Icertis supports customers in regulated industries and needed to scale security without adding headcount. This customer story shows how the contract intelligence company deployed Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Purview, and Microsoft Entra to protect generative AI applications and enforce compliance, cutting alert triage time by 80%. Read the story to learn from Icertis's experience.
How did Icertis improve SOC efficiency and reduce security incidents?
Icertis reshaped its SOC by standardizing on the Microsoft security stack, with
Microsoft Defender for Cloud and
Security Copilot at the center.
Key outcomes:
- 50% drop in SOC incident volume
- Mean time to resolution reduced from 40 to 25 minutes
- Alert triage time cut by up to 80% (from about 60 minutes to 15 minutes for high-priority alerts)
How they achieved this:
- Used Defender for Cloud as a cloud-native application protection platform (CNAPP) to monitor workloads, including Azure OpenAI deployments, detect malicious prompts, and enforce security policies.
- Introduced Security Copilot agents to summarize and correlate alerts across Microsoft security and compliance tools, giving analysts a unified timeline and recommended actions.
- Automated common response steps (for example, in a phishing case: identifying malicious domains, revoking sessions, enforcing MFA, and resetting passwords within minutes).
- Enabled developers to generate KQL queries from natural language, speeding up onboarding and helping engineers investigate threats independently.
Together, these changes allowed Icertis to scale security operations without adding headcount, while maintaining a stronger security posture across its environment.
How does Icertis secure sensitive contract data and generative AI workloads?
Icertis treats security as a core feature of its contract intelligence platform, especially as it expands generative AI capabilities like its
Vera suite and Copilot agents.
To protect sensitive contract data and AI workloads, Icertis uses an integrated set of Microsoft solutions:
- Microsoft Defender for Cloud to:
- Monitor Azure OpenAI deployments.
- Detect malicious prompts and AI-specific threats such as prompt injection and jailbreak attempts.
- Provide AI posture visibility, attack paths, and risk reduction recommendations.
- Apply built-in regulatory frameworks like ISO 27001, SOC 2, and NIST 800-53 across more than 300 Azure subscriptions.
- Use Azure policies to block public endpoints and correct policy drift, with multicloud connectors extending visibility into AWS.
- Microsoft Purview to:
- Automatically classify and encrypt files across regions and environments.
- Enforce conditional access and block unauthorized activity from unmanaged devices.
- Microsoft Sentinel to:
- Correlate insights from Defender for Cloud Apps and other sources.
- Provide a unified view of threats across SaaS and generative AI ecosystems.
- Generate high-fidelity alerts and actionable insights for faster response.
- Microsoft Entra to:
- Implement a daily Zero Trust model—no default access; roles must be explicitly requested, justified, and approved.
- Use risk-based identity monitoring to flag anomalies such as impossible travel or token misuse and trigger automated remediation.
- Defender for Cloud Apps to:
- Discover, classify, and control web and GenAI apps, including shadow IT.
- Assign security scores and block low-scoring apps.
- Integrate with Sentinel and Defender Threat Intelligence for stronger detection and response.
These tools are backed by Secure by Design practices—early threat modeling, risk assessments, architectural reviews, and an internal AI policy and training program—so that security is embedded into every layer of Icertis’s AI-driven contract intelligence platform.
How does Icertis maintain compliance and support audits at scale?
Icertis needed to keep pace with rapid AI experimentation and cloud deployments while staying compliant across a large, complex environment. The company addressed this by standardizing on Microsoft’s unified security and compliance stack and automating as much as possible.
Key elements of their approach:
- Defender for Cloud as the compliance backbone:
- Applies built-in regulatory frameworks such as ISO 27001, SOC 2, and NIST 800-53 across 300+ Azure subscriptions.
- Uses Azure policies to block public endpoints and correct configuration drift automatically.
- Extends visibility to AWS via multicloud connectors, so compliance posture is consistent across clouds.
- Microsoft Purview for data governance:
- Automatically classifies and encrypts sensitive contract data.
- Enforces conditional access and prevents unauthorized activity from unmanaged devices.
- Microsoft Entra for access governance:
- Implements strict role-based access with no default permissions.
- Requires explicit requests, justification, and approval before roles are provisioned in production.
- Uses risk-based identity monitoring to detect anomalies and trigger automated remediation.
- Defender for Cloud Apps for SaaS and GenAI governance:
- Discovers and scores web and GenAI apps, blocking low-scoring or unsanctioned tools.
- Helps evaluate shadow IT GenAI apps and decide whether to sanction their use.
This combination of automated controls, unified visibility, and Zero Trust access helps Icertis pass audits, maintain continuous compliance, and still move quickly with new AI-powered capabilities in its Vera suite and broader contract intelligence platform.