Microsoft revamps cybersecurity approach post critical CSRB assessment

May 5, 2024
1 min read

TLDR:

  • Microsoft security chief pledges significant reforms to prioritize security
  • New strategy includes adding Deputy CISOs to product teams, linking pay to security goals

After a scathing report from the Cyber Safety Review Board (CSRB), Microsoft’s security chief, Charlie Bell, announced plans to overhaul the company’s cybersecurity strategy. This shift will focus on prioritizing security above all other product features. The new strategy includes adding Deputy CISOs to each product team, linking a portion of senior leaders’ pay to security milestones and goals, and implementing state-of-the-art standards for identity and secrets management. Microsoft will also prioritize protecting its networks and systems, improving isolation, monitoring, inventory, and secure operations.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and