Free tools Windows power users keep installed
One-click scans. No signup required.
Microsoft’s Secure Future Initiative (SFI) pairs company-wide security training and employee performance expectations with a Deputy CISO-led Cybersecurity Governance Council and senior-leadership oversight. Microsoft has reported high course-completion figures, but those company-reported numbers do not by themselves prove a lasting culture change or show that these measures alone caused better security.
What Microsoft’s security culture reboot involves
Microsoft launched SFI in November 2023 as a multiyear effort to improve how it designs, builds, tests, and operates products and services. In May 2024, the company expanded the initiative around six security pillars. Microsoft describes SFI as an evolving, cross-company program organized in waves and connected to Zero Trust principles and the NIST Cybersecurity Framework.
The governance council and training are therefore parts of a broader operating model, not standalone programs. Microsoft’s SFI overview on Microsoft Learn describes that wider framework.
How the Cybersecurity Governance Council works
Microsoft publicly described its Cybersecurity Governance Council on September 23, 2024. Led by CISO Igor Tsyganskiy, it brings together Deputy CISOs aligned to key security functions and engineering divisions. Their remit includes cyber risk, defense, and compliance. Microsoft said the structure is intended to consolidate risk visibility and accountability across the company.
#1 Best Overall
The council sits within a wider oversight structure: senior leaders review SFI progress weekly, and Microsoft provides quarterly progress updates to its Board. The company also said senior leadership security performance is tied to compensation. These mechanisms set reporting and accountability expectations; the announcement does not establish how independently their effectiveness is assessed.
What security training and employee accountability mean
In 2024, Microsoft made Security a Core Priority for employees and said it would be included in performance reviews. The company also described a worldwide Security Skilling Academy offering curated training. In the announcement, Executive Vice President of Microsoft Security Charlie Bell stated, “Security is now a core priority for all employees at Microsoft and will be included in their performance reviews.”
Rank #2
- Matt-laminated and greaseproof pages ensure glare-free reading and long life
- The outside covers are made from a new rubberized material for better Handling and Grip
- All the Tool Holder Identification Sections now include a full INCH section along with a METRIC section
- Updated and Improved Index Searching
Microsoft has published training figures at different times, with different wording and populations. They should be read as dated company reports rather than as one continuous, directly comparable metric.
| Report date | What Microsoft reported | How to interpret it |
|---|---|---|
| April 21, 2025 | 50,000 Security Skilling Academy participants; 99% completion of the Security Foundations and Trust Code courses; and completed risk inventories and prioritization by all 14 Deputy CISOs. | The 99% figure refers to employees completing the two named courses; the report does not specify full-time employees for that figure. The Academy participation number and Deputy CISO figure are separate measures. |
| July 10, 2026 | More than 99% of full-time employees had completed mandatory Trust Code training. | This later figure is specifically for full-time employees and mandatory Trust Code training. It is not the same measure as the 2025 figure covering two courses and a differently specified population. |
Both updates are Microsoft’s own reporting: the April 2025 SFI progress announcement and the July 2026 progress announcement. The 2026 announcement’s author, Microsoft Cloud Security Corporate Vice President Salim Chawro, wrote, “Security is never finished.”
Recommended Free Tools
What the reported progress does—and does not—show
The figures indicate that Microsoft reported broad participation or completion for the stated training measures, alongside a defined Deputy CISO risk-inventory process. They do not establish, on their own, how much employee behavior changed, whether the measures were independently audited, or whether these culture and governance steps caused improvements in security outcomes. The July 2026 report also cites 99.97% phishing-resistant MFA coverage of user/device pairs, but that is a technical-control measure—not a training or culture metric.
For context on the initiative’s origin and scope, Microsoft’s Learn documentation describes SFI’s six-pillar structure, while the September 2024 announcement sets out the council, employee priority, and leadership oversight. Taken together, the announcements show the mechanisms Microsoft says it has put in place and the progress it has reported—not independent verification that the company’s security culture has permanently changed.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

