Accountability, oversight and AI: Inside Microsoft’s security transformation | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


After suffering a series of high-profile cyberattacks over the past decade, Microsoft says a new initiative to reinvigorate its security culture is bearing fruit.

The tech giant’s stumbles — and the expectation that a company of its size would have been able to prevent them — made it a punching bag in the cybersecurity community. In 2022, the teenage cybercrime gang LAPSUS$ broke into the company’s systems. In 2023, operatives from both Russia and China hacked Microsoft in separate incidents, stealing valuable information from the State Department and other customers. China’s hack prompted a federal review board to sharply criticize Microsoft’s lax security practices. Even Russia’s 2020 SolarWinds espionage campaign sparked outrage over Microsoft’s pricing practices. Experts and lawmakers soon revived decades-old warnings that the government’s dependence on Microsoft posed a major security risk.

To contain the damage, Microsoft in November 2023 launched the Secure Future Initiative, vowing to completely overhaul how it developed and secured its software. Since then, the company has published progress reports documenting changes to its culture and technology that it says will reduce the risk of another major failure.

Microsoft believes it has radically transformed how employees approach cybersecurity. In interviews last week at Microsoft’s headquarters in Redmond, Wash., company leaders told Cybersecurity Dive that the SFI had purged much of the internal friction around security that had led to Microsoft’s most embarrassing breaches.

“Our operations [and] products must be secure. That’s how we earn trust with our customers,” said Hammad Rajjoub, the initiative’s director. “You’ve got to go do what you’ve got to do for shipping your products, features, capabilities, but security almost becomes a non-negotiable from that perspective.”

Cybersecurity culture and accountability

Improving cybersecurity requires company-wide buy-in, and in an organization as large as Microsoft, there are bound to be some engineers and managers who don’t agree with how the new security-first mindset manifests itself.

“The core tension is speed versus assurance,” said Fernando Montenegro, vice president and practice lead for cybersecurity and resilience at The Futurum Group. “Ship dates, market pressure, and now the race to ship AI capabilities all push against slowing down for security.”

To combat those pressures, the team behind the SFI has focused on changing Microsoft’s culture.

“It’s an accountability conversation more than anything else,” Rajjoub said. “We still have humans working on these difficult problems, and then they have motivations and challenges that drive that work. So culture is a big, big, big part of that.”

Rajjoub and others at Microsoft are quick to point to CEO Satya Nadella’s edict that the company should always err on the side of security.

At one Microsoft leadership retreat, a corporate vice president complained to Nadella about the trade-offs between spending resources on better security and spending resources deploying features that customers were waiting for. 

“Without hesitation,” according to Rajjoub, “Satya said, ‘Prioritize security above all else.’”

“When your CEO says that this is your number-one priority, and he consistently repeats it over and over again,” Rajjoub added, “that drives change in behavior.”

Outside industry analysts are seeing a difference. Montenegro said “the SFI effort does seem to be paying off.”

Microsoft President Brad Smith testifies before a Senate committee in February 2021 about the company’s role in the SolarWinds data breaches.

Drew Angerer via Getty Images

 

Inside Microsoft, a Cybersecurity Governance Council composed of deputy CISOs for each of the company’s major business lines — including Windows, Azure and Microsoft 365 — meet regularly to discuss the best ways to manage the trade-offs required to emphasize cybersecurity.

“There are active review conversations where there are discussions on, ‘What features are we going to ship? What does the prioritization look like?’” Rajjoub said.

Further down the org chart, employees are evaluated on how they achieve that balancing act.

——————————————————-


Click Here For The Original Source.