I also had to follow up on Microsoft’s story and the criticism the company faces regarding security.
Last week, Microsoft President Brad Smith faced questioning from the House Homeland Security Committee regarding the company’s handling of reported security flaws in its products. The criticism came after a ProPublica investigation revealed that Microsoft ignored warnings about a product flaw that left millions of users, including federal employees, vulnerable to attack.
According to that ProPublica report, Microsoft dismissed an employee’s warnings about a vulnerability later exploited in the SolarWinds Orion attacks. The vulnerability, known as “Golden SAML,” allowed threat actors to maintain access to compromised environments undetected. Microsoft now recommends migrating to its newer Microsoft Entra ID system. Microsoft’s product team rejected proposed fixes due to concerns about business impact and competition with rival companies. A cybersecurity firm later disclosed the weakness, but Microsoft did not publicly warn customers. The flaw was only addressed after the SolarWinds attack occurred.
Microsoft has announced that it will prioritize security over artificial intelligence (AI) following major cyberattacks by Russia and China. The Cyber Safety Review Board found that the event was made possible by a “cascade of avoidable errors” and a security culture “that requires an overhaul.” Smith stated that cybersecurity will be a higher priority than AI, with CEO Satya Nadella taking personal accountability for security.
And from IT Pro, Microsoft plans to tie executive bonuses to their departments’ security performance to improve its lax cyber security practices. This decision comes after high-profile security breaches and criticism of the company’s corporate culture. The move aims to ensure buy-in from business leaders and drive significant culture changes towards security.
Microsoft’s handling of the vulnerability and subsequent criticism highlight the importance of transparency and proactive security measures. IT service providers must learn from this situation to maintain trust and credibility with their clients. Transparency about vulnerabilities and timely communication are critical in mitigating reputational damage. I may be dismissive of the long term ramifications. Covering it up always makes it worse.
The decision to link executive bonuses to security performance is what will drive change. Full stop. That’s what matters here.

