Tech News

New chief security officer Hayete Gallot on company’s push into agent era – GeekWire

Hayete Gallot, now senior vice president of Microsoft Security, speaks at Microsoft’s event in France in 2024. (Microsoft Image)

GeekWire is profiling over the next few weeks some of the people and teams shaping Microsoft’s transition into what we call its “Microsoft 2.5” era.

AI has impacted almost every technology product category, but especially security. Attackers use AI; customers looking to protect with AI. The goals keep changing. “Agenttic security” is now a holy grail, and Hayete Gallot, vice president of Microsoft Security, is leading the way.

Gallot, a 16-plus-year Microsoft veteran who joined the company in February after a 1.5-year stint at Google, replaces Charlie Bell, who came to Microsoft from AWS in 2021 and continues at the company as an individual focused on engineering quality.

“Customers care about two things: solving security and affordability,” Gallot said when I asked during our interview this week why he returned to Microsoft.

“I’m a problem solver. I’m also an engineer at heart (and by training). Security is the most important issue right now – and Microsoft is the only place that has all the pieces of the puzzle to help our customers.”

Since his return, Gallot has never been shy about shaking things up. As recently noted by Informationat least nine corporate vice presidents who previously reported to Bell have left the company this year.

“We are making changes to ensure that we are in the best possible position to pursue this opportunity,” he admitted.

“I’m motivated to do the right thing for our customers, my teams, and technical results. I like to move fast; days and weeks, not months and years, I learn by doing, iterate quickly, and adjust based on real customer signals.”

A company does not start at the beginning. As of 2021, Microsoft said security was the company’s $10 billion business. By 2023, the security would have reached an annual revenue of $20 billion, officials said.

Those claims were not without controversy. Microsoft has built a large business on finding and fixing security problems that some customers felt were of the company’s design.

Microsoft has an extensive and unregulated security portfolio, including identity management (Entra), endpoint protection (Defender), endpoint management (Intune), security information and event management (Sentinel), and compliance (Purview), among others.

In 2023, Microsoft launched its Security Copilot suite of AI analytics services integrated with its other existing security offerings. But a portal-based solution like Security Copilot doesn’t offer the kind of end-to-end coverage that an agent’s security platform can provide, Gallot said.

The problem is that attackers use agents, too. Customers need real-time insight into what’s happening in their environment, and the ability to act quickly, Gallot said.

Agent security is about “taking signals and turning them into a useful graph,” Gallot said. “If you try to reason with 100 billion signals, it doesn’t really work.” He said the graph allows agents to choose the correct model for each threat and close the loop.

In practice, that means the system can lock the device or revoke its access on its own, for example, rather than waiting for someone.

Microsoft’s existing security products will continue to play a role as the landscape changes, we identify issues and act on them. The Security Copilot is not out of the process: “You’ll have a Copilot and you’ll have company security,” he said.

The company’s new Agent 365 “control plane” — a central console for tracking every AI agent the company runs — comes in by allowing customers to see an agent’s “explosion zone,” meaning everything a hacked agent can access, Gallot said. It’s similar in concept to Zero Trust, the “never trust, always verify” security model that limits how far an attacker can get with a compromised employee login, but applied now to agents rather than people.

So what exactly is this ‘agent security’ thing? Microsoft has an entire website dedicated to the topic.

Traditional AI security and agent AI security are very different, says Microsoft. Agent security doesn’t just protect models and training data; and can protect tools, workflows, memory, connected systems and more. Because agents can take action, the potential for good and bad is high.

While AI has helped businesses make strides in detecting and remediating vulnerabilities, it hasn’t moved much beyond that. Microsoft introduced the multi-model agetic scanning harness (MDASH) as its first step into the agent security space, Gallot said.

The company has used MDASH internally to improve the availability and repair of Windows security issues, and is now making it available to select customers in extended preview. MDASH will allow customers to use a best-of-breed model to protect all different types of codes, he said.

Microsoft is rumored to be studying a comprehensive agent security offering, of which MDASH is likely just one piece.

Microsoft is far from the only one doing this. AWS, Anthropic, and OpenAI provide security tools on their platforms, and dedicated security vendors are building their own agent platforms.

Microsoft has an advantage of scale in business. The question is whether Gallot and his new leadership team can turn that scale and nascent AI tools into a bigger business for the company and better protection for its customers.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button