Cybersecurity Archives - Inside Track Blog http://approjects.co.za/?big=insidetrack/blog/tag/cybersecurity/ How Microsoft does IT Mon, 29 Jun 2026 18:24:55 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 137088546 How we approach cybersecurity risk management at Microsoft http://approjects.co.za/?big=insidetrack/blog/how-we-approach-cybersecurity-risk-management-at-microsoft/ Thu, 25 Jun 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24461 Cybersecurity risk management at Microsoft is an enterprise-wide discipline spanning governance, engineering, operations, and organizational culture. Through our international operations and diverse portfolio of products, services, and regulatory obligations, we’ve developed a mature, scalable framework designed to facilitate proactive risk identification, structured mitigation, and continuous oversight. This article presents our approach to cybersecurity risk management, […]

The post How we approach cybersecurity risk management at Microsoft appeared first on Inside Track Blog.

]]>
Cybersecurity risk management at Microsoft is an enterprise-wide discipline spanning governance, engineering, operations, and organizational culture. Through our international operations and diverse portfolio of products, services, and regulatory obligations, we’ve developed a mature, scalable framework designed to facilitate proactive risk identification, structured mitigation, and continuous oversight.

This article presents our approach to cybersecurity risk management, detailing the internal governance structures, lifecycle methodologies, regulatory compliance processes, and organizational practices that collectively promote transparency and accountability. This approach is built on two foundational components: a structured risk management lifecycle and a governance model that integrates cybersecurity risk into enterprise-level decision making.

Governance as the foundation

Microsoft’s cybersecurity risk management program is fundamentally structured around robust governance mechanisms. Central to this framework is the Cybersecurity Governance Council, a cross-functional body composed of the Chief Information Security Officer (CISO), Deputy CISOs (DCISOs), and representatives from legal and regulatory affairs. This council convenes twice weekly to evaluate emerging risks, validate mitigation plans, and ensure alignment with enterprise priorities.

The governance model is designed to facilitate bidirectional communication of risk intelligence. Information flows upward from engineering and operational domains to executive leadership, and downward from strategic oversight to operational execution. This exchange is essential for maintaining situational awareness and ensuring that risk mitigation efforts are both evidence-based and scalable.

At the operational level, DCISOs are accountable for reviewing, prioritizing, mitigating, and accepting risks within their domains. This domain-aligned ownership model ensures that accountability for cybersecurity risk is clearly defined and directly connected to enterprise decision making.

Once risks are identified, they are reviewed on a recurring basis and aggregated to inform enterprise-level prioritization. Risk acceptance decisions are tiered based on residual risk levels and aligned with Microsoft’s defined risk appetite. They are then governed and monitored to ensure consistency and appropriate oversight.

A pyramid with bidirectional arrow showing how risk information flows back and forth from foundational elements to senior leadership.

Foundational elements

Listening systems

  • Internal and external audits
  • Current and pending regulation
  • Incidents and media
  • Industry groups

Methodology

  • Risk management framework
  • Risk rating criteria
  • Risk universe

Tools

  • Power BI
  • Risk portfolio and accountability matrix
  • Risk assessments
  • NIST cybersecurity assessments

Risk domains

  • Cybersecurity
  • Quality and availability
  • Business resilience
  • Corruption
  • Digital safety and service misuse
  • Product safety
  • Sustainability
  • Global trade
  • Antitrust and regulation
  • Talent management
  • Data privacy
  • Supply chain
  • Financial
  • Facility security and people safety

Operational risk

  • Search, advertising, and news
  • Artificial intelligence
  • Cloud and AI
  • Commercial business
  • Consumer business
  • Security
  • Experience + Devices
  • Customer and partner solutions
  • Gaming
  • LinkedIn
  • Corporate, External, & Legal Affairs (CELA)
  • Finance
  • Human resources
  • Business development and corporate strategy
  • Marketing

Enterprise risk

  • Identify, assess, and prioritize risk to strategy
  • Senior leadership accountability and mitigation quality
  • Enable board risk governance

Microsoft’s security standards are published on an annual basis, establishing explicit requirements for risk entry, scoring, and mitigation. Adherence to these standards is mandatory for all teams, ensuring uniformity and accountability across the organization. The standards are subject to periodic revision in response to evolving threats, regulatory developments, and historical incident analysis.

The CISO GRC team synthesizes risk intelligence into a semi-annual enterprise risk management (ERM) report. The report is disseminated to senior leadership and the audit committee, elevating cybersecurity risk management from operational domains to the highest levels of organizational oversight.

Microsoft also defines and tracks key risk management metrics to measure and evaluate the effectiveness of its cybersecurity risk management program, providing visibility into risk posture over time and enabling informed decision making as part of governance and reporting processes.

A lifecycle approach to risk management

Microsoft’s risk management lifecycle is organized into four principal stages: identification, assessment, mitigation and remediation, and prevention and monitoring. Each stage is designed to ensure that risks are logged, actively managed, tracked, and validated.

Risk identification draws on a range of inputs, including threat intelligence, penetration testing, post-incident reviews, security research reports, red team exercises, and internal assessments. Risks are also surfaced through self-identification by teams, findings from defense operations, and structured self-assessments, such as the annual NIST Cybersecurity Framework (CSF) maturity review. The process is designed to be inclusive, allowing any employee or vendor with appropriate access to submit risks into a centralized system. This multifaceted approach aims to provide a comprehensive view of the threat landscape.

Upon identification, risks are entered into a centralized risk register, which provides early visibility and facilitates prompt action. The system is designed to be inclusive, permitting any employee or vendor with corporate access to submit risks. This democratized process reflects Microsoft’s commitment to broad-based risk identification across the organization.

Risk assessment is conducted by specialized teams employing structured methodologies, including impact and likelihood scoring, root cause analysis, and contextual evaluation informed by both internal signals and external intelligence. Assessment methodologies align with enterprise risk management practices and incorporate factors such as impact, likelihood, and management action and control opportunities to determine overall risk prioritization. Curators, who are Microsoft domain experts with risk management training, triage and assign risks to the appropriate DCISO area, thereby ensuring consistency and objectivity across all domains.

Risk mitigation and remediation strategies are tailored to the specific characteristics of each risk. Mitigation efforts may be prioritized and driven at an enterprise level through initiatives such as the Secure Future Initiative (SFI), or managed within specific organizational domains depending on scope and impact. These may involve deploying new controls, process adjustments, or implementation of technological solutions. Each risk is assigned an owner who is accountable for executing the mitigation plan and validating its effectiveness. Progress is monitored through workflow systems, and validation steps are employed to confirm the sustained efficacy of mitigations. Following mitigation, outcomes may inform updates to Microsoft security standards to strengthen systemic controls and prevent recurrence.

Prevention and monitoring constitute ongoing activities. Insights derived from mitigation efforts are also used to inform improvements delivered to customers, including secure-by-default configurations, product controls, and published guidance. Microsoft utilizes regression prevention techniques, continuous monitoring tools, and assurance systems to ensure the durability of mitigations over time. Insights derived from these activities are reintegrated into the identification process, thereby establishing a continuous improvement loop that is essential for maintaining resilience in a dynamic threat environment.

A graphic showing different aspects of the four stages of the cybersecurity risk management lifecycle.
The four stages of the cybersecurity risk management lifecycle include identification, assessment, remediation, and prevention and monitoring.

The risk register: Centralized oversight

The cybersecurity risk register functions as the central repository for Microsoft’s risk management program.

The workflow for risk management within the register encompasses seven defined stages: submission, triage, response, confirmation, information sharing, mitigation, and archiving. Each stage is governed by explicit service-level agreements to ensure accountability.

Risks are required to be triaged and scored within a specific timeframe following submission, and mitigation plans must be developed within a defined period after prioritization. Risk owners are required to provide regular, ongoing updates on the process of mitigation activities.

To support this workflow, roles within the risk register are clearly delineated:

  • Risk Submitter: Responsible for providing comprehensive descriptions and supporting documentation for identified risks
  • Risk Curator: Charged with validating, prioritizing, and assigning risks to appropriate domains
  • Risk Owner: Accountable for implementing and monitoring mitigation plans
  • Risk Viewer: Individuals such as auditors and senior leaders who access risk data for oversight and compliance purposes

In addition to these roles, DCISOs provide domain-level oversight and accountability for risks, including prioritization, acceptance, and escalation to enterprise governance structures.

Risk Submitter

The Risk Submitter is an individual, FTE or vendor who enters a new or existing risk into the Risk Register. Anyone with corp access can submit a risk, including Microsoft security experts. Responsible for submitting a clear, detailed, and understandable title, description, and supporting information for a risk.

Risk Curator

Delegated to take action by their DCISO, these are engineers, architects or analysts with respective domain knowledge and context who are responsible for triaging and prioritizing submitted security risks, ensuring the right DCISO area ownership alignment, identifying ownership, and tracking remediation.

Risk owner

The Risk Owner is an FTE, typically in a DCISO’s scope, that is responsible for updating mitigation status of a prioritized risk. This accountability continues until all mitigations are complete and the risk is deprioritized or archived.

Risk Viewer

The Risk Viewer is an FTE who requires read-only access to risk data to fulfill a business or compliance obligation. Where possible, their access is limited to PBI reports instead of direct access to the Risk Register itself.

Risks are reviewed on a quarterly basis, and prioritized lists are communicated to leadership to inform strategic decision making. The centralized risk register enables prioritized risks to be surfaced and reported to the CISO function and Enterprise Risk Management (ERM), supporting enterprise-level visibility and oversight. These prioritized risks inform the Secure Future Initiative (SFI), which drives systemic change across Microsoft.

Regulatory compliance integration

Microsoft’s cybersecurity risk management program is aligned with global regulatory frameworks, including ISO 27001, NIST SP 800-53, and the NIST Cybersecurity Framework, and is continuously updated to incorporate emerging requirements such as DORA and NIS2. These regulatory baselines inform both control implementation and risk evaluation, ensuring alignment between compliance requirements and operational risk management activities.

DCISOs are responsible for regulatory implementation and compliance within their respective domains. This encompasses oversight of regulated sectors such as healthcare, legal, and government, as well as emerging domains including artificial intelligence safety and privacy. The Cybersecurity Governance Council conducts regular reviews of regulatory risks and ensures that mitigation strategies are aligned with statutory and legal obligations.

A graphic showing details about how cybersecurity risk management at Microsoft is integrated with our enterprise risk management process.
Our cybersecurity risk identification and risk assessment and remediation practices are aligned with and connected to our enterprise risk management reporting system.

ERM reporting integrates cybersecurity risks alongside financial and operational risks, thereby ensuring that regulatory compliance is embedded across the organization’s overall broader risk posture. This integrated approach enables Microsoft to respond expeditiously to regulatory changes and maintain trust with customers, partners, and regulatory authorities.

What makes Microsoft’s approach unique

The scale and complexity of Microsoft necessitate a risk management methodology that is both rigorous and adaptable. Several practices distinguish Microsoft’s program from industry counterparts.

The Secure Future Initiative (SFI) establishes a structured mechanism for driving systemic change, prioritizing critical risks and aligning mitigation efforts across engineering, operations, and executive leadership. While not all risks are represented within SFI, the initiative functions as a strategic accelerator, publicly articulating the prioritized risks and corresponding mitigation efforts that drive enterprise-wide improvements.

The culture of risk awareness is embedded throughout the organization. Risk identification is actively encouraged, and submissions are evaluated irrespective of origin, reflecting a commitment to democratized and proactive risk reporting. Internally, Microsoft advocates for a culture that celebrates the identification of risks and enables proactive reporting.

The governance cadence is highly disciplined; the Cybersecurity Governance Council convenes twice weekly, and DCISOs conduct reviews and confirm top risks every 90 days. These structured intervals ensure that risk management remains proactive, with clear accountability and continuous oversight.

The integration of operational and enterprise risk is seamless. The CISO GRC team synthesizes risk intelligence from across the organization and presents it in a unified ERM report, ensuring that cybersecurity risks are incorporated into strategic decision making, rather than isolated within technical silos.

Finally, Microsoft’s control ecosystem reinforces the durability of risk mitigation. Initiatives like the Secure Development Lifecycle (SDL), exception governance processes, and SFI collectively ensure that mitigations are implemented and sustained over time.

A blueprint for security leadership

Microsoft’s cybersecurity risk management program is a model of maturity, scalability, and transparency. The program integrates structured governance, rigorous processes controls, and a culture of accountability to ensure that risks are systematically identified, mitigated, and subject to continuous monitoring and improvement. For cybersecurity leaders seeking to understand risk management at scale, Microsoft offers a compelling blueprint: a proactive, integrated, and transparent framework that combines structured governance, rigorous process controls, and a culture of accountability.

Ultimately, cybersecurity risk management is not solely dependent on technical controls and frameworks; it is fundamentally about empowering individuals, building trust across teams, and connecting operational rigor with strategic clarity. If you are developing or refining your program, prioritize both structural and cultural elements, and build resilient processes around engaged teams. Security leadership presents significant challenges, but with the appropriate structure, culture, and rhythm, it can drive transformative outcomes.

Key takeaways

This article is not solely an account of Microsoft’s practices; it is a call to action for security leaders. If you are responsible for cybersecurity in your organization, here are five practical takeaways you can implement—regardless of your company’s size or industry:

  • Establish a structured governance cadence. Implement a regular schedule for risk management activities. While Microsoft’s Cybersecurity Governance Council convenes twice weekly, the essential principle is consistency. Monthly risk reviews and quarterly board updates can ensure sustained visibility and actionable oversight of cybersecurity risks.
  • Enable accessible risk reporting. Facilitate open channels for risk submission, allowing all stakeholders to contribute to risk identification. Democratizing risk reporting fosters transparency and organizational trust.
  • Integrate operational risk with strategic oversight. Elevate operational risks to enterprise-level reporting to ensure their inclusion in strategic decision making. Collaboration between security and enterprise risk teams is critical for comprehensive oversight. Risks that stay buried in technical teams rarely get the attention they deserve.
  • Implement structured risk lifecycle processes. Define clear roles, responsibilities, and timelines for each stage of the risk management lifecycle. Even in smaller organizations, a simplified version of this model can enhance accountability and progress tracking.
  • Proactively align with regulatory expectations. Maintain alignment with relevant standards and regulations, such as NIST, ISO, DORA, and NIS2. Regularly review emerging regulation requirements and collaborate with legal and compliance teams to ensure readiness.

Try it out

Related links

The post How we approach cybersecurity risk management at Microsoft appeared first on Inside Track Blog.

]]>
24461
Microsoft CISO advice: Governing security at scale with Security Development Lifecycle http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-governing-security-at-scale-with-security-development-lifecycle/ Thu, 18 Jun 2026 15:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24347 Microsoft first mandated use of Security Development Lifecycle (SDL) in 2004. Now, SDL underpins our Secure Future Initiative (SFI) and supports SFI’s goals of secure by design, secure by default, and secure operations.​​ The SDL is a proven, adaptable approach we apply to building secure products and services. In this video, Tony Rice, principal security […]

The post Microsoft CISO advice: Governing security at scale with Security Development Lifecycle appeared first on Inside Track Blog.

]]>
Microsoft first mandated use of Security Development Lifecycle (SDL) in 2004. Now, SDL underpins our Secure Future Initiative (SFI) and supports SFI’s goals of secure by design, secure by default, and secure operations.​​ The SDL is a proven, adaptable approach we apply to building secure products and services.

In this video, Tony Rice, principal security program manager in the Office of the CISO, discusses the teams and organizational systems that help define and adapt security requirements that are applied across the enterprise. You’ll hear about how teams work together to embed security into engineering workflows and scale assurance through automation, secure defaults, and data driven KPIs. We seek to continuously monitor and improve security by applying both automated controls and use of human-driven security reviews.

“This isn’t just about ticking boxes. It’s about making sure that security is embedded in every stage of development and operation,” says Rice.

Watch this video to hear Tony Rice describe how Microsoft uses governance and automation to apply its Secure Development Lifecycle (SDL) at enterprise-level scale. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=oyciotF-qGA.)

Key takeaways

Here are some practices to socialize in your organization as you seek ways to embed “security first” thinking in your organization:

  • Inventory, deeply and regularly. Create and review regularly an accurate, complete and categorized inventory of development assets at your company. This practice provides the foundation for automation without knowing what we have.
  • Invest in scaling assurance functions. Having security policies is not enough. It takes time, attention, and effort to define processes and build technical control automation.
  • Shift left. “Shifting left” means not waiting until a service or feature is nearly done to consider security requirements. Consider ways to integrate meeting security requirements in the work developers do every day.
  • Have humans review. Prioritize human-driven security reviews on the ​businesses most critical scenarios and assets.
  • Measure your organizational progress. The best way to know if you are succeeding is to measure your progress against your organization’s security requirements. Incremental improvements in measurement and remediation drives real security outcomes.

Try it out

Related links

The post Microsoft CISO advice: Governing security at scale with Security Development Lifecycle appeared first on Inside Track Blog.

]]>
24347
Microsoft CISO advice: Securing AI with full stack red teaming http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-securing-ai-with-full-stack-red-teaming/ Thu, 04 Jun 2026 15:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23971 At Microsoft, we approach security for AI systems holistically using a full stack red teaming that goes beyond just testing an AI model. Corporate Vice President of red teaming at Microsoft Craig Nelson describes what he looks for with this method, “I’m interested in the model, but I’m also interested in how that model connects […]

The post Microsoft CISO advice: Securing AI with full stack red teaming appeared first on Inside Track Blog.

]]>
At Microsoft, we approach security for AI systems holistically using a full stack red teaming that goes beyond just testing an AI model.

Corporate Vice President of red teaming at Microsoft Craig Nelson describes what he looks for with this method, “I’m interested in the model, but I’m also interested in how that model connects with underlying additional data. And then how that model also executes automation from the back end.”

In this video, Nelson explains why securing AI requires more than testing the model alone.

Watch this video to see Craig Nelson describe how Microsoft approaches full stack red teaming. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=68MmP084rXA.)

Key takeaways

When you apply full stack red teaming to AI, here are some key questions to answer:

  • How are AI models connecting to data sources?
  • What backend automation do we allow AI to execute?
  • What security credentials do we require?
  • Do we have logs you need to understand how the model works with our backend infrastructure?

The post Microsoft CISO advice: Securing AI with full stack red teaming appeared first on Inside Track Blog.

]]>
23971
Microsoft CISO advice: Consider the risks of early integration with mergers and acquisitions http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-consider-the-risks-of-early-integration-with-mergers-and-acquisitions/ Thu, 14 May 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23592 When considering mergers and acquisitions (M&A), security needs to be an important part of the financial and operational due diligence process. At Microsoft, the security organization does more than fulfill the traditional role of assessing risk. It seeks also to address questions about the speed and costs of integrating new resources and capabilities. Geoff Belknap, […]

The post Microsoft CISO advice: Consider the risks of early integration with mergers and acquisitions appeared first on Inside Track Blog.

]]>
When considering mergers and acquisitions (M&A), security needs to be an important part of the financial and operational due diligence process. At Microsoft, the security organization does more than fulfill the traditional role of assessing risk. It seeks also to address questions about the speed and costs of integrating new resources and capabilities.

Geoff Belknap, CVP and operating CISO shares the questions he asks when considering when and how to integrate technologies with a merged or acquired company.

Watch this video to see Geoff Belknap share questions about integration with M&A. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=mrE2FSXZ-ss.)

Key takeaways

Think about moving slowly with early integration with M&A. Here are some key questions to consider:

  • What do we risk by combining tools or technical capabilities too quickly?
  • Is the deal still valuable if we do not integrate systems?
  • What operational safeguards and governance are needed?

The post Microsoft CISO advice: Consider the risks of early integration with mergers and acquisitions appeared first on Inside Track Blog.

]]>
23592
Microsoft CISO advice: Apply engineering fundamentals to securing AI http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-apply-engineering-fundamentals-to-securing-ai/ Thu, 30 Apr 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23334 Agentic AI, like any software, is just one part of a business solution. It is not the only element that needs to be secured. Engineers need to approach securing agentic AI in the corporate IT ecosystem the same way they would consider any security problem—from end to end. Yonatan Zunger, CVP and deputy CISO for […]

The post Microsoft CISO advice: Apply engineering fundamentals to securing AI appeared first on Inside Track Blog.

]]>
Agentic AI, like any software, is just one part of a business solution. It is not the only element that needs to be secured. Engineers need to approach securing agentic AI in the corporate IT ecosystem the same way they would consider any security problem—from end to end.

Yonatan Zunger, CVP and deputy CISO for Microsoft, suggests focusing exclusively on hardening a piece of software to security threats may make it difficult to use and introduce a new risk when users get frustrated and try to bypass controls. This is why engineers need to consider not just individual components but how they work together to maintain productivity.

“Think of every system as a socio-technical system containing many parts, and all of them working together in unison have to be secured,” Zunger says.

Watch this video to see Yonatan Zunger explain why engineering fundamentals are critical to building resilient AI systems. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=YU-8lpwPtm0 )

The post Microsoft CISO advice: Apply engineering fundamentals to securing AI appeared first on Inside Track Blog.

]]>
23334
Microsoft CISO advice: How to build trustworthy agentic AI http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-how-to-build-trustworthy-agentic-ai/ Thu, 16 Apr 2026 15:15:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23173 Building production-ready solutions with agentic AI comes with inherent risks. When agents make mistakes or hallucinate, the potential impacts can multiply rapidly. “It turns out that it’s very easy to write AI-powered software, but it’s very hard to write AI-powered software that works right in real-world cases,” says Yonatan Zunger, CVP and deputy CISO for […]

The post Microsoft CISO advice: How to build trustworthy agentic AI appeared first on Inside Track Blog.

]]>
Building production-ready solutions with agentic AI comes with inherent risks. When agents make mistakes or hallucinate, the potential impacts can multiply rapidly.

“It turns out that it’s very easy to write AI-powered software, but it’s very hard to write AI-powered software that works right in real-world cases,” says Yonatan Zunger, CVP and deputy CISO for Microsoft.

Yunger explains how important it is to test if you want to build trustworthy agentic AI.

Watch this video to see Yonatan Zunger explain how to build trustworthy agentic AI. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=eNU7c48541M)

Key takeaways

Here are best practices to apply while building trustworthy agentic AI:

  • Prototype. Test. Iterate. Think of and try prompts your real users might give your agentic AI. Use real data. From those trials, build a set of test cases and keep testing.
  • Use AI tools to amplify testing. Evaluating agents requires a “try it and repeat it” mindset. Using AI Foundry with such tools as Python Risk Identification Tool amplifies these assessment capabilities.
  • Record your tests. Applying this practice, as you would with unit testing, enables you to repeat evaluations as your data models and agents evolve.
  • Don’t skimp on testing. Test early, test often, test with real data. This is the best way to understand what your agent might do when it encounters the unexpected.

The post Microsoft CISO advice: How to build trustworthy agentic AI appeared first on Inside Track Blog.

]]>
23173
Microsoft CISO advice: The importance of a written AI safety plan http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-the-importance-of-a-written-ai-safety-plan/ Thu, 09 Apr 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23016 Yonatan Zunger, CVP and Deputy CISO for Microsoft, has spent his career considering complex questions with security and privacy while building platform infrastructure and solutions. His experience underpins his advice on how to build a safety plan for working with AI. First and foremost, his advice is to have a written plan. “Make it an […]

The post Microsoft CISO advice: The importance of a written AI safety plan appeared first on Inside Track Blog.

]]>
Yonatan Zunger, CVP and Deputy CISO for Microsoft, has spent his career considering complex questions with security and privacy while building platform infrastructure and solutions. His experience underpins his advice on how to build a safety plan for working with AI. First and foremost, his advice is to have a written plan.

“Make it an expectation in your organization that people will create safety plans and have them for everything,” Zunger says. “People get so excited about having clarity in front of them that they end up making much more systematic, careful plans, and the rate of errors goes down dramatically.”

Watch this video to see Yonatan Zunger discuss his advice for creating an AI safety plan. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=H5reZ0uw0EA

Key takeaways

Here are questions and ideas to consider as you create a safety plan for your AI systems:

  • Define the problem. What problem are you trying to solve? A simple and clear problem statement is always a great starting point before building anything, including an AI agent.
  • Outline the solution. What is the basis of your solution? Can you explain your solution to an end user? What does a developer or administrative user of your solution need to know about what it is and does?
  • List the things that can go wrong. What can go wrong with your solution? Creating this list is the first step to figuring out how to deal with those issues.
  • Document your plan. What is your plan to address identified concerns? Identify the process you will follow when something goes wrong.
  • Draft your plan early and update it as your solution matures. Your safety plan can be as simple as a list or outline and should evolve as you prepare to build your solution.
  • Get feedback and buy-in. When you review the plan with stakeholders and leaders in your team and organization, you may uncover risks or issues you had not thought of. You also build awareness and agreement on what to do when something goes wrong.
  • Make a template and build its use into your processes. This tip is for anyone who leads a team or influences process development. Encourage using a safety template in all your projects to bring clarity and structure to how you work with AI.

The post Microsoft CISO advice: The importance of a written AI safety plan appeared first on Inside Track Blog.

]]>
23016
Microsoft CISO advice: The most important thing to know about securing AI http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-the-most-important-thing-to-know-about-securing-ai/ Thu, 02 Apr 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=22863 Using AI comes with inherent risks. In a recent video, Yonatan Zunger, CVP and deputy CISO for Microsoft, suggests thinking about AI as a new intern will help you naturally take the right approach to AI security.  Zunger and his team focus on AI safety and security. They consider all the different ways anything involving […]

The post Microsoft CISO advice: The most important thing to know about securing AI appeared first on Inside Track Blog.

]]>
Using AI comes with inherent risks. In a recent video, Yonatan Zunger, CVP and deputy CISO for Microsoft, suggests thinking about AI as a new intern will help you naturally take the right approach to AI security. 

Zunger and his team focus on AI safety and security. They consider all the different ways anything involving working with AI can go wrong.

“An important thing to know about AI is that AI’s make mistakes,” Zunger says. “You already know how to work with systems that make mistakes, get tricked.”

Watch this video to see Yonatan Zunger discuss his advice for working with AI. (For a transcript, please view the video on YouTube: https://youtu.be/b1x6gDbSWVY. )

The post Microsoft CISO advice: The most important thing to know about securing AI appeared first on Inside Track Blog.

]]>
22863