Unisys Adds Security Copilot Workflows to Its Managed Detection ServiceEditorial image generated for IT Automation Week.

Unisys has integrated Microsoft Security Copilot capabilities into its Managed Detection and Response service, a change the company says is intended to automate selected security-operations tasks and give analysts more unified visibility during an investigation.

The enhanced managed service combines Microsoft security technologies with Unisys’ security-operations expertise. Unisys said Security Copilot will work alongside Microsoft Defender and Microsoft Sentinel, bringing information from endpoints, identities, cloud workloads and networks into a more centralized operational workflow.

The practical change is the addition of AI-powered agents to routine steps such as phishing triage, threat-intelligence analysis, and parts of incident investigation and response. Unisys also said the service can evaluate and suppress low-risk incidents when defined confidence thresholds are met, while retaining an audit trail of those actions.

For security teams, that design addresses a familiar operations problem: analysts often move among detection tools, case records and threat-intelligence sources before deciding whether an alert needs attention. Bringing those steps into a managed workflow could reduce some context switching, but the release does not specify how many alerts can be handled automatically or what thresholds customers should use.

Unisys is positioning the service as a structured way for organizations to operationalize Security Copilot rather than simply turn on a generative-AI feature. The company said the approach includes adoption, governance and integration work, reflecting the fact that automation in a security operations center requires decisions about data access, escalation paths and human oversight.

The announcement also distinguishes between automation and fully autonomous response. The release describes agents automating routine work and low-risk incident handling under confidence thresholds; it does not say that customers can hand all containment decisions to an agent. That boundary matters where a false positive could interrupt a business service or alter a production environment.

Before deployment, a customer can map the operating model around the service. That includes the systems to connect, who owns alert tuning, how analysts validate an AI-produced summary, and which outcomes are recorded in the incident case. Those choices affect whether automation reduces workload or simply moves it to a later review step. The release describes the capabilities, but it does not provide comparative response-time or alert-volume measurements.

Organizations considering the service will still need to determine which data sources are available to Defender, Sentinel and Security Copilot, how alerts are prioritized, and when an analyst must approve action. They will also need to align the managed workflow with existing incident-response procedures and evidence-retention requirements.

For IT security leaders, the notable development is not a new standalone Copilot interface. It is the attempt to place Microsoft’s AI capabilities inside a managed detection and response process, where triage, enrichment and response are already tied to operational accountability. Unisys said the service is delivered through its global security operations center.

Before deployment, a customer can map the operating model around the service. That includes the systems to connect, who owns alert tuning, how analysts validate an AI-produced summary, and which outcomes are recorded in the incident case. Those choices affect whether automation reduces workload or simply moves it to a later review step. The release describes the capabilities, but it does not provide comparative response-time or alert-volume measurements.

Security leaders should also test the role boundaries around automated suppression and escalation. A complete audit trail can help with review after an event, but it does not substitute for clear rules on which alerts may be closed automatically and which must remain visible to an analyst. The integration therefore gives teams another workflow option, while the customer remains responsible for governing its operational use.

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest News