Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Microsoft Tied Part of Senior Executive Incentive Pay to Security

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Microsoft’s May 2024 announcement put cybersecurity into executive compensation and moved security oversight closer to product teams. The company later formalized a distinct security category in its fiscal-year 2025 incentive plan, assigned deputy CISOs across product and business functions, and made security a performance priority for all employees. The design is more concrete than a general pledge, but public disclosures do not show individual executives’ scores or payouts—or prove that the changes reduced breach risk.

What Microsoft announced in 2024

On May 3, 2024, CEO Satya Nadella said that a portion of senior leaders’ compensation would depend on progress against security plans and milestones. At the same time, Charlie Bell, then leading Microsoft’s security work, described placing deputy CISOs within major product and functional areas. The moves were part of Microsoft’s broader Secure Future Initiative (SFI), launched in November 2023 as a multiyear security effort. Microsoft’s announcement framed security as a company-wide responsibility rather than a concern left to a central specialist team.

The announcement followed intense scrutiny of Microsoft’s security practices, including the U.S. Cyber Safety Review Board’s examination of the Storm-0558 compromise. That context helps explain the urgency, but it does not establish that a specific compensation or organizational change was caused by one incident. Microsoft’s stated approach was to pursue broader security improvements and accountability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What “part of compensation” means

Microsoft’s FY2025 executive incentive plan made Security a distinct performance category. In its proxy filing, the company assigned that category a 10% weighting for the CEO and 16.67% for named executive officers. The figures are weights within the annual cash incentive plan—not percentages of salary, total compensation, or guaranteed bonuses. The plan combined categories that had previously been separate, including Product & Strategy and Customers & Stakeholders. The SEC filing sets out the formal plan structure.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Microsoft said the assessment would consider leaders’ contributions to the SFI and include quantitative measures, qualitative judgments, progress on recommendations from the Cyber Safety Review Board, and other aspects of cybersecurity work and performance. The board also retained discretion to reduce compensation outcomes when it considered performance inadequate. Microsoft’s June 2024 explanation describes those assessment elements.

This is not a stated rule that every breach triggers an automatic pay cut. Security is difficult to evaluate with one incident count: an incident can occur despite serious preventive work, while a low count does not by itself show that risks were well managed. A meaningful assessment must consider such matters as prevention, detection, response, remediation, and whether leaders make durable improvements.

There is also a transparency limit. The public materials identify the category weights and broad evaluation factors, but do not provide a full scorecard for each executive, a threshold-and-payout table, or worked examples showing how a particular failure changes an individual’s bonus. The policy is more specific than a slogan, but outsiders cannot independently calculate an executive’s result from the published information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why put deputy CISOs inside product groups?

A centralized security organization can set standards and coordinate response, but product teams make day-to-day decisions about design, engineering, infrastructure, and release schedules. Microsoft’s deputy-CISO model aims to put security leadership closer to those decisions, so teams can identify risks during product development rather than only at a later review.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Microsoft’s profiles illustrate how varied these roles are. Mark Russinovich, Azure CTO, works on risks affecting Azure and core engineering systems. Igor Sakhnov combines identity engineering leadership with deputy-CISO responsibilities for identity-related risks. Yonatan Zunger focuses on AI-related failure modes, tools, and incident response. Other named leaders cover Business Applications, Microsoft’s security products, consumer products such as Edge and Bing, core infrastructure and mergers and acquisitions, and customer security engagement. Microsoft’s first profile series, part two, and part three describe examples of the work.

The structure can make product teams more directly responsible for risk, but it raises a governance question: some deputy CISOs also hold operating or product roles. That proximity can help security choices fit the systems being built; it can also create tension when a security concern competes with a delivery deadline. The public descriptions do not establish that every deputy CISO has independent authority to stop a release or compel resources. Clear escalation paths and authority matter as much as titles.

By April 2025, Microsoft said its Cybersecurity Governance Council included 14 deputy CISOs, spanning areas such as AI, Azure, Business Applications, Consumer, Core Systems and M&A, Identity, Gaming, Government, Microsoft Corporate, Microsoft Security, and Regulated Industries. The company reported that all 14 had completed risk inventories and prioritization for their areas. In its November 2025 SFI update, Microsoft described three additional deputy-CISO functions: supply chain and third parties; business functions, marketing, and finance; and compliance with EU cybersecurity legislation. The scope is an evolving governance arrangement, not necessarily a fixed organization chart.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security became an employee performance priority, too

The executive incentive category is not the same as the employee-wide program. Beginning in FY2025, Microsoft gave all employees a “Security Core Priority,” making cybersecurity a subject of performance reviews and manager discussions and a factor considered in annual bonus and compensation decisions. That does not mean every employee has the same security weighting or incentive formula as senior executives. Microsoft’s June update described the change.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

In its April 2025 report, Microsoft said 99% of employees had completed Security Foundations and Trust Code courses and 50,000 had participated in its Security Academy. It also reported that the deputy CISOs had completed their area risk inventories. Those figures indicate reported implementation and participation; they do not, by themselves, show whether employees changed behavior or whether specific risks were reduced.

What Microsoft reported by November 2025

Microsoft’s November 2025 SFI report presented a range of operational indicators. Among them, the company reported phishing-resistant multifactor authentication enforced for 99.6% of employees and devices; more than 98% of production infrastructure centrally tracked; nearly all production builds and 94% of release pipelines using governed templates; and 72% success in addressing vulnerabilities within its reduced time-to-mitigate target. It also reported $17 million in bug-bounty payments during the reporting period and a nine-point increase in engineering sentiment about security since February 2024. Microsoft said 95% had completed a course on guarding against AI-powered attacks.

These are Microsoft-reported figures, not independent audits. They measure specific coverage, process, training, and remediation indicators—not the probability of a future compromise or proof that a product is secure. For example, a governed release template can improve consistency, but its value depends on what controls it enforces and whether teams use it effectively.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The latest SFI progress report located for this account is the November 2025 report; Microsoft also published an overview of that update. The figures should be read as the company’s description of progress, not as outside assurance that the program caused better security outcomes.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A separate leadership change in 2026

In February 2026, Nadella announced that Hayete Gallot would return to Microsoft as executive vice president of Security, reporting directly to him, while Charlie Bell moved to a role focused on engineering quality. Nadella said Gallot and her team would be accountable for security-product operating rhythms. Microsoft’s announcement is a later leadership and operating-structure change; it should not be confused with the 2024 compensation policy or treated as proof of its results.

How to judge whether the model creates accountability

Linking pay to security can focus attention, but the link is only as credible as its design. For Microsoft—or any company—readers should ask:

  • Are targets specific and time-bound? Broad commitments are difficult to evaluate. Metrics should identify the intended control or outcome and the period in which it should be achieved.
  • Is the incentive material? A defined category can matter, but its practical effect depends on the full incentive plan, scoring, and payout ranges.
  • Who validates the measures? Independent review, board oversight, or internal audit can make it harder for leaders to define success solely on their own terms.
  • Is responsibility fairly assigned? A company-wide incident may involve decisions made across teams. Accountability should distinguish an unavoidable event from weak preparation, delayed response, or failure to fix known problems.
  • Can security leaders escalate or block a risky decision? Embedded expertise is useful only if responsibilities, reporting lines, and decision rights are clear.
  • Do metrics reward durable fixes? A narrow target such as closing vulnerabilities quickly can encourage superficial closure unless verification and recurrence are also considered.
  • Are outcomes disclosed? Targets, results, and explanations of material shortfalls allow investors, customers, and employees to assess whether the policy affected decisions.

These tests also expose possible unintended incentives. If compensation is tied too mechanically to incident counts, managers may focus on classifying or disclosing incidents rather than learning from them. If only easy-to-count remediations earn credit, slower architectural work may be neglected. A robust system needs both measurable milestones and informed judgment, with safeguards against gaming.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why Microsoft customers should care

Microsoft’s internal security governance matters to customers because its products and cloud services—including Azure, Microsoft 365, Entra ID, Windows, and Copilot—are part of many organizations’ critical operations. A stronger process for surfacing product risks could benefit customers, but organizational reform is not a guarantee that future incidents will be prevented.

Enterprise buyers evaluating Microsoft or another technology provider can ask who owns product security, whether security goals affect senior incentives, how those goals are validated, whether security leaders can delay a release, and how lessons from incidents become engineering standards. They should also distinguish a vendor’s progress indicators from independent assurance and assess controls against their own threat model and compliance obligations.

Microsoft’s changes are also relevant beyond its own products. They offer a governance pattern other companies can examine: combine executive accountability with security ownership inside operating teams, while preserving independent escalation and transparent measurement. The difficult part is not announcing a security category or naming deputy CISOs; it is demonstrating that the structure changes priorities, decisions, and remediation when security conflicts with short-term business goals.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.