Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft strengthens in-house cyber governance, training

By CIO Dive by By CIO Dive
April 21, 2025
Home Enterprise IT
Share on FacebookShare on Twitter


This audio is auto-generated. Please let us know if you have feedback.

Microsoft said Monday it has reached additional milestones in a multiyear effort to strengthen its product development, threat detection and corporate governance structure under a program called the Secure Future Initiative. 

The company has now rolled out a secure-by-design toolkit to 22,000 employees involved in product development, linked employee performance reviews to adoption of security standards and named a deputy CISO for business applications, among other changes. 

“We have made progress across culture and governance by fostering a security-first mindset in every employee and investing in holistic governance structures to address cybersecurity risk across our enterprise,” Charlie Bell, executive vice president, security at Microsoft, wrote in a blog post. 

Out of 28 objectives outlined in the SFI plan, which was first announced in 2023, the company said it is near completion on five and has made significant progress on 11. 

Among the new SFI developments:

  • About 92% of employee productivity accounts are now using phishing-resistant multifactor authentication.
  • The company now has a 73% success rate in addressing cloud vulnerabilities under its reduced time-to-mitigate window. Microsoft did not specify what the new time frame is.
  • The company has removed more than 6.3 million legacy tenants, including more than 550,000 since September 2024. 

The company launched SFI after a China-linked threat group hacked into the Microsoft Exchange Online environments of at least 22 customers.The hack led to the exfiltration of more than 60,000 emails from the U.S. State Department, and the threat group gained access to other highly sensitive accounts, including Commerce Secretary Gina Raimondo.

Microsoft was widely condemned in a 2024 report by the Cyber Safety Review Board, which said the Exchange attack was entirely preventable. The company faced sharp criticism for prioritizing speed to market and “cool” product features over ensuring its products were built using secure development practices.

The report also faulted Microsoft for a separate attack by Midnight Blizzard, a Russia-backed threat group that launched a massive password-spray attack against the company in 2023. The attackers stole emails from top Microsoft executives and later stole credentials from U.S. federal agencies after those credentials were exchanged over email with Microsoft.



Source link

By CIO Dive

By CIO Dive

Next Post
What the Discover merger approval means for Capital One and 2 other financials

What the Discover merger approval means for Capital One and 2 other financials

Recommended.

SalesMail announces integration with RealPage and Knock CRM, expanding its multifamily offering

SalesMail announces integration with RealPage and Knock CRM, expanding its multifamily offering

January 24, 2025
MiTAC Computing Advances Agentic AI Infrastructure with 6th Gen AMD EPYC™ Server CPUs

MiTAC Computing Advances Agentic AI Infrastructure with 6th Gen AMD EPYC™ Server CPUs

July 23, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
Anaconda Extends AI-Native Application Development With Acquisition

Anaconda Extends AI-Native Application Development With Acquisition

May 1, 2026
AT&T Vs. Verizon: How The Country’s Biggest Carriers Fared In Q4 2025

AT&T Vs. Verizon: How The Country’s Biggest Carriers Fared In Q4 2025

January 30, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio