Microsoft says its Secure Future Initiative is improving security culture and reducing cyber risk

Microsoft tied security to pay and promotions for all employees after its SFI overhaul, with CEO Satya Nadella telling leaders to "prioritize security above all else." The company also deployed an AI code scanner that found critical TCP/IP flaws in code developers thought was thoroughly audited.

Categorized in: AI News IT and Development
Published on: Sep 12, 2026
Microsoft says its Secure Future Initiative is improving security culture and reducing cyber risk

Microsoft says its Secure Future Initiative (SFI), launched in November 2023 after a string of damaging breaches, is reshaping how the company builds and ships software. The overhaul touches everything from performance reviews to code scanning, and outside analysts say the early results look real.

The company's security failures had become a running embarrassment. The teenage cybercrime gang LAPSUS$ broke into Microsoft's systems in 2022. Russian and Chinese operatives followed in 2023, with the China hack prompting a federal review board to criticize Microsoft's lax practices. Lawmakers revived warnings about the government's dependence on the company.

Culture change starts at the top

Hammad Rajjoub, the SFI's director, said the initiative is fundamentally "an accountability conversation more than anything else." The company has tied security performance to promotions and raises, and every employee review now includes a discussion of how that person contributed to Microsoft's and its customers' security.

"It doesn't matter [if] you sit in marketing, engineering, incident response, sales," Rajjoub said. "The question is the same."

CEO Satya Nadella set the tone directly. At one leadership retreat, a corporate vice president asked about trade-offs between security spending and shipping features customers wanted. "Without hesitation," Rajjoub said, "Satya said, 'Prioritize security above all else.'"

Fernando Montenegro, vice president and practice lead for cybersecurity and resilience at The Futurum Group, said the core tension remains "speed versus assurance." But he added that "the SFI effort does seem to be paying off."

Shifting security left in Windows

The Windows division has 7,000 employees, including 5,000 engineers. Dana Huang, corporate vice president for Windows Security, oversees a security engineering team of "a dozen people" - a ratio she acknowledged requires focus. Her team now concentrates on design-time sign-offs and early engagement rather than pre-launch checkboxes.

"Some of the learning in there was, we engaged too late," Huang said. "There's [a] narrow view [among developers] of, 'I don't think that's a problem,' and then my security engineer looks at it [and says], 'No, there is a problem.'"

One of her team's top priorities is Microsoft's agentic AI technology. "I have a dedicated principal-level security engineer engage with the team who are building the foundation layer for agents," she said. "You don't need to look at every single agent. But those agents will [be] built on some sort of platform."

Montenegro cautioned against overreach. "A dozen can't inspect the work of 5,000, and shouldn't try," he said. "Their job is building the standards, tooling, and secure defaults [that developer] teams inherit."

MDASH and automated vulnerability hunting

Microsoft has also deployed a multi-LLM agentic code scanner called MDASH. The tool found critical remote-code-execution vulnerabilities in Windows' TCP/IP network stack - flaws that surprised developers who considered the code thoroughly audited.

"Everyone didn't believe [the TCP/IP flaws were real], because, 'Hey, this [code] is extremely stable, we've audited it many times,'" said Taesoo Kim, a vice president of security research. "But we found and proactively addressed all these vulnerabilities by using MDASH."

The scanner now runs continuously on code Microsoft is shipping and actively building. Rajjoub said "there are enforcements in place that will not allow you to ship your code unless and until you're meeting the security bar." Microsoft also uses MDASH to scan open-source packages like the Linux kernel and FFmpeg, and sells the tool to customers for their own repositories.

Secure defaults and the MFA mandate

Microsoft has started requiring protections that were previously optional. In October 2024, the company began requiring multifactor authentication for Azure. Executives staggered the rollout to avoid breaking customer workflows: new accounts needed MFA immediately, while older accounts got a transition period.

Huang said Microsoft also discovered it could deactivate certain risky features by default "and still allow people to move to 'on' if they have a specific need and they have enough protections." For customers who want those features, the company works with them to establish guardrails.

Analysts offered measured assessments. Forrester's Merritt Maxim said the changes "are improving security across the Microsoft ecosystem," but warned that "urgency, especially around AI," could quietly erode discipline. His colleague Allie Mellen said the changes "need to remain embedded and improve over time to truly have a long-term impact."

Why this matters for IT and development teams

If your organization builds on Microsoft's stack, these changes will reach you whether you opt in or not. The Azure MFA mandate is already in effect. Risky features now ship off by default. And the security review process inside Microsoft means features may arrive later - or arrive with constraints - because a security engineer flagged a design issue before release. For teams running Microsoft products, expect more secure defaults and fewer surprises from unpatched vulnerabilities. For teams building software, the shift-left model Huang describes is worth studying: a small security team setting standards and tooling early, rather than auditing at the end.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)