Microsoft has stepped up its pitch to security teams with a new artificial intelligence model built specifically for cyber defence, and the message it is leading with is price. According to International Business Times Australia, the company is positioning the system as a way to match, and in places beat, rival offerings from Anthropic and Google while charging roughly half as much to run it. In a market where the cost of running large models has become a board-level worry, that framing is deliberate.
The context matters. Over the past two years the big cloud and AI vendors have raced to bolt generative models onto security tooling, promising analysts a co-pilot that can triage alerts, summarise incidents, hunt for threats and draft response plans in plain language. Microsoft has been among the most aggressive, folding its Security Copilot into the wider Defender and Sentinel stack that millions of organisations already pay for. Anthropic and Google, through Claude and Gemini respectively, have pushed hard into the same territory, pitching their frontier models as capable reasoning engines for stretched security operations centres. What has held many buyers back is not appetite but arithmetic: running a top-tier model across a torrent of security telemetry, day and night, gets expensive quickly.
The news
That is the gap Microsoft is now trying to exploit. Rather than simply reselling access to the largest, most general model it can build, the company is offering a system tuned for the narrower job of cyber defence, and arguing that a purpose-built approach delivers comparable results without the frontier price tag. The claim, as reported, is twofold: competitive performance against Anthropic and Google on security tasks, and a running cost said to be around half that of the alternatives. If both halves hold up under independent testing, it would reset the value calculation for a lot of organisations that have trialled AI-assisted security but baulked at scaling it.
It is worth being clear about what has and has not been demonstrated. Vendor benchmarks are notoriously self-serving, and “half the cost” can mean very different things depending on how you count tokens, infrastructure, licensing and the human time saved or added. Microsoft’s own security leadership, headed by Charlie Bell, has spent heavily to make the company a serious security business rather than an operating-system vendor that happens to ship antivirus. A cheaper, defence-specific model fits that strategy neatly, because it gives Microsoft another reason for customers to consolidate their security spending inside its ecosystem instead of buying point products from a dozen suppliers.
Two ways to read it
Supporters of the move argue that lower running costs are exactly what the defensive side of the industry needs. Attackers are already using automation and generative tools to scale phishing, reconnaissance and malware development, and the economics currently favour them because it is cheap to attack and expensive to defend. Anything that lets a mid-sized bank or a state government agency run capable AI across its whole environment, rather than rationing it to the crown-jewel systems, arguably tips the balance back toward the defenders. On this reading, a price war between Microsoft, Anthropic and Google is good news for buyers, because competition drives down the cost of protection.
The sceptical view is harder to dismiss. Consolidating detection, response and now the reasoning layer inside a single vendor deepens the kind of dependency that security professionals are usually paid to avoid. If the model that defends your network, the cloud it runs on and the identity system it protects all carry the same logo, a serious flaw or outage in that stack becomes a single point of failure. There is also the question of trust in the numbers. Independent analysts will want to see how the model performs on real incidents rather than curated tests, how often it produces confident but wrong conclusions, and whether the advertised savings survive contact with production workloads. Cheaper is only better if the model is genuinely good enough to be relied on, and that bar is high when the cost of a missed intrusion runs into the millions.
What it means for Australia
For Australian organisations the stakes are practical rather than abstract. Microsoft is deeply embedded across the local economy, from the major banks and the big miners to universities, hospitals and large slices of federal and state government that run on Microsoft 365, Azure and Defender. A cheaper security model that plugs into tooling those bodies already own could accelerate AI adoption in security operations centres that have so far moved cautiously. The Australian Signals Directorate and its Cyber Security Centre continue to log a cyber incident roughly every six minutes, and the recurring lessons from breaches at Optus, Medibank and Latitude have kept boards focused on how quickly a threat can be spotted and contained. Tools that let smaller teams do more, faster, land in fertile ground here.
There is a sovereignty angle too. Canberra has been sharpening its language about the risks of relying on foreign models and foreign infrastructure for critical functions, and cyber defence is about as critical as it gets. A defence-specific model from a hyperscaler will prompt exactly the questions Australian policymakers and chief information security officers have been raising elsewhere: where does the data sit, who can see it, and what happens to national resilience if the whole sector standardises on one American provider. The cost savings are attractive, but for regulated industries and government the harder conversation is about concentration risk, not the monthly bill. Local providers pitching sovereign alternatives will use Microsoft’s move to argue that price should not be the only measure that counts.
What’s next
The immediate test will be evidence. Expect Anthropic and Google to contest the performance claims and to sharpen their own pricing in response, and expect independent researchers and Australian security vendors to run the model against real-world scenarios before anyone commits budget. Chief information security officers here will likely trial it in narrow, low-risk workflows first, measuring both accuracy and the true landed cost rather than the headline figure. If the savings prove real and the quality holds, Microsoft will have changed the terms of the debate from whether organisations can afford AI in the SOC to whether they can afford not to use it. If the numbers wobble under scrutiny, this will be remembered as one more round in an increasingly noisy AI security marketing war. Either way, Australian buyers now have more leverage at the negotiating table, which is rarely a bad thing.
Sources: International Business Times Australia.



















































