Secure Future Initiative – Secure by Design | Microsoft (original) (raw)
This is the Trace Id: 351d77fc4868a73f0f21820bce2ab86d
Security above all else
Read the November 2025 progress report as part of this multiyear journey to bolster cybersecurity and explore actionable guidance from the Secure Future Initiative (SFI).
Three principles anchor our approach to the SFI. We’re continuously applying what we’ve learned from incidents to improve our methods and practices, ensuring that security is paramount in everything we create and provide.
Secure by design
Security comes first when designing any product or service.
Secure by default
Security protections are enabled and enforced by default, require no extra effort, and aren’t optional.
Secure operations
Security controls and monitoring will be continuously improved to meet current and future cyberthreats.
Foundations of the Secure Future Initiative
Successful business operations and change management are predicated on people, process, and technology working in harmony. These are the foundations of the SFI.
Security-first culture
Culture is reinforced through daily behaviors. Regular meetings between engineering executive vice presidents, SFI leaders, and all management levels ensure bottom-up, end-to-end problem-solving that ingrains security thinking into our everyday actions.
Security governance
We're elevating security governance with a new framework led by the chief information security officer. This will introduce a partnership with engineering teams to oversee SFI, manage risks, and report progress to leadership.
Continuous security improvement
The SFI empowers every employee at Microsoft to prioritize security, driven by a growth mindset of continuous improvement. We integrate feedback and learnings from incidents into our standards, enabling secure design and operations at scale.
Paved paths and standards
Paved paths are best practices that optimize productivity, compliance, and security. These become standards when they enhance security or the developer experience. With the SFI, we set and measure standards across all six prioritized security pillars.
Secure Future Initiative pillars
The six SFI pillars include goals and actions that define our approach to security.
See the highlights
View the most recent highlights in our November report.
35K
Equivalent of full-time Microsoft engineers dedicated to security
17+
Product innovations across Microsoft Azure, Microsoft 365, Windows, Surface, and the Microsoft Security portfolio
NIST CSF
Introduced mapping to the NIST CSF to help customers understand our progress using a recognized industry framework
Actionable guidance grounded in real-world security
Scale securely following SFI patterns and practices based on Microsoft’s tested security insights—what worked, what changed, and what we learned.
Constrain failure with threat modeling for AI systems
Approach threat modeling for AI systems as an ongoing engineering mindset rather than a one-time checklist.
Take a layered approach to defense in depth for agents
This case study shares the top risks of agents and what the layers of the "layered approach" actually are.
Secure your agentic systems
Reduce risk without stalling innovation.
Frequently asked questions
- The Microsoft Secure Future Initiative, launched in November of 2023, is a multiyear commitment that advances the way we design, build, test, and operate our Microsoft technology to ensure that our solutions meet the highest possible standards for security.
- Microsoft launched the SFI to prepare for the increasing scale and high stakes of cyberattacks. SFI brings together every part of Microsoft to advance cybersecurity protection across our company and products. We carefully considered what we saw across Microsoft and what we heard from customers, governments, and partners to identify our greatest opportunities to impact the future of security. For more information on our initial announcement about SFI, see our blog post.
- We plan to keep ourselves accountable and provide the latest SFI news to customers, partners, and the security community through regular updates.
Explore Secure Future Initiative resources
Keep up with the latest SFI information.
Explore our progress
Read what Charlie Bell has to say about the latest SFI report (November 2025), which discusses our advancements in this multiyear journey to bolster cybersecurity for Microsoft, our customers, and the industry at large.
Explore the November 2025 SFI Progress Report
Explore highlights from our November 2025 SFI Progress Report online, with links to each section of the full report so you can get the details you want.
Microsoft Secure Future Initiative patterns and practices
Strengthen your organization's security with guidance that uses proven security architectures and best practices.
Learn from IDC highlights on SFI in action
Explore IDC’s view on SFI and the changes needed by organizations preparing for the future of cybersecurity.
See where we were in April
Read the April 2025 SFI Progress Report which discusses our advancements in this multiyear journey to bolster cybersecurity for Microsoft, our customers, and the industry at large.
Deceived, not hacked
Why keeping people safe online now starts with smarter design.
Shaping global policy for a secure future
Learn how to foster a security-first culture in AI, strengthen resilience, and reinforce accountability.
Building a lasting security culture at Microsoft
Discover how building a lasting security culture is a call to action at Microsoft.