logo

Dozens of tech companies pledge to build safer, more secure tech

ID: eb5fc8a8-f731-5786-b949-693cb366a05a

STIX ID: report--eb5fc8a8-f731-5786-b949-693cb366a05a

Feed Name: CyberScoop

Date Published: 2024-05-09

Date Updated: 2026-04-21

Author: mbracken

...
...

CISA announced a voluntary Secure by Design pledge at the RSA Conference, with over 60 major technology firms (including Google, Microsoft, Cisco, IBM, and AWS) committing to strengthen default security (e.g., MFA and phishing-resistant auth), reduce hardcoded/default passwords and common vulnerabilities, improve patch adoption, enhance vulnerability disclosure processes, and expand logging for better breach detection. The push follows scrutiny of limited logging in commercial offerings highlighted by the Microsoft Storm-0558 incident, and includes calls to address cloud log retention gaps. While some skepticism remains due to its voluntary nature, CISA plans to measure progress over the next year to foster a more durable security culture.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.