Saturday, 15 Nov 2025
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Microsoft’s largest ever security transformation detailed in new report
Security

Microsoft’s largest ever security transformation detailed in new report

Last updated: September 23, 2024 3:01 pm
Published September 23, 2024
Share
Vector collage of the Microsoft logo among arrows and lines going up and down.
SHARE

Microsoft made safety its No. 1 precedence for each worker earlier this 12 months, following years of safety points and a scathing report from the US Cyber Security Assessment Board. Practically six months after Microsoft CEO Satya Nadella instructed your complete firm that safety must be prioritized above all else, the software program large is offering a report on its progress.

Microsoft first kicked off its Safe Future Initiative (SFI) in November 2023, simply months earlier than the US Cyber Security Assessment Board concluded that “Microsoft’s safety tradition was insufficient and requires an overhaul.” That blistering evaluate actually kicked Microsoft into gear, and the corporate is revealing at this time that it now has the equal of 34,000 full-time engineers working towards its SFI, making it the largest cybersecurity engineering effort ever within Microsoft.

Each Microsoft worker is now being judged on their safety work, after the corporate tied its safety efforts to worker efficiency critiques final month. In latest months, Microsoft has additionally accomplished a collection of enhancements to its safety processes because of the SFI.

Microsoft has up to date its Entra ID and Microsoft Account (MSA) methods to generate, retailer, and robotically rotate entry token signing keys utilizing Azure-managed {hardware} safety module. 5.75 million inactive tenants have additionally been eradicated to scale back assault surfaces. Microsoft additionally now makes use of a brand new system for testing that has safe defaults to keep away from legacy methods from inflicting safety complications sooner or later.

Microsoft is now monitoring over 99 p.c of its bodily community in a central stock system that helps with firmware compliance and logging. Microsoft has improved its audit logs to retain logs for no less than two years, too.

See also  Microsoft's new Magnetic-One system directs multiple AI agents to complete user tasks

Engineering groups inside Microsoft have now had private entry tokens lower down to only seven days, SSH entry disabled for all inside engineering repos, and the quantity of individuals with entry to key engineering methods has been lowered.

Microsoft has been criticized for the period of time it takes to reply to safety points up to now, and the corporate is now publishing CVEs “even when no buyer motion is required, to enhance transparency.”

Reworking Microsoft’s engineering processes and safety tradition is not any simple activity, particularly when the corporate has 100,000 engineers, designers, and undertaking managers engaged on greater than 500,000 work objects every single day and 5 million builds every month.

Microsoft is implementing new requirements by utilizing a “Begin Proper, Keep Proper, and Get Proper” method. “Begin Proper” ensures initiatives adhere to safety requirements utilizing templates, insurance policies, and self-service instruments. “Keep Proper” then makes certain there’s monitoring on initiatives and related coverage enforcement. The ultimate half is “Get Proper,” which is designed for Microsoft to observe its state of compliance.

The software program large has additionally created a brand new Cybersecurity Governance Council and appointed 13 deputy CISOs, 4 of whom are new Microsoft hires:

  • Damon Becknel, vp and deputy CISO, regulated industries: Becknel joined Microsoft in July, after serving as CISO at ID.me and Horizon Blue Cross Blue Defend.
  • Geoff Belknap, company vp and deputy CISO, core and mergers and acquisitions: Belknap beforehand served as CISO at Microsoft-owned LinkedIn and was additionally beforehand CISO at Slack and CSO at Palantir.
  • Shawn Bowen, vp and deputy CISO, gaming: Bowen has spent 27 years in engineering and safety roles, together with serving as CISO at World Kinect and america Marine Corps Intelligence.
  • Timothy Langan, company vp and deputy CISO, authorities: Langan spent greater than 26 years on the FBI earlier than becoming a member of Microsoft in July, masking cyber, prison examine, and different operations on the US company.
See also  Microsoft announces its own Black Hat-like hacking event with big rewards for AI security

The opposite 9 deputy CISOs are a wide range of veteran Microsoft executives which have many years of expertise on the firm, together with technical fellow Mark Russinovich, who has been named deputy CISO for Azure alongside his present Azure CTO function. Microsoft’s senior management workforce is now reviewing SFI progress weekly and offering updates to Microsoft’s board of administrators quarterly on the progress.

Lastly, Microsoft launched a safety skilling academy in July, which incorporates coaching for all workers to bolster “the significance of safety in day by day operations.” This ongoing coaching, efficiency critiques, and the oversight of Microsoft’s senior management workforce definitely places strain on workers to focus extra on safety than ever earlier than, however Microsoft remains to be on a protracted path to profitable again belief and placing the headlines about its safety document within the rearview mirror.

“Our dedication to transparency and business collaboration stays unwavering,” says Charlie Bell, head of Microsoft safety. “By fostering this tradition of steady studying and enchancment, we’re constructing a future the place safety isn’t just a characteristic, however a basis.”

Source link

TAGGED: Detailed, largest, Microsofts, report, security, Transformation
Share This Article
Twitter Email Copy Link Print
Previous Article The Pros and Cons of Public Cloud Storage for Data Center Backups The Pros and Cons of Public Cloud Storage for Data Center Backups
Next Article Wind River introduces eLxr Pro enterprise Linux distribution for cloud-to-edge deployments Wind River introduces eLxr Pro enterprise Linux distribution for cloud-to-edge deployments
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Singapore Says 2.5m Transactions Failed Amid Data Center Disruption | DCN

About 2.5 million Singapore payment and ATM transactions couldn’t be completed during DBS Group Holdings and…

February 5, 2024

Oracle’s Vision and Strategy – Larry Ellison Keynote at CloudWorld 2024

Oracle co-founder and CTO Larry Ellison took the stage at Oracle CloudWorld to ship a…

September 16, 2024

OpenAI’s GPT-5 rollout is not going smoothly

Need smarter insights in your inbox? Join our weekly newsletters to get solely what issues…

August 9, 2025

Emotive voice AI startup Hume launches new EVI 3 model with rapid custom voice creation

Be a part of our day by day and weekly newsletters for the most recent…

May 30, 2025

How Capital One built production multi-agent AI workflows to power enterprise use cases

How do you steadiness danger administration and security with innovation in agentic programs — and…

July 13, 2025

You Might Also Like

Quantencomputer
Global Market

Microsoft’s largest quantum site to be built in Denmark

By saad
Yotta
Security

Explore Our Online Events

By saad
Anthropic to Pour $50B into US Data Centers
Security

Anthropic to Pour $50B into US Data Centers

By saad
Security lapses emerge amid the global AI race
AI

Security lapses emerge amid the global AI race

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.