Close Menu
CloudSecNewsHub
  • News
  • Technologies
  • Automation
  • Updates
  • Guides
  • Tools
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

What's Hot

Google Cloud Security Plitz attacks e -hunting, improves vision

May 8, 2025

How to pick up criminal evidence for Microsoft 365

May 8, 2025

Cloud security treatment: American federal edition

May 7, 2025
Facebook X (Twitter) Instagram
Trending
  • Google Cloud Security Plitz attacks e -hunting, improves vision
  • How to pick up criminal evidence for Microsoft 365
  • Cloud security treatment: American federal edition
  • The most prominent report: 2025 Experience of exposure to cloud data
  • Artificial intelligence agents to convert Google Cloud Security Ops
  • The necessity of cloud security in the electronic scene today
  • Gap block: How to simplify QULYS Compliance NCA ECC 2024 for companies
  • Ransomware Spike displays cracks in cloud safety
Facebook X (Twitter) Instagram Pinterest Vimeo
CloudSecNewsHubCloudSecNewsHub
  • News

    How to pick up criminal evidence for Microsoft 365

    May 8, 2025

    The most prominent report: 2025 Experience of exposure to cloud data

    May 7, 2025

    Artificial intelligence agents to convert Google Cloud Security Ops

    May 6, 2025

    Ransomware Spike displays cracks in cloud safety

    May 5, 2025

    Sentinelone wins the best safety point and cloud security at the 2025 SC Awards

    May 1, 2025
  • Technologies

    Gartner: How to build a safe institution cloud environment

    April 21, 2025

    Promote South Korea's national security by adopting the cloud

    April 11, 2025

    “The traditional methods of cloud safety, where organizations depend on the segmented cloud safety tools, are not simply enough”

    April 3, 2025

    Stream.security The cloud solution in actual time in industry with TRP technology designed to dilute proactively from the effect of breach in the cloud

    April 1, 2025

    Skyhawk's creation platform mentioned in 2024 Gartner Emerging Tech Impact Radar: Preventive Cyber ​​Security

    March 28, 2025
  • Automation

    Cloud Security Alliance launches an initiative to automate compliance

    April 30, 2025

    The security automation market to see a great expansion

    April 25, 2025

    GSA FedRAMP '20X' rejuvenation keys to automation, to the approvals in “Weeks” – MERITALK

    April 16, 2025

    Cortex Cloud – cloud safety conversion

    April 11, 2025

    TUFIN extends the possibilities of the security of the cloud and the network with the latest version of the synchronous pavilion

    April 8, 2025
  • Updates

    Google Cloud Security Plitz attacks e -hunting, improves vision

    May 8, 2025

    April 2025 Correction Tuesday: updates and analysis

    April 15, 2025

    Google Cloud 2025: News and updates

    April 12, 2025

    5 Google Big Google Aman ads on the next 2025

    April 9, 2025

    Google offers a unified safety platform and safety agents driven by artificial intelligence

    April 9, 2025
  • Guides

    CISO guide for effective cloud security strategies

    April 30, 2025

    Singapore offers instructions to support the cloud and the elasticity of the first place

    April 29, 2025

    Singapore has new guidelines to enhance flexibility and security for cloud services and data centers

    April 5, 2025

    What is the safety of the cloud? | IBM

    April 3, 2025

    Google gets Wiz for $ 32 billion to boost cloud safety

    March 19, 2025
  • Tools

    Cloud security treatment: American federal edition

    May 7, 2025

    The necessity of cloud security in the electronic scene today

    May 6, 2025

    Crowdstrike (CRWD) launches Amnesty International Security tools to improve the cloud p

    April 30, 2025

    The 5 best CNAPP benefits that you need to know in 2025

    April 26, 2025

    The security coalition cloud launches the latest security report. Saas

    April 26, 2025
  • Compliance

    Gap block: How to simplify QULYS Compliance NCA ECC 2024 for companies

    May 5, 2025

    Ensuring commitment to international standards

    April 29, 2025

    Thales and Deloitte are an alliance to enhance the security and compliance data strategies

    April 22, 2025

    AWS security compliance is easy: IT-Magic Devops solutions for a stronger security situation

    April 21, 2025

    5 ways that banks can achieve smooth security and compliance in 2025

    April 14, 2025
Login
CloudSecNewsHub
Home»Updates»Microsoft Happy-Talk security update raises 10 tough questions
Updates

Microsoft Happy-Talk security update raises 10 tough questions

CloudSecNewsHubBy CloudSecNewsHubSeptember 26, 2024No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Microsoft Happy Talk Security Update Raises 10 Tough Questions
Share
Facebook Twitter LinkedIn Pinterest Email

While Microsoft appears to be aggressively beefing up its cybersecurity efforts after a series of embarrassing incidents, the company's list of proof points meant to emphasize that “security is our top priority” raises some pretty big questions, starting with this one: What Is Microsoft's goal? Top priority before security?

I'll get to these other big questions in a moment, but first let me make some guesses about what the previous “highest priority” might be:

profit? openeye? Activision deal closing? Footnotes? Will it figure out how to turn its plans to become a massive user of nuclear energy into its “green” form? (BTW, I'm a big fan of the Three Mile Island Plan!) Want to stay on top of your revitalized AWS?

I guess what bothers me is that Microsoft seems to want to be praised, appreciated, and admired for realizing – here in 2024 – that security cannot be a second thought and certainly should never be an afterthought. That's why I'm confused about Microsoft's top priority before CEO Satya Nadella finally gets fed up with his company's many security shortcomings and public embarrassment and decides that from now on, security is now the big thing.

I think the sheer fact that Microsoft is finally acknowledging the priority of security in today's digital world is a good thing. But to put it bluntly, what the hell took them so long to realize that??

Below is an excerpt of the big security updates released by Microsoft this week. I'm not sure what you'll make of that, but to me it all seems pretty clear — it all sounds like the kind of things everyone just assumed Microsoft was doing over the past five years as it became the world's largest enterprise. Cloud provider, cloud revenues in calendar 2024 are likely to approach $150 billion. The excerpt is from Microsoft Executive Vice President and Head of Security Business Charlie Bell in a blog post earlier this week:

“At Microsoft, we recognize our unique responsibility to protect the future of our customers and our community. As a result, everyone at Microsoft plays a pivotal role in ‘Putting Security Above All’. We have made significant progress in fostering a security-first culture.

Well – it looks nice and warm and all that. But the key point comes in the third and final sentence when Bell specifically admits that Microsoft — again, the world's largest cloud vendor and one of the world's leading suppliers of AI technology, enterprise applications and much more — does not have a security system. Culture First, instead simply makes “progress in promoting a security-first culture.”

Ask your Cloud Wars AI Agent about this analysis

To the CEOs and IT managers evaluating cloud and AI providers: Does this revelation from security leader Bill give you complete confidence about handing over the future of your organization — and perhaps your career, too — to Microsoft?

Okay, I see I'm starting to go through my big list of questions about this whole Microsoft conversion, so let's get to those.

Question: As stated above, what took Nadella and his team so long to realize that security wasn't just an upgrade or add-on, but should instead be at the core of everything Microsoft does? Question: How can Nadella have such a complete blind spot on security, which has dominated high-level thinking among the top 10 companies in Cloud Wars for the past several years? Peter Drucker famously said, “Culture eats strategy for breakfast.” In a damning report on Microsoft's security shortcomings released earlier this year, a team within the US Department of Homeland Security called the Cyber ​​Safety Review Board criticized Microsoft's culture for failing to prioritize security, and failing to hold anyone accountable for security problems and disasters. Failure to link financial incentives for executives to security, and failure to adequately fund security initiatives despite Microsoft being one of the richest companies the world has ever known. (For fiscal year 2024, Microsoft's net income was $88.1 billion.) Question: Aside from the trivial cultural changes that Bill mentioned in his blog post, how is Microsoft trying to reform its culture to ensure that security actually becomes the top priority rather than security? In messages? Late last year, Microsoft hired a new CISO from outside the company – and good luck with that decision! Igor Tsygansky comes from one of the world's largest asset management firms (Bridgewater Associates) and brings a much-needed client perspective to this vital position. Brett Arsenault, the former chief information security officer, has been among the company's best insiders his entire life: During his 35-year career at Microsoft, he was chief information security officer for 23 consecutive years until Nadella realized late last year that a leader was needed. New with a fresh vision to lead the company. Necessary changes. Question: How could Nadella – one of the world's top CEOs – not realize much earlier that a new chief information security officer was necessary as part of a much-needed security overhaul? New CISO Tsyganskiy reports to Security Leader Bell, who for the past three years has served as Executive Vice President of Security, Compliance, Identity and Administration. And Arsenault, who may be a great guy but who nonetheless headed with Bill an organization that was so out of touch with current reality that Microsoft is overhauling its entire security operation, now serves as the company's vice president and senior cybersecurity advisor. Questions: Since joining Microsoft from Amazon in September 2021, has Bill been loudly and relentlessly urging Nadella to overhaul Microsoft's entire approach to security? If not, why do Nadella and Microsoft's customers think he is the right person to lead the necessary changes? Conversely, if Bill was beating the drum for sweeping changes in security, why didn't Nadella listen? Why did Nadella wait two years? What conflicting priorities have blinded Nadella and other high-level leaders from viewing security as anything other than the top priority?

Final thoughts

In addition to the blog post from Bell outlining these first rounds of changes, Microsoft also earlier this week published a September 2024 progress report on its efforts. Much of this 25-page document is devoted to discussing the company's six “engineering pillars” on which its development and new security behavior depend. Take a look at these six pillars:

Protect identities and secrets Protect tenants and isolate production systems Protect networks Protect engineering systems Monitor and detect threats Accelerate response and remediation

In Bell's blog post, he says that all six of these “core pillars” represent a “critical area of ​​focus for cybersecurity. These pillars guide our continued work to elevate security across Microsoft and help us meet the evolving demands of the security landscape.”

Do these pillars—the descriptions of which take up nearly 20 of the progress report's 25 pages—fill you with optimism about Microsoft's new security vision, security commitment, and security culture?

Me too.

AI Copilot Summit NA is the first AI event to identify opportunities, impact and outcomes possible with Microsoft Copilot for mid-market companies and enterprises. Register now to attend the AI ​​Copilot Summit in San Diego, CA March 17-19, 2025.

HappyTalk Microsoft Questions raises security tough Update
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Security Updates: Lots of Promises and Pledges
Next Article AI-Powered Edge Computing: Cloud Security Issues
admin
CloudSecNewsHub
  • Website

Related Posts

Updates

Google Cloud Security Plitz attacks e -hunting, improves vision

May 8, 2025
News

How to pick up criminal evidence for Microsoft 365

May 8, 2025
Tools

Cloud security treatment: American federal edition

May 7, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Debian 12.6 released with 84 security updates and 162 bug fixes

July 15, 20241 Views

Google Cloud Security Plitz attacks e -hunting, improves vision

May 8, 20250 Views

How to pick up criminal evidence for Microsoft 365

May 8, 20250 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Don't Miss
Updates

Google Cloud Security Plitz attacks e -hunting, improves vision

CloudSecNewsHubMay 8, 2025
News

How to pick up criminal evidence for Microsoft 365

CloudSecNewsHubMay 8, 2025
Tools

Cloud security treatment: American federal edition

CloudSecNewsHubMay 7, 2025

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

Most Popular

Debian 12.6 released with 84 security updates and 162 bug fixes

July 15, 20241 Views

Google Cloud Security Plitz attacks e -hunting, improves vision

May 8, 20250 Views

How to pick up criminal evidence for Microsoft 365

May 8, 20250 Views
Don't Miss

Google Cloud Security Plitz attacks e -hunting, improves vision

May 8, 2025

How to pick up criminal evidence for Microsoft 365

May 8, 2025

Cloud security treatment: American federal edition

May 7, 2025

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

Facebook X (Twitter) Instagram Pinterest
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
© 2025 CloudSecNewsHub. All Rights Reserved

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?