From music to hacking: Tori Westerhoff is part of the AI Red Team at Microsoft. Instead of playing the trombone, she now systematically looks for false notes in AI systems.
Photo: Tobias Bolzern
AI expert compares hacking to composing a security symphony
The psychological effects of AI systems surprise researchers and developers
In 2018, the AI Red Team started with IT security and today it assesses bioweapon risks
Blick’s artificial intelligence is still learning and may make mistakes.
Tobias Bolzern
digital Editor
Tori Westerhoff, you almost studied trombone at the conservatory, now you’re cracking AI systems. Do you still think like a musician?
Tori Westerhoff: Yes, actually! No one has ever asked me that, but I think about it all the time.in a symphony, the melody is distributed among various instruments, sometimes the
Microsoft Doubles Down on Cybersecurity with $17M bug Bounty Programme and AI Security Focus
Table of Contents
Microsoft is significantly increasing its investment in cybersecurity, responding to a growing threat landscape and a series of recent security incidents. The company is bolstering its defenses through a large-scale initiative, a substantial bug bounty program, and a dedicated team focused on securing its artificial intelligence systems.
The Secure Future Initiative (SFI)
Launched in 2023,Microsoft’s “Secure Future Initiative” (SFI) represents a major commitment to cybersecurity. As of late 2023, the SFI supported the equivalent of approximately 34,000 full-time positions dedicated to security-related work. [Microsoft On the Record] This substantial investment reflects the increasing sophistication and frequency of cyberattacks.
Key improvements implemented under the SFI include:
- Multi-Factor Authentication (MFA): MFA has been enabled for 99.6% of all Microsoft employees, adding a critical layer of security to employee accounts.
- Cloud environment Shutdown: microsoft has proactively shut down 560,000 unused cloud environments, reducing the potential attack surface.
- Threat Detection Systems: More than 50 new threat detection systems have been implemented to identify and respond to emerging threats.
Rewarding Security Researchers: A $17 Million Bug Bounty
Recognizing the value of external expertise, Microsoft paid out $17 million in bonuses last year to third-party security researchers who responsibly disclosed vulnerabilities in its systems. [Microsoft Security Response Center] This bug bounty program incentivizes security professionals to find and report weaknesses before they can be exploited by malicious actors. The program is a crucial component of a layered security approach.
AI Red Teaming: Securing the Future of AI
With the rapid advancement of artificial intelligence,Microsoft is prioritizing the security of its AI systems. Tori Westerhoff leads the AI Red Team, a dedicated group responsible for proactively testing AI systems for vulnerabilities before they are released to the public. This “red teaming” approach simulates real-world attacks to identify and mitigate potential risks. Red teaming is a critical security practice that involves authorized simulated attacks to evaluate the effectiveness of security measures.
What is Red Teaming?
Red teaming is a specialized cybersecurity practice where a team of ethical hackers attempts to penetrate an organization’s security defenses. Unlike traditional penetration testing, which focuses on specific vulnerabilities, red teaming aims to simulate a sophisticated, real-world attack. The goal is to identify weaknesses in people, processes, and technology, providing valuable insights for improving overall security posture.
Key Takeaways
- Microsoft is making significant investments in cybersecurity through the Secure Future initiative.
- The company rewards security researchers with a substantial bug bounty program, paying out $17 million last year.
- A dedicated AI Red Team, led by Tori Westerhoff, is focused on securing Microsoft’s AI systems.
- Proactive security measures, like MFA and cloud environment shutdown, are being implemented across the organization.
Microsoft’s commitment to cybersecurity is a continuous process. As the threat landscape evolves, the company will likely continue to invest in new technologies, expand its security teams, and refine its security practices to protect its customers and its own infrastructure. The focus on AI security, in particular, will be crucial as AI becomes increasingly integrated into all aspects of technology.
Related reading