TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft ties executive pay to security after multiple failures and breaches

186 pointsby stalfosknightabout 1 year ago

22 comments

PedroBatistaabout 1 year ago
Unfortunately most of the &quot;hard&quot; work will be metrics massaging, redefining words and covering stuff.<p>But the first phase will be a lot of &quot;security &amp; quality&quot; presentations to the troops, some hiring and ground prep-work so the blaming can be done when things go south.<p>I would like to be more positive, but I already saw this cycle too many times.<p>How about security being part of the requirements to keep a job instead of monetary bonus? and this has to be applied to the top, only then to the bottom.
评论 #40253510 未加载
评论 #40253539 未加载
评论 #40257840 未加载
评论 #40253376 未加载
stoperaticlessabout 1 year ago
A bit curious how is it worded. I wonder, will it actually improve security, or will it be metrics that are being played around actually decreasing security (e.g. Teams might stop registering&#x2F;tracking issues as a way of not having registered bugs)
评论 #40252972 未加载
titheabout 1 year ago
&quot;...its Senior Leadership Team&#x27;s pay partially dependent on whether the company is &quot;meeting our security plans and milestones,&quot; though Bell didn&#x27;t specify how much executive pay would be dependent on meeting those security goals.&quot;<p>What&#x27;s the percentage? What are the milestones?<p>Edit: The &quot;security plans and milestones&quot; appear to be here: <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;security&#x2F;blog&#x2F;2024&#x2F;05&#x2F;03&#x2F;security-above-all-else-expanding-microsofts-secure-future-initiative&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;security&#x2F;blog&#x2F;2024&#x2F;05&#x2F;03&#x2F;sec...</a>
cjk2about 1 year ago
Perhaps they should tie executive pay to customer satisfaction?<p>Security is somewhere under that umbrella. Also all the other stuff end users give a shit about that Microsoft doesn&#x27;t...
评论 #40253382 未加载
评论 #40253374 未加载
评论 #40253398 未加载
评论 #40253750 未加载
ChrisArchitectabout 1 year ago
Actual article: <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;security&#x2F;blog&#x2F;2024&#x2F;05&#x2F;03&#x2F;security-above-all-else-expanding-microsofts-secure-future-initiative&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;security&#x2F;blog&#x2F;2024&#x2F;05&#x2F;03&#x2F;sec...</a><p>(<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40249290">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40249290</a>)
评论 #40253074 未加载
评论 #40253630 未加载
dinvladabout 1 year ago
Funny how I&#x27;ve heard from an Azure employee who worked with many big clients that very few among them cared about security - the incentives were just not there.<p>Seems like they&#x27;re finally doing something about that, to set an example for the rest of the industry.
评论 #40253117 未加载
评论 #40253038 未加载
评论 #40253186 未加载
评论 #40258748 未加载
tracerbulletxabout 1 year ago
For sure will result mostly in hiding and not admitting things.
评论 #40253957 未加载
评论 #40253351 未加载
评论 #40253454 未加载
wrsabout 1 year ago
I had heard the previous overriding directive was “DO AI” so now am wondering how that combines with “DO SECURITY”.
评论 #40253143 未加载
ripvanwinkleabout 1 year ago
about time. you also need a clawback provision since it can take a while for flaws to be detected and the execs could be in new jobs by then.
exitzer0about 1 year ago
If anyone is dumb enough to trust Microsoft after all the shit they&#x27;ve pulled over the last 30+ years, including the most recent collection of large-scale security fuckups, they deserve what they get.
fsfloverabout 1 year ago
Related recent discussion: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40228212">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40228212</a>
gigel82about 1 year ago
&quot;Secure by default: Security protections are enabled and enforced by default, require no extra effort, and are not optional.&quot;.<p>Let me guess: logging in with a Microsoft Account is a security protection, as is collecting more telemetry, for security of course.
GreedIsGoodabout 1 year ago
Charlie has been at MSFT a little while now, I suspect he knows how the machine works.<p>I would expect this to result in lower feature velocity. In theory features are tied to increasing revenue. If so, I wonder if he is actually willing to make that trade off.
rawgabbitabout 1 year ago
I wonder why is Microsoft doing this now? They had blithely ignored security for many years. Their products have been insecure by default as long as I can remember.
fennecbuttabout 1 year ago
How about just fire them with no golden handshake if they don&#x27;t do a good job, just like any other employee.
WhyNotHugoabout 1 year ago
So they&#x27;re providing financial incentives to executives who don&#x27;t disclose breaches in security?<p>This is terrible.
评论 #40263482 未加载
Crontababout 1 year ago
MS might not be providing security but at least they are giving us the Copilot key and in-Windows advertising.
minisoftmicroabout 1 year ago
Nice. Looking forward to more of those security training and unskippable tests every few months.
m463about 1 year ago
I don&#x27;t know if this is play to win or play to not lose.
jauntywundrkindabout 1 year ago
This is like the Samsung managers that have to work 6 days a week. What a drain on morale.<p>Software in particular has been so lucky to have so many people able to steam ahead, break ground, make features and new products. This caring for the rest, looking at longer lifecycle &amp; maintaining... It&#x27;s not fun. It&#x27;s not inspirational. It&#x27;s not fast. It doesn&#x27;t feel productive or creative.<p>And that&#x27;s some of the next decades for this profession. An end to fun and innovation. More being yolked and driven by external demands &amp; stressors. Good luck all.
userbinatorabout 1 year ago
More excuses to justify increasing authoritarianism. I don&#x27;t think this will have any positive effect.
ein0pabout 1 year ago
Fun fact: for many years now executive (and manager) pay at Microsoft has been tied to meeting diversity quotas, and hiring straight white men when you’re under quota required exec approval: <a href="https:&#x2F;&#x2F;www.cspicenter.com&#x2F;p&#x2F;what-diversity-and-inclusion-means" rel="nofollow">https:&#x2F;&#x2F;www.cspicenter.com&#x2F;p&#x2F;what-diversity-and-inclusion-me...</a>.<p>How this particular new “tying” of one thing to another impacts the overall state of things is anyone’s guess.
评论 #40254899 未加载
评论 #40253731 未加载
评论 #40253648 未加载
评论 #40253554 未加载
评论 #40253590 未加载
评论 #40253593 未加载