CypherCon 2026
Red Team Lessons from Copilot Deployments
Christian Stegh
Abstract:
As organizations race to deploy GenAI tools like Copilot, new risks emerge—often bypassing legacy controls like IAM and DLP. In this session, we’ll go beyond theory with live red teaming demos, showing how natural language prompts can surface confidential data (think offer letters, salary reports, board minutes) that evade automated scans. You’ll learn how attackers exploit permission gaps, why traditional markers fail, and what you can do to proactively defend your environment. Walk away with actionable tactics, sample prompts, and a critical framework for testing your own AI deployments—before adversaries do.

Christian Stegh
Copilot MVP
Christian Stegh has spent his career of 25+ years helping organizations harness technology for competitive advantage.
Chris is an active participant in webinars, industry events, and online posts including as a guest writer for Forbes. He is one of ~3,000 worldwide Microsoft Most Valuable Professionals. His published book on GenAI in the enterprise is called Elevate The Enterprise Using Microsoft 365 Copilot: A Guide for Power Users, CxOs, and IT Pros.
Currently the CTO + VP of Strategy for eGroup, a 9x Partner of the Year of Microsoft, Chris builds strategic roadmaps with customers around cybersecurity, collaboration, AI, and organizational change.