Cybersecurity

NetSafe MDR Stops Identity Attacks in Seconds

Post by
Net Friends Icon
Susanna Perrett

Cybersecurity has always been a game of speed. What changed this year is that both sides got the same upgrade. Attackers are using AI to move faster than ever, and now NetSafe® MDR is using AI right back. With one major difference, with NetSafe MDR, humans are still involved.

Attackers got an AI upgrade  

Reconnaissance that used to mean hours of manually scraping LinkedIn, Twitter, and public records can now happen with a single prompt, giving attackers detailed target profiles almost instantly. Social engineering has leveled up too. Voice cloning tools need only a few seconds of audio to produce a convincing fake, and video deepfakes are now good enough that "just call them back to verify" is no longer solid advice on its own.

Even the follow through has gone hands free. AI agents can now handle lateral movement on their own, spotting a file server by its process count and data volume and moving toward it without a human giving step-by-step direction. Net Friends' SOC has described this as a shift from breaking the door down to simply walking in with a key. Noisy exploits and detectable malware are being replaced by valid credentials and trusted tools, which makes an attacker look a lot like your own IT admin. It's a sobering reminder that in 2026, trust itself has become something attackers actively try to earn and exploit rather than break.

Perhaps the most eye-opening example is how low the bar has dropped. We have seen convincing phishing campaigns that are built using an AI chat assistant in about five minutes. That is not a hypothetical risk. That is Tuesday afternoon for a motivated attacker.

Identity is the new front line

The data tells a clear story. Common identity attack methods sail right past multi-factor authentication (MFA) by reusing session tokens that already passed authentication once.  

Here is the part that should keep security teams up at night. A stolen session token can be weaponized in minutes, sometimes less. By the time a human analyst opens the alert, reads the context, and decides what to do, the attacker may already be inside, setting up shop and covering their tracks. Speed isn't a “nice to have” anymore. It's the whole game.

Once an attacker is inside, the playbook is consistent. Rogue app registrations, inbox rules that hide their tracks, quiet pivots from cloud to on-premises systems, and using the compromised account to phish the next victim. And the prize is no longer just a password. Today's info stealing malware goes after crypto wallets, API tokens for AI models, and cloud access keys, which massively widens the damage a single stolen credential can do.

An AI Teammate

This is the landscape NetSafe® MDR was built for. The AI agent watches over Microsoft 365 and Google Workspace accounts and can shut down a high confidence credential attack in under two minutes on average.

That speed only matters because attacks move at machine pace, not human pace. A human analyst doing everything right might still take 20 or 30 minutes to confirm a threat and lock it down. NetSafe MDR closes that gap by acting the moment it's confident, no waiting on a coffee break or a shift change. Taking the human out of that first critical loop is not about cutting corners, it is about matching the attacker's own timeline.

Cybersecurity Attacks Comparison AI vs Human Only Analyst

What makes the agent trustworthy is what it was built on. It was trained using years of real decisions made by Net Friends' own SOC analysts, forensic evidence pulled from hundreds of actual breaches, and telemetry gathered from close to a million protected accounts. It only acts on its own when confidence is high, and everything else still gets a human set of eyes.

The Human Touch Remains

This is really the heart of the story. Net Friends' SOC is staffed by seasoned security operators, and it is their judgment that shaped where the AI is allowed to act alone and where it has to check in first. As one Net Friends security leader puts it, the AI acts faster, but human judgment secures the outcome and always will.

Lower confidence threats still get escalated to an analyst for a real investigation, and the broader threat hunting work, digging into new attacker tradecraft and publishing research, remains entirely human-led.

In other words, the AI took over the sprinting, while the humans kept the thinking. That is a pretty good division of labor, and honestly, it takes a load off everyone's shoulders.

AI Handles Humans Handle
High-confidence threat detection Lower-confidence threat investigation
Automated account lockdown in under 2 minutes Escalated alert review and analysis
Session token revocation Broader threat hunting and research
Real-time monitoring across M365 and Google Workspace Publishing new attacker tradecraft findings
Acting at machine pace Shaping where AI is and isn't allowed to act

The AI took over the sprinting. The humans kept the thinking.

Looking Ahead

If the last year proved anything, it is that when attacks happen in minutes, defense must happen in seconds. AI on the attacker's side calls for AI on the defender's side too.

But the most reassuring part of NetSafe MDR is not the automation itself. It's that behind every split-second decision. There is still a person who helped teach the system what trustworthy looks like.

Speed catches the moment. Judgment is what keeps you safe the next time too.

If you do not have NetSafe MDR, set up a meeting with one of our IT experts. We would love to help you secure your data.

Follow us on LinkedIn

More Reading

NetSafe® MDR Protects Your Business Systems
How Training Impacts Identity Theft

Top 5 Cybersecurity Steps

Take IT Off Your To-Do List.

Tech holding you back? Losing productivity to downtime?
Discover how we can simplify your tech and free up your time, contact us today.

Start a Conversation

At Net Friends, we believe in the power of human expertise. While we leverage AI to enhance our content and processes, all blog posts are written and edited by our knowledgeable staff. You can trust you are getting insights directly from our team.