcount, while freeing engineers from manual alert review to focus on higher-value security work.
How does Icertis secure generative AI and sensitive contract data?
Icertis works with contracts that contain
highly sensitive business rules and arrangements, and many of its customers operate in regulated industries. To secure this environment while using generative AI, Icertis has reimagined its security and compliance approach around Microsoft technologies.
Key elements include:
- Defender for Cloud for AI workloads:
- Monitors Azure OpenAI deployments used in Icertis’s Foundry Models and Vera AI suite.
- Detects malicious prompts (e.g., prompt injection, jailbreak attempts).
- Enforces security policies as a first line of defense for AI-related threats.
- Built-in compliance frameworks: Defender for Cloud uses regulatory templates such as ISO 27001, SOC 2, and NIST 800-53 to help maintain continuous compliance across all Azure subscriptions, while Azure policies block public endpoints and correct policy drift.
- Data governance with Microsoft Purview:
- Automatically classifies and encrypts files across regions and environments.
- Enforces conditional access and blocks unauthorized activity from unmanaged devices.
- Threat detection with Microsoft Sentinel: Correlates insights from Defender for Cloud Apps and other sources to provide a unified view of threats across SaaS and generative AI applications, resulting in higher-fidelity alerts and more actionable response.
- Identity and access with Microsoft Entra:
- Implements a daily Zero Trust model—no default access.
- Roles must be explicitly requested, justified, and approved before production access is granted.
- Risk-based identity monitoring flags anomalies such as impossible travel or token misuse and triggers automated remediation.
Together, these controls help Icertis protect generative AI applications built on Azure OpenAI, safeguard contract data, and support frequent audits without slowing innovation.
How is Icertis governing AI and embedding security into its products?
Icertis is using AI at the core of its contract intelligence platform and has reshaped its governance and engineering practices so security is built in, not bolted on.
Here’s how:
- Secure by Design product lifecycle:
- Early threat modeling, risk assessments, and architectural reviews for new features.
- Security and quality treated as core product features, supporting long-term resilience and customer trust.
- Governance of generative AI and SaaS apps:
- Defender for Cloud Apps discovers, classifies, and controls web and GenAI apps.
- Assigns security scores and blocks low-scoring apps to reduce shadow IT risk.
- Integrates with Microsoft Sentinel and Defender Threat Intelligence for stronger detection and response.
- Combined with Microsoft Purview and Entra, it gives more granular control over data movement and user behavior.
- AI policy and employee enablement:
- An internal Icertis AI Policy grounded in the company’s FORTE values guides how AI is designed and deployed.
- Training and AI literacy programs help employees use generative AI tools more securely.
- Secure development and CI/CD integration:
- Developers integrate Microsoft Defender for Containers into CI/CD workflows.
- Python-based container images are scanned for vulnerabilities before deployment, reducing the risk of run-time exploits.
- Forward-looking initiatives: Icertis plans to extend Defender for Cloud capabilities across its Vera AI suite and is exploring malware scanning as a service to detect threats in uploaded documents before they reach production.
By combining technical controls, governance policies, and training, Icertis is rethinking how secure AI innovation is delivered in the contract intelligence space, with a focus on digital trust and practical risk reduction.
.jpg)
Icertis cuts SOC incidents by 50% with Defender for Cloud | Microsoft Customer Stories
published by Strong Connexions
Strong Connexions is a technology company located in Salt Lake City, Utah. We offer a suite of solutions including Managed IT, Phone and Voice, Door Access solutions, Security Cameras, Structured Cabling services, Cyber Forensics, Government Compliance support, and Education & Training programs. All our services are designed to meet your unique technological needs, boost operational efficiency and maximize security. With our expert offerings, we aim to elevate your business infrastructure, ensuring compliance, enhancing connectivity, and empowering your business operation resilience in a constantly evolving digital landscape.