Wednesday, 22 January 2025
24.6 C
Singapore
20.1 C
Thailand
19.8 C
Indonesia
26 C
Philippines

Microsoft admits cybersecurity challenges but outlines steps towards improvement

Microsoft acknowledges cybersecurity challenges but details efforts under the Secure Future Initiative to improve security and address breaches.

It’s been a challenging year for Microsoft in terms of cybersecurity. The tech giant has faced a series of serious security breaches involving its products, and thereโ€™s clear work to be done. Despite its status as a major player in the tech world, Microsoft has had to confront some significant incidents in recent months, including attacks on high-profile targets within the US government.

One of the most prominent breaches involved Russian state-sponsored hackers infiltrating Microsoftโ€™s corporate email system to gain access to US government emails. Another attack in 2023, orchestrated by a Chinese state-backed group, breached Microsoft Exchange Online mailboxes. High-level figures were affected, including Commerce Secretary Gina Raimondo, US Ambassador to China R. Nicholas Burns, and Congressman Don Bacon.

Despite these setbacks, Microsoft remains committed to making cybersecurity its top priority. In its latest update, the company detailed its progress on the Secure Future Initiative (SFI), a programme launched in November 2023 to bolster its defences.

Learning from the past to protect the future

Microsoftโ€™s recent progress report on the SFI highlights its steps to reinforce its focus on security. This initiative aims to โ€œprioritise security above all else,โ€ the update outlines several key actions. These include governance improvements, upskilling initiatives for staff, and comprehensive security reviews designed to strengthen Microsoftโ€™s cybersecurity posture.

One of the companyโ€™s biggest moves over the past year has been the creation of a Cybersecurity Governance Council. This body is made up of Deputy Chief Information Security Officers (CISOs), who meet regularly to review cybersecurity risks, ensure compliance, and refine Microsoftโ€™s defence strategies. Furthermore, executives now have their compensation linked directly to security performance. This measure is intended to encourage greater accountability and focus on minimising risks and avoiding the mistakes of the past.

Microsoft introduced the Security Skilling Academy to address the growing cybersecurity skills gap. This programme aims to equip employees with the latest knowledge and tools in cybersecurity, enabling them to play a more active role in defending the company against cyber threats.

Enhancing security across the board

Microsoft has also taken significant steps to address its six key pillars of cybersecurity. These include improvements to identity protection, better token management, and enhanced phishing resistance within its Microsoft Entra ID access management system. The company has also tightened tenant and production protection by streamlining app lifecycle management and reducing inactive tenants, thereby reducing the potential attack surface.

Network security has also seen major upgrades. By isolating certain virtual networks with limited backend connectivity, Microsoft aims to curb lateral movement within systems, making it harder for attackers to spread. Admin rules for Azure Storage, SQL, Cosmos DB, and Key Vault have also been improved, giving customers stronger tools to protect their data.

As part of the SFIโ€™s achievements, 85% of Microsoftโ€™s production build pipelines for commercial cloud now operate under centralised governance. To further enhance security, the lifespan of Personal Access Tokens has been slashed to just seven days, and new security checks have been introduced into the software development process. The company has also reduced the number of elevated roles that can access critical engineering systems.

When it comes to threat detection and monitoring, Microsoft has simplified its processes with the introduction of standardised security audit logs. Centralised log management now covers 99% of network devices, making it easier to detect and respond quickly to potential threats.

Looking ahead: a culture of continuous improvement

One key commitment in Microsoftโ€™s SFI update is a renewed focus on transparency. The company has pledged to reduce the time it takes to address common vulnerabilities and exposures (CVEs) across its cloud infrastructure. Additionally, it has set up a Customer Security Management Office to improve communication with customers when a security issue arises.

Microsoft admits cybersecurity challenges but outlines steps towards improvement
Image credit: Geek Wire

Regarding Microsoftโ€™s progress, Executive Vice President of Microsoft Security, Charlie Bell, commented, โ€œThe work weโ€™ve done so far is only the beginning. We know that cyber threats will continue to evolve, and we must evolve with them. By fostering this continuous learning and improvement culture, we are building a future where security is not just a feature but a foundation.โ€

Microsoftโ€™s journey to strengthening its cybersecurity defences is far from over. However, its steps under the Secure Future Initiative indicate a serious commitment to addressing past vulnerabilities and building a more secure future for its users.

Hot this week

Amazon pauses drone deliveries in the US after testing crash

Amazon halts US drone deliveries after crashes during testing, citing safety concerns and working on software updates for its fleet.

Apple reveals apps removed from U.S. App Store alongside TikTok

Apple lists all apps removed in the U.S. alongside TikTok, including CapCut and Lemon8, citing legal obligations under U.S. law.

President Trump repeals Bidenโ€™s AI executive order on first day in office

President Trump repeals Biden's 2023 AI executive order on day one, sparking debate over AI regulation, innovation, and national security risks.

President Trump signs executive order delaying TikTok ban for 75 days

Trump delayed the TikTok ban with a 75-day executive order, allowing time to address national security concerns and find a resolution.

How to download your TikTok videos and data before the ban

The Supreme Court has upheld a TikTok ban, and hereโ€™s how you can back up your videos and data before it happens.

Apple set to launch iPhone SE 4 with Dynamic Island and iPad Air featuring M3 chip

The iPhone SE 4 with Dynamic Island and iPad Air with M3 chip are expected to launch soon. They will offer modern design and performance upgrades.

President Trump signs executive order delaying TikTok ban for 75 days

Trump delayed the TikTok ban with a 75-day executive order, allowing time to address national security concerns and find a resolution.

President Trump repeals Bidenโ€™s AI executive order on first day in office

President Trump repeals Biden's 2023 AI executive order on day one, sparking debate over AI regulation, innovation, and national security risks.

RedNote, Flip, Clapper, and Likee dominate app charts as TikTok returns online

TikTokโ€™s brief ban boosted rivals RedNote, Flip, Clapper, and Likee, which are now leading U.S. app charts and reshaping video-sharing app trends.

Related Articles