A memo from Microsoft Chief People Officer Kathleen Hogan: “everyone at Microsoft” now has “security” as a “Core Priority”, used in performance reviews
“The Security Core Priority is not a check-the-box compliance exercise; it is a way for every employee and manager to commit to … X: Justin Elze / @hackinglz : I have heard security is important https://x.com/... Chirag Mehta / @chirag_mehta : This is a good first step by @MicrosoftSec to shift left by decentralizing security at the product level and centralizing the incentives. It's hard to cultivate a security-first culture but I hope they do it. It's a long road to regain customers' trust. #CyberSecurity Forums: r/technology : Every Microsoft employee is now being judged on their security work - The Verge
Context & Ripple Effects
Microsoft had already framed security as an organizational program through its Secure Future Initiative, then tied security principles and goals to executive compensation after the review-board criticism in April. Extending accountability to performance reviews moves that emphasis from specialist teams and leadership into routine management.
The change matters because it makes security an explicit employment incentive across Microsoft, complementing its existing large security engineering organization rather than treating security solely as a dedicated function.
First-order effects
- Microsoft employees and managers will have security assessed in performance reviews, making security work a formal part of individual accountability.
- The company’s earlier security goals linked to executive compensation are now reinforced by incentives that reach the broader workforce.
Second-order effects
- Product, engineering, and operational teams face stronger pressure to incorporate security considerations into their own workflows, rather than escalating them only to central security specialists.
- Managers will need review criteria that can distinguish meaningful security contributions from compliance-box checking, making implementation quality central to the policy’s credibility.
Third-order effects
- If sustained, this points to security becoming a company-wide operating metric at major software platforms, with talent management used alongside dedicated security organizations and technical programs.
- The broader test is whether incentive changes translate into more reliable vulnerability response and customer trust; performance-review language alone does not establish that outcome.
The trend: Security is shifting from a centralized technical function toward an organization-wide accountability system tied to leadership and employee incentives.