Microsoft has had a tough year in terms of cybersecurity and the nature of the breaches it has had to deal with. The tech giant is facing a series of major security breaches involving some of its most important and widely used products .
See also: Microsoft: Launches Windows app for iPhone, Mac & Android
Now Microsoft has admitted that it has been lagging behind in its cybersecurity efforts, as evidenced by several high-profile incidents. Among those breaches is Russian state hackers who managed to steal sensitive US government emails, putting the company's corporate email accounts at risk.

In another disturbing incident, a Chinese state-sponsored group breached Microsoft Exchange Online, including those belonging to key figures such as Commerce Secretary Gina Raimondo, U.S. Ambassador to China R. Nicholas Burns , and Congressman Don Bacon.
In response to these security gaps, Microsoft has stated that cybersecurity is now its top priority. To back up this claim, the company released an update to its Secure Future Initiative (SFI) , a program that launched in November 2023 with the goal of significantly strengthening Microsoft's cybersecurity defenses .
See also: Meta AI chatbot: It will use the voices of famous actors
The SFI progress report outlines the steps Microsoft is taking to “prioritize security above all else.” These include significant governance updates, new employee onboarding programs, and rigorous security reviews. The company is focusing on addressing the core pillars of cybersecurity, reflecting its commitment to fundamental changes in its approach to protecting user data and systems.

In terms of specific cybersecurity measures, Microsoft has focused on six key pillars. These include improving identity and protection through improved token management and phishing in its access management solution, Microsoft Entra ID. The company has also streamlined application lifecycle management and reduced the attack surface by removing inactive users, thereby improving protection and productivity.
To improve threat detection and monitoring, Microsoft has introduced standardized security audit logs and centralized log management, now covering 99 percent of network devices. The company has also committed to increasing transparency and reducing the time it takes to address common vulnerabilities and vulnerabilities (CVEs) across cloud . This includes updating processes and creating the Customer Security Management Office to better communicate with customers during security incidents.
See also: Tor says it's still secure despite reports of deanonymize
Despite these efforts, Microsoft acknowledges that the work is far from complete. Charlie Bell, Executive Vice President of Microsoft Security, emphasized that threats are constantly evolving, and Microsoft must evolve with them to ensure the security of its products. The company is fostering a culture of continuous learning and improvement, with the goal of making security not just a feature, but the foundation of its operations in the future.
Source: firstpost
