
More Security Lessons Learned Using Copilot w/ Bronwen Aker
Source: YouTube · Black Hills Information Security · published Aug 22, 2025 · 57:50
[BLUF] Securing Microsoft Copilot requires aligning licensing tiers with security needs, as enterprise access amplifies insider threats, making strict Role-Based Access Control (RBAC) and metadata management critical 0:50.
Key Takeaways:
• Copilot tiers dictate risk levels; enterprise licenses grant deep data access (email, Teams), significantly increasing insider threat potential compared to free tiers 0:50.
• Copilot amplifies existing access rather than creating new vulnerabilities; strong RBAC is the primary defense against data leaks and metadata exposure 2:15.
• Organizations must monitor Copilot Studio and Security Copilot usage, as low-code tools can introduce risks if not managed by skilled personnel 3:40.
• Continuous monitoring, logging, and DLP policies are essential because AI features evolve rapidly, often outpacing static security configurations 4:30.
[Closing statement]
Organizations must prioritize fundamental security controls like RBAC and DLP over relying on AI's built-in safeguards. Proactive monitoring and intentional AI adoption are essential to mitigate the rapid evolution of Copilot-related risks.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello. Uh, usually I'm I guess normally we have an introduction, but I'm introducing myself. Hi, welcome to my uh webcast. My name is Bronwinaker and this is more cyber security lessons learned about securing co-pilot in your organization. So, if you didn't attend the webcast that I did in May, we're going to do a bit of review of what was covered in that webcast, but also touch on recent updates to what has happened in specifically the co-pilot space and in the AI space in general a bit as well because it is a rapidly evolving field. It is just nuts how quickly things are changing. We're going to talk about the different co-pilot tiers, pricing, and features. Believe me, it is germanine. It has to do a lot. It will impact the security issues tremendously. We're also going to talk about se…