Summary
In this chapter, we explored the state of cybersecurity. As someone who is deploying, operating, and responding to incidents with Microsoft 365 Defender, it’s important to know what threats exist and the frameworks the industry uses to manage them. The question of Microsoft’s commitment to security was also answered, with an overview of the Zero Trust approach that the business advocates. You learned about the cyber kill chain, its various stages, and its relationship to the MITRE ATT&CK framework. Additionally, you will now be able to articulate what Zero Trust is as one of Microsoft’s core security philosophies.
In the next chapter, we’ll take these learnings about the state of play in cybersecurity and discuss how they apply to Microsoft 365 Defender itself. An extended detection and response (XDR) platform, Microsoft 365 Defender is a relatively new breed of protection service. You’ll find out what its capabilities are, with examples of how it can be used throughout the cyber kill chain, across your environment.