Secure Future Initiative – Secure by Design | Microsoft (original) (raw)

This is the Trace Id: 829e8e75dbee59699dede5a63f0b1f68

Security above all else

Read the November 2025 progress report as part of this multiyear journey to bolster cybersecurity and explore actionable guidance from the Secure Future Initiative (SFI).

 A group of people talking to eachother.

Three principles anchor our approach to the SFI. We’re continuously applying what we’ve learned from incidents to improve our methods and practices, ensuring that security is paramount in everything we create and provide.

Secure by design

Security comes first when designing any product or service.

Secure by default

Security protections are enabled and enforced by default, require no extra effort, and aren’t optional.

Secure operations

Security controls and monitoring will be continuously improved to meet current and future cyberthreats.

Foundations of the Secure Future Initiative

Successful business operations and change management are predicated on people, process, and technology working in harmony. These are the foundations of the SFI.

Security-first culture

Culture is reinforced through daily behaviors. Regular meetings between engineering executive vice presidents, SFI leaders, and all management levels ensure bottom-up, end-to-end problem-solving that ingrains security thinking into our everyday actions.

Security governance

We're elevating security governance with a new framework led by the chief information security officer. This will introduce a partnership with engineering teams to oversee SFI, manage risks, and report progress to leadership.

Continuous security improvement

The SFI empowers every employee at Microsoft to prioritize security, driven by a growth mindset of continuous improvement. We integrate feedback and learnings from incidents into our standards, enabling secure design and operations at scale.

Paved paths and standards

Paved paths are best practices that optimize productivity, compliance, and security. These become standards when they enhance security or the developer experience. With the SFI, we set and measure standards across all six prioritized security pillars.

Secure Future Initiative pillars

The six SFI pillars include goals and actions that define our approach to security.

See the highlights

View the most recent highlights in our November report.

35K

Equivalent of full-time Microsoft engineers dedicated to security

17+

Product innovations across Microsoft Azure, Microsoft 365, Windows, Surface, and the Microsoft Security portfolio

NIST CSF

Introduced mapping to the NIST CSF to help customers understand our progress using a recognized industry framework

Actionable guidance grounded in real-world security

Scale securely following SFI patterns and practices based on Microsoft’s tested security insights—what worked, what changed, and what we learned.

Two persons looking into laptop screen and takliking to each ohter.

Constrain failure with threat modeling for AI systems

Approach threat modeling for AI systems as an ongoing engineering mindset rather than a one-time checklist.

A woman holding a phone infront of her laptop

Take a layered approach to defense in depth for agents

This case study shares the top risks of agents and what the layers of the "layered approach" actually are.

Two women sitting besides each other and working on their laptops

Secure your agentic systems

Reduce risk without stalling innovation.

Frequently asked questions

Explore Secure Future Initiative resources

Keep up with the latest SFI information.

Laptop screen shows “Secure Future Initiative, November 2025 progress report.

Explore our progress

Read what Charlie Bell has to say about the latest SFI report (November 2025), which discusses our advancements in this multiyear journey to bolster cybersecurity for Microsoft, our customers, and the industry at large.

Graphical text of secure future initiative

Explore the November 2025 SFI Progress Report

Explore highlights from our November 2025 SFI Progress Report online, with links to each section of the full report so you can get the details you want.

Person with long dark hair in a sleeveless top standing outside a modern glass building with greenery.

Microsoft Secure Future Initiative patterns and practices

Strengthen your organization's security with guidance that uses proven security architectures and best practices.

IDC logo

Learn from IDC highlights on SFI in action

Explore IDC’s view on SFI and the changes needed by organizations preparing for the future of cybersecurity.

A blue gradient banner with the text 'Secure by Design' and 'Secure Future Initiative'.

See where we were in April

Read the April 2025 SFI Progress Report which discusses our advancements in this multiyear journey to bolster cybersecurity for Microsoft, our customers, and the industry at large.

A graphical image with a person working in laptop

Deceived, not hacked

Why keeping people safe online now starts with smarter design.

A women working on the laptop

Shaping global policy for a secure future

Learn how to foster a security-first culture in AI, strengthen resilience, and reinforce accountability.

A group of people discussing and working on the laptop

Building a lasting security culture at Microsoft

Discover how building a lasting security culture is a call to action at Microsoft.

Back to carousel navigation controls