Skip to content

Search the site

Microsoft CISO Igor Tsyganskiy: Our defense posture is improving

Microsoft rips out 5.75 million inactive tenants, an eye-watering 730,000 unused applications, and 440,000 "resources" managed by legacy systems across its own estate.

Microsoft CISO Igor Tsyganskiy.

Shortly after Microsoft CISO Igor Tsyganskiy took office in January 2024 it emerged that Redmond was under attack by a Russian threat group – which had spotted an insecure and exposed Microsoft “test tenant”, piggybacked from it onto another insecure application that had “elevated access to the Microsoft corporate environment,” and wreaked havoc. 

“The subsequent days are some I remember vividly” Tsyganskiy said in an update on his efforts at Microsoft, detailing his subsequent creation of a new Office of the CISO and hiring of “a number of Deputy CISOs [who] work with our major product groups and programs to drive greater depth and rigor in cybersecurity governance across the entire company…”

See also: How Russian spooks hacked Microsoft, its “morally indefensible” response, and what CISOs can learn from the attack

This post is for subscribers only

Subscribe

Already have an account? Sign In

Latest