Fusion Solution organized a Cybersecurity Workshop featuring simulated attacks and the protection of organizational data

Cybersecurity readiness isn't measured solely by the availability of tools; it also requires demonstrating that the team can accurately detect, analyze, and respond to threats. Fusion Solution therefore organized a Cybersecurity Workshop titled “Enterprise Cyber Defense Lab: Attack Simulation & Data Protection War Room” for SMC customers on Monday, July 20, 2026, from 8:30 AM to 4:30 PM at MPR2, Microsoft Thailand Office, One Bangkok Tower 4, 35th Floor. The workshop focused on simulated scenarios covering data breach investigation, AI risks, account-based attacks, and handling compromised devices using Microsoft Purview, Microsoft Defender, and XDR.
Cybersecurity Workshop that connects data, identity, and devices
Cyber threats within an organization don't originate from a single point. An incident might begin with a compromised user account, connect to endpoints, and lead to access to or the transfer of sensitive data out of the organization.
The Enterprise Cyber Defense Lab program is therefore designed to cover key elements of cybersecurity, including data, user identity, endpoints, and emerging threats related to the use of AI within organizations.
The event format was not limited to lectures but included expert insights, threat situation analysis, and a hands-on lab, allowing participants to practice detecting and responding to simulated incidents step-by-step.

Get the latest cybersecurity trends from Microsoft
The event began with the topic "Cybersecurity Trends from Microsoft," presented by Navapoj Prakobpol, Account Technology Strategist.
Microsoft Thailand Co., Ltd. to convey an overview of cybersecurity trends and key issues that organizations should prioritize.
Next was the Executive Threat Briefing on the topic "Your Data is the New Attack Surface – Are You Ready for the Breach?", which reflected the fact that organizational data is becoming one of the primary targets of attacks.
This issue becomes even more critical as organizations store and utilize data through cloud systems, business applications, collaboration tools, and AI services. Security therefore needs to extend beyond simply protecting networks or devices; it must also provide visibility into the data flow and movement.

Review internal data and risks with Microsoft Purview
The first part of the Security Session focused on Data Protection and Insider Risk Investigation with Microsoft Purview under a simulated Inside the Breach scenario.
This topic helps participants visualize scenarios where sensitive data may be removed from an organization, whether through intentional actions, user error, or inadequate data control processes.
Microsoft Purview is integrated with an insider risk assessment and data protection approach, allowing security teams to systematically examine data traces and flows, rather than analyzing events from fragmented data.

Dealing with Identity, AI Threats, Endpoint, and XDR
Another section of the content is Microsoft Defender Threat Protection under the heading Attack Chain Under Fire, which covers threats related to Identity, AI, Endpoint, and XDR.
XDR, or Extended Detection and Response, is an approach that helps connect security signals from multiple sources, allowing teams to see the relationships between events more clearly. This includes things like user account anomalies, behavior observed on devices, and data-related activity.
Linking this data is crucial for analyzing attack paths because what may seem like a minor anomaly in one system could be part of an ongoing intrusion into another.

Practice detection and response through 4 Hands-on Labs.
Hands-on Lab 1: Data Exfiltration Hunt
The first lab involves training in detecting data theft within the organization, simulating a scenario where an employee takes data externally. Participants will practice detecting traces and analyzing the possible paths through which data may have been leaked.
The key goal is to understand what signals the team should consider when data is moved from a defined location or channel, and how to link events for investigation.

Hands-on Lab 2: AI Data Guardrail
As organizations begin using AI in their operations, a new risk that needs attention is the unauthorized ingestion of sensitive or confidential data into AI systems without proper controls.
The AI Data Guardrail Lab therefore focuses on experimenting with rules to prevent confidential data from being fed into AI, while learning ways to mitigate the risks of AI use within organizations without necessarily blocking the benefits of the technology altogether.

Hands-on Lab 3: Identity Attack Drill
User accounts are one of the key gateways attackers may use to access systems and data. This lab simulates account-based attacks to allow participants to practice tracing intrusion paths and identifying related vulnerabilities.
This type of training helps the team see that identity-based attacks may not end at login but can link to other data, applications, and devices within the organization.

Hands-on Lab 4: Compromised Device Response
The final lab focuses on handling compromised or suspicious devices. Participants will practice isolating devices from the system, mitigating risks, and implementing corrective actions step-by-step.
This process is crucial for incident control because a delayed response or a lack of clear procedures could allow threats to spread to other systems.

The meaning of Workshop for organizations within the SMC group.
For organizations within the SMC group, investment in cybersecurity requires consideration of technology, people, and collaborative processes. Even the most powerful tools may not fully mitigate risk if the team cannot detect signals, alert relevant parties, or implement established response procedures.
This Cybersecurity Workshop helps shift the security mindset from prevention alone to preparing for incident detection and response. Participants will see the connection between data, users, AI, and devices—all part of an organization's attack surface.

How should organizations prepare?
Based on the topics and scenarios within the workshop, organizations can take the following points into consideration.
Specify where critical organizational data is located and through which channels it is being transmitted.
Establish data control guidelines that can be applied to AI services.
Assess the risks associated with user accounts and prepare procedures to handle identity Attacks.
Establish procedures for isolating and troubleshooting devices exhibiting suspicious behavior.
Develop a Security Action Plan that clearly defines the roles and response guidelines for the team.
The event will conclude with a summary of the lessons learned in the topic of Mission Debrief: Lessons Learned & Security Action Plan, to gather insights from each scenario and use them to develop an organizational security plan.

Fusion Solution is ready to support cybersecurity planning for organizations.
Fusion Solution is a provider of technology solutions and Microsoft Solutions for organizations. They offer consulting services on data protection, AI-powered risk management, threat detection, and the customized implementation of Microsoft Purview and Microsoft Defender to suit each organization's systems and processes.
For organizations needing to assess their cybersecurity readiness or design a systematic approach to protecting data, identities, and devices, Fusion Solution is ready to provide consultation and help plan solutions that align with the organization's risk profile and business goals.




