Customers Want AI. Their Security Teams Are Nervous. Both Sides Are Right.
- Jul 7
- 5 min read

One of the more interesting things I've noticed over the last six months is that very few AI conversations stay as AI conversations for long.
A customer might start by asking about Copilot. Somebody else might have seen a demo of an agent and started wondering whether it could replace a manual process. Leadership teams are increasingly asking how AI fits into their wider business strategy, particularly as Microsoft's messaging shifts towards what it now calls Frontier Transformation.
The conversation usually begins with productivity, but it rarely ends there.
Before long, somebody asks a question that changes the direction of the discussion entirely.
"How do we know what information AI can access?"
At that point, the conversation isn't really about AI anymore. It's about trust.
And trust is rapidly becoming one of the most valuable things security partners can help customers establish.
Security Has Quietly Moved Closer to the Centre of the Conversation
Historically, security often sat alongside transformation programmes rather than at the heart of them.
A business would decide what it wanted to achieve, a technology strategy would emerge, and security would be brought in to validate the approach and ensure risks were understood and managed.
That model feels increasingly outdated.
Today, the organisations moving fastest on AI are not necessarily the ones with the biggest budgets or the most ambitious leadership teams. They are often the organisations that already have confidence in their security foundations. They know where their data lives, they understand who has access to it, and they have governance structures that allow them to adopt new technologies without months of uncertainty and internal debate.
Conversely, many organisations that are enthusiastic about AI discover quite quickly that they are less prepared than they thought. Not because they've done anything wrong, but because AI has a habit of exposing problems that have existed quietly in the background for years.
Permissions that nobody has reviewed.
Sensitive information stored in unexpected places.
A lack of visibility around data ownership.
Processes that have evolved organically without anybody stepping back to understand whether they still make sense.
Those aren't AI problems.
They're business problems that AI happens to reveal.
The Real Opportunity Isn't Cybersecurity
When most customers start exploring AI, they aren't looking to buy more security tooling. In many cases they already own a significant proportion of Microsoft's security stack.
The challenge is rarely a lack of technology, it's a lack of confidence.
Customers want to know whether they can move forward safely. They want to understand where the risks are, what good governance looks like, what they need to fix first, and how they avoid creating new challenges whilst solving existing ones.
That feels much more like an advisory conversation than a traditional security engagement.
In fact, some of the most valuable work security partners may undertake over the next few years might have very little to do with incident response, endpoint protection or threat management.
Instead, it may revolve around helping customers answer a much simpler question:
"What do we need to do before we're comfortable moving forward?"
Microsoft's own FY27 investments appear to recognise this shift. The Frontier Accelerate for Security engagements place considerable emphasis on assessments, posture reviews, roadmap development and Zero Trust-aligned planning activities designed to help customers understand their environment before making wider investments.
Where I Think The Most Interesting Opportunities Are Emerging
If I were running a Microsoft Security practice today, I'd be paying close attention to where AI projects tend to stall. Whenever technologies create uncertainty, opportunities emerge for partners that can provide clarity
.
For some customers, that uncertainty revolves around data governance. For others, it's identity, compliance or information protection. Increasingly, organisations are asking how they can adopt AI whilst maintaining control of information, meeting regulatory requirements and avoiding the sorts of risks that become very expensive to explain after the fact.
That's why I think many security partners should be looking beyond traditional assessments and managed services and considering how they package expertise.
An AI Security Readiness Review feels like a natural starting point, so does a Copilot Governance Assessment designed to help organisations understand whether their existing permissions, labelling and information management policies are fit for purpose.
I've also seen increasing demand for workshops that sit somewhere between security and business transformation. Rather than focusing exclusively on technology, they help leadership teams understand where AI introduces new risks, where existing controls remain relevant, and where governance needs to evolve.
The common thread is that these services help customers make decisions, and better decision-making is becoming a valuable service in its own right.
The Managed Services Opportunity Might Look Different Than Expected
Most managed security services are built around monitoring, response and protection, and while those capabilities aren't going away, the scope of what customers expect most definitely is.
As organisations deploy more AI capabilities, agents and automation, there is likely to be growing demand for ongoing governance, optimisation and oversight. Permissions need reviewing. Policies need refining. New use cases emerge. Business processes evolve.
In other words, security increasingly becomes part of how customers manage change rather than simply how they manage risk. That opens up interesting possibilities for partners willing to think beyond conventional managed security models.
Looking Ahead
One of Microsoft's recurring themes for FY27 is the idea of helping customers become Frontier organisations, businesses that move beyond experimentation and begin using AI, automation and data to drive meaningful operational change. Security sits underneath that ambition more than many people realise. Microsoft's broader Frontier Transformation messaging consistently positions security as part of the trusted foundation required to support AI adoption and business transformation.
The opportunity for security partners isn't simply to protect customers from threats.
It's to help customers move forward with confidence. Those are subtly different things.
The first is reactive.
The second is strategic.
And if I had to place a bet on where the most valuable conversations are likely to happen in FY27, I'd expect them to sit firmly in that second category.
Where Pargentic Comes In
Most security partners don't need help understanding that AI is changing the market.
What they're trying to work out is how to respond to it.
Which services make sense? Which opportunities are genuine? How closely does Microsoft's investment strategy align with your existing business? And perhaps most importantly, how do you turn all of that into something customers will actually buy?
That's where we help.
At Pargentic, we work with Microsoft partners to identify where Microsoft's priorities, customer demand and commercial opportunity intersect. Whether that's shaping new service offerings, aligning to Microsoft's FY27 direction, improving co-sell readiness or understanding where Frontier opportunities exist within your customer base, the goal is always the same.
Turning market change into sustainable growth.
Because whilst AI may be driving the headlines, trust is increasingly what determines who moves forward, and trust has always been a security conversation.



Comments