Jim Langevin’s Post

View profile for Jim Langevin

Former United States Congressman

My entire career, I’ve worked to make government cybersecurity more transparent and accessible. I’ve continued this work at Rhode Island College by promoting consistent collaboration between the private and public sectors.   Microsoft’s Windows Endpoint Security Ecosystem Summit, happening today, is a critical moment for the broader cyber ecosystem. I’m glad to see that Microsoft will convene this meeting to discuss pressing security issues facing individuals, small businesses, large companies, and government agencies.   However, Microsoft will hold this summit behind closed doors, without input from the public or media access. While the summit is an important conversation to hold, Microsoft should consider holding an open forum to discuss emerging cyber issues and recent incidents, including last summer’s China hack and the recent global outage. Our collective national security depends on Microsoft’s ability to build secure systems and take accountability when something does go wrong.

Chris H.

CEO @ Aquia | Chief Security Advisor @ Endor Labs | 2x Author | Veteran | Advisor

6mo

Jim Langevin thank you for your continued efforts and calls for more transparency as well!

Thanks for your Congressional work and for continuing your efforts!

Like
Reply
Bill Radford

Solutions Architect at Cisco

6mo

Opening this up would be a great benefit. The open armed embrace of AI (not just by MS but all security vendors) is both a benefit and a significant threat. I would be very interested in the discussion focused around AI threats (specifically in endpoint security)

Lance Lorenz

Senior Federal Program Manager

6mo

Spot on, Jim!

Like
Reply

If the State Dept contacted and alerted MSFT about STORM-0558 breach as cited/reported, what makes you think MSFT had any visibility and understanding of what actually happened? Last I checked — no verified CTI/TTPs in ATT&CK. MSFT new SbD, Secure Future initiative in some ways is an admission that their software security practices needed to be modernized. Perhaps this is their way of being accountable to improve their cybersecurity. I’m not sure I buy it, but that could be a response to industry.

Like
Reply
See more comments

To view or add a comment, sign in

Explore topics