Microsoft president hauled to House for security mistakes

May 12, 2024
1 min read



TLDR:

Key Points:

  • Microsoft’s Brad Smith summoned by House Committee on Homeland Security over cybersecurity failures
  • Major security breaches by China and Russia lead to scrutiny of Microsoft’s security practices

Article Summary:

Microsoft’s vice chair and president, Brad Smith, has been summoned by the House Committee on Homeland Security to address the company’s recent cybersecurity shortcomings. The hearing, scheduled for May 22, will focus on a series of security breaches, including the Microsoft Exchange attack in June 2023 and a separate incident in January involving Russia’s Midnight Blizzard group. The Cyber Safety Review Board harshly criticized Microsoft for a “cascade of avoidable errors” that led to the successful attacks. In response to the criticism, Microsoft’s exec veep, Charlie Bell, announced major changes in the company’s culture, emphasizing security as a top priority. The new Secure Future Initiative (SFI) will focus on six key pillars to enhance security measures within the company.

Security expert Kevin Beaumont praised Microsoft’s efforts to address internal security issues, calling it the company’s “last chance saloon moment on security.” While Microsoft has acknowledged the need for improvement and has outlined plans to enhance security by design and default, the House Committee on Homeland Security is still deliberating on the date for Smith’s hearing. Despite facing backlash for its recent security breaches, Microsoft’s proactive approach towards cybersecurity reform has been commended by industry experts.


Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is