pwshub.com

Microsoft is binding employee bonuses and promotions to security performance

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

The big picture: Microsoft has taken heat over security issues in its products for years. Despite CEO Satya Nadella making security a "top priority" in the wake of major cyberattacks and criticism from the feds back in May, it didn't stop the CrowdStrike fiasco from happening. More work was clearly needed, so the company is now doubling down by tying security directly to employee performance reviews and compensation.

In an internal memo obtained by The Verge, Microsoft's chief people officer Kathleen Hogan outlined the company's new "Security Core Priority" policy, which builds on the previous "Secure Future" initiative ushered in by Nadella. She re-emphasized the CEO's words in the memo, saying that when faced with a trade-off, employees have their marching orders: "security above all else."

However, the new policy adds some more teeth behind the push. A lack of focus on security could directly impact promotions, salary increases, and bonuses for Microsoft's workforce.

Microsoft essentially wants employees to do more than simply check boxes on compliance requirements. It expects employees to bake security into every aspect of their work and hold themselves accountable. All staff will need to demonstrate how they prioritized and improved security through their regular performance conversations, tracked in the company's "Connect" tool.

For those on the technical side of building products, it means security gets integrated from the initial design phase rather than tacked on as an afterthought.

It's not just developers in the crosshairs, though. Microsoft is strengthening its commitment to the "security-first mindset" across the entire workforce, regardless of role. Even executives will have specific security deliverables tied to their Connect reviews.

The stakes are high for Microsoft as it rebrands itself as a security-focused company after years of being battered by malware, vulnerabilities, and data breaches. After all, the company's software and services like Windows, Office, and Azure run mission-critical systems across enterprises and governments worldwide. Losing that trust could be catastrophic.

The new policy formalizes security as a core priority on par with Microsoft's existing mandates around diversity and inclusion.

"The Security Core Priority is not a check-the-box compliance exercise; it is a way for every employee and manager to commit to – and be accountable for – prioritizing security, and a way for us to codify your contributions and to recognize you for your impact. We all must act with a security-first mindset, speak up, and proactively look for opportunities to ensure security in everything we do."

The changes are already impacting some Microsoft products and services. Basic Authentication for personal Outlook accounts gets dropped next month in a move to push people to use Modern Authentication. Meanwhile, the lightweight Outlook web app gets retired on August 19 to eliminate any potential security risks.

Source: techspot.com

Related stories
1 week ago - Chatterbox Labs CEO claims Chief Digital and Artificial Intelligence Office unfairly cancelled a contract then accused him of blackmail In-depth Chatterbox Lab CEO Danny Coleman alleges that after three and a half years of uncompensated...
1 week ago - You have options to click one box to order companies not to blab your personal data. California might soon require it by law.
5 days ago - Oh look, another voluntary, non-binding agreement to do better Some of the largest AI firms in America have given the White House a solemn pledge to prevent their AI products from being used to generate non-consensual deepfake pornography...
1 month ago - New Display settings let you modify the resolution, refresh rate, and monitor orientation. There's also a new RTX Video enhancements section for converting SDR video playing in your browser into HDR.Read Entire Article
1 week ago - VirtualBox's refreshed UI brings a more modern feel, including a switch from simplified controls for beginners to full settings for experienced users, and more.Read Entire Article
Other stories
34 minutes ago - Experts at the Netherlands Institute for Radio Astronomy (ASTRON) claim that second-generation, or "V2," Mini Starlink satellites emit interference that is a staggering 32 times stronger than that from previous models. Director Jessica...
34 minutes ago - The PKfail incident shocked the computer industry, exposing a deeply hidden flaw within the core of modern firmware infrastructure. The researchers who uncovered the issue have returned with new data, offering a more realistic assessment...
34 minutes ago - Nighttime anxiety can really mess up your ability to sleep at night. Here's what you can do about it right now.
34 minutes ago - With spectacular visuals and incredible combat, I cannot wait for Veilguard to launch on Oct. 31.
35 minutes ago - Finding the perfect pair of glasses is difficult, but here's how to do so while considering your face shape, skin tone, lifestyle and personality.