Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s Secure Future Initiative (SFI) pairs company-wide security training and employee performance expectations with a Deputy CISO-led Cybersecurity Governance Council and senior-leadership oversight. Microsoft has reported high course-completion figures, but those company-reported numbers do not by themselves prove a lasting culture change or show that these measures alone caused better security.

What Microsoft’s security culture reboot involves

Microsoft launched SFI in November 2023 as a multiyear effort to improve how it designs, builds, tests, and operates products and services. In May 2024, the company expanded the initiative around six security pillars. Microsoft describes SFI as an evolving, cross-company program organized in waves and connected to Zero Trust principles and the NIST Cybersecurity Framework.

The governance council and training are therefore parts of a broader operating model, not standalone programs. Microsoft’s SFI overview on Microsoft Learn describes that wider framework.

How the Cybersecurity Governance Council works

Microsoft publicly described its Cybersecurity Governance Council on September 23, 2024. Led by CISO Igor Tsyganskiy, it brings together Deputy CISOs aligned to key security functions and engineering divisions. Their remit includes cyber risk, defense, and compliance. Microsoft said the structure is intended to consolidate risk visibility and accountability across the company.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The council sits within a wider oversight structure: senior leaders review SFI progress weekly, and Microsoft provides quarterly progress updates to its Board. The company also said senior leadership security performance is tied to compensation. These mechanisms set reporting and accountability expectations; the announcement does not establish how independently their effectiveness is assessed.

What security training and employee accountability mean

In 2024, Microsoft made Security a Core Priority for employees and said it would be included in performance reviews. The company also described a worldwide Security Skilling Academy offering curated training. In the announcement, Executive Vice President of Microsoft Security Charlie Bell stated, “Security is now a core priority for all employees at Microsoft and will be included in their performance reviews.”

Rank #2
Sale
Black Books EBB3INCH Engineers Black Book 3rd Edition (1 per Pack)
  • Matt-laminated and greaseproof pages ensure glare-free reading and long life
  • The outside covers are made from a new rubberized material for better Handling and Grip
  • All the Tool Holder Identification Sections now include a full INCH section along with a METRIC section
  • Updated and Improved Index Searching

Microsoft has published training figures at different times, with different wording and populations. They should be read as dated company reports rather than as one continuous, directly comparable metric.

Report date What Microsoft reported How to interpret it
April 21, 2025 50,000 Security Skilling Academy participants; 99% completion of the Security Foundations and Trust Code courses; and completed risk inventories and prioritization by all 14 Deputy CISOs. The 99% figure refers to employees completing the two named courses; the report does not specify full-time employees for that figure. The Academy participation number and Deputy CISO figure are separate measures.
July 10, 2026 More than 99% of full-time employees had completed mandatory Trust Code training. This later figure is specifically for full-time employees and mandatory Trust Code training. It is not the same measure as the 2025 figure covering two courses and a differently specified population.

Both updates are Microsoft’s own reporting: the April 2025 SFI progress announcement and the July 2026 progress announcement. The 2026 announcement’s author, Microsoft Cloud Security Corporate Vice President Salim Chawro, wrote, “Security is never finished.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the reported progress does—and does not—show

The figures indicate that Microsoft reported broad participation or completion for the stated training measures, alongside a defined Deputy CISO risk-inventory process. They do not establish, on their own, how much employee behavior changed, whether the measures were independently audited, or whether these culture and governance steps caused improvements in security outcomes. The July 2026 report also cites 99.97% phishing-resistant MFA coverage of user/device pairs, but that is a technical-control measure—not a training or culture metric.

For context on the initiative’s origin and scope, Microsoft’s Learn documentation describes SFI’s six-pillar structure, while the September 2024 announcement sets out the council, employee priority, and leadership oversight. Taken together, the announcements show the mechanisms Microsoft says it has put in place and the progress it has reported—not independent verification that the company’s security culture has permanently changed.

Quick Recap

SaleBestseller No. 2
Black Books EBB3INCH Engineers Black Book 3rd Edition (1 per Pack)
Black Books EBB3INCH Engineers Black Book 3rd Edition (1 per Pack)
Matt-laminated and greaseproof pages ensure glare-free reading and long life; The outside covers are made from a new rubberized material for better Handling and Grip
$33.99
SaleBestseller No. 4

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.