Microsoft beefs up cyber initiative after hard-hitting US report | Computer Weekly
Summary
Microsoft is doubling down on its recently-launched Secure Future Initiative (SFI), expanding the programme – which sets out to address the software and vulnerability issues frequently exploited by threat actors – in the wake of the United States government Cyber Safety Review Board (CSRB) report on last year’s Storm-0558 intrusion and the January 2024 Midnight Blizzard (Cozy Bear) attack. In addition, we will instil accountability by basing part of the compensation of the company’s Senior Leadership Team on our progress in meeting our security plans and milestones,” he said. “We are delivering on these goals through a new level of coordination with a new operating model that aligns leaders and teams to the six SFI pillars, in order to drive security holistically and break down traditional silos,” he added. Internally, Microsoft is also taking steps to improve how its people respond as a collective, implementing new initiatives to help operationalise its learnings from incidents, and instituting a new governance framework overseen by its CISO Igor Tsyganskiy, which introduces a partnership between engineering teams and a newly-created group of deputy CISOs, and will be backed by the full breadth of Microsoft’s existing nation state actor and threat hunting capabilities. It also plans to do more to instil a security-first culture, and will be starting broadscale weekly and monthly operational meetings to include all levels of management and senior- individual contributors working on detailed execution and continuous improvement of security.