Senior reporter at @CyberSecDive covering all things digital security. I also co-host @hothtakes. | Send me tips: ericjgeller.com/contact.html

Washington, D.C.
Last week, I visited Microsoft's headquarters and talked to senior leaders about how the company has tried to turn a corner on cybersecurity. Here's my story about what's working, what remains challenging, and, of course, how AI factors into everything: cybersecuritydive.com/news/m…
2
5
31
12,156
The FBI is investigating what appears to be a serious hack of its jobs portal by the cybercrime group ShinyHunters that may have exposed FBI agents' and applicants' sensitive personal data, sparking fears of an intelligence bonanza for foreign adversaries. cybersecuritydive.com/news/f…
14
23
2,592
CISA wants to hire infrastructure security experts who can work broadly across sectors, rather than people specializing in certain sectors, acting CISA Director Nick Andersen told reporters today at Google's Cyber Defense Summit. My story: cybersecuritydive.com/news/c…
2
7
12
2,238
Andersen also dodged my question about whether (and if so, when) CISA would comply with a congressional requirement to restore funding to the EI-ISAC. CISA's foot-dragging prompted a letter earlier this month from @SenAlexPadilla and @RepJoeMorelle. padilla.senate.gov/wp-conten…
1
3
729
But Andersen also said that CISA was getting ready — "probably in the next couple of days" — to formally announce its election security plan for the midterms, which will detail the services and other assistance that the cyber agency will prove to state & local election officials.
477
ICYMI: I recently met with Microsoft leaders at the company's HQ and learned about how the tech giant is working to repair its software (and its public image) after years of embarrassing hacks.
Last week, I visited Microsoft's headquarters and talked to senior leaders about how the company has tried to turn a corner on cybersecurity. Here's my story about what's working, what remains challenging, and, of course, how AI factors into everything: cybersecuritydive.com/news/m…
1
2
8
2,313
ICYMI: My story about how Microsoft is rethinking security. "The changes they’ve made so far are valuable and will help Microsoft products be more secure," one analyst said. "However, these changes need to remain embedded and improve over time to truly have a long-term impact."
Last week, I visited Microsoft's headquarters and talked to senior leaders about how the company has tried to turn a corner on cybersecurity. Here's my story about what's working, what remains challenging, and, of course, how AI factors into everything: cybersecuritydive.com/news/m…
2
2,065
Resharing this story. There's a table in here with some interesting stats from Microsoft's Secure Future Initiative progress reports.
Last week, I visited Microsoft's headquarters and talked to senior leaders about how the company has tried to turn a corner on cybersecurity. Here's my story about what's working, what remains challenging, and, of course, how AI factors into everything: cybersecuritydive.com/news/m…
2
12
2,442
Just another plug for my new story about Microsoft's attempt to reinvent its security culture. "We’re shifting left in terms of critical areas where I must have a security engineer sign off at the design time," the head of Windows Security told me.
Last week, I visited Microsoft's headquarters and talked to senior leaders about how the company has tried to turn a corner on cybersecurity. Here's my story about what's working, what remains challenging, and, of course, how AI factors into everything: cybersecuritydive.com/news/m…
1
2,005
Last week, I visited Microsoft's headquarters and talked to senior leaders about how the company has tried to turn a corner on cybersecurity. Here's my story about what's working, what remains challenging, and, of course, how AI factors into everything: cybersecuritydive.com/news/m…
2
5
31
12,156
Microsoft is constantly trying to balance better default security with easy user experience. Company leaders acknowledged that this balancing act wasn't easy but pointed to Azure MFA as an example of how to achieve it. And not every org needs every feature on by default.
1
1
460