Mark Simos

@markasimos.bsky.social

Lead Cybersecurity Architect • Executive and Board Advisor • Keynote Speaker • Professional Storyteller https://www.youtube.com/@MarkonCybersecurity

One thing SAF does well is to help you connect business priorities to architecture, controls, processes, operations (as well as Microsoft implementation guidance). We many programs struggle with this. See aka.ms/SAF (no paywall, no registration)

Bild

Controlling access requires a subject, verb, and object (regardless of whether it involves humans, AI agents, data, deterministic systems, or physical objects) - Who or what is requesting access? - What action are they taking? - What business asset are they touching?

Bild

We need to have an honest conversation about legacy systems… Most organizations have unsupported systems that they aren’t able to change or move and this creates business risk. This is normal and common, no surprise. 🧵

Bild

Are you still applying security patches as an exception? or patching by default? One of the biggest impacts of Mythos, MDASH, and other AI vuln discovery/exploit technologies is that you have to get really good at all aspects of software vulnerability management. 🧵

Bild

The SAF documentation site and June 2026 MCRA just went live on Microsoft Learn! Check it out and let us know what you think! aka.ms/SAF Note: This is the first release and we will be continuing to add to it. Send us your feedback, requests, and ideas.

Bild

I keep hearing people are "Automating Tier 1 with AI" (or some other job) and I think words really matter here. ◾ Are you trying to replace a human person with AI? Assigning a human role to AI? ◾ Are you automating the tasks currently being done by people? a short 🧵

Bild

Security can never “win the game” - it's not the job we signed up for. We are the defense squad so we don't score goals or points - we just keep opponents from scoring points.

Bild

I recently did an interview-style session for an internal Microsoft team on why end to end security is so important and thought I would share my notes on the points to cover. 🧵

Bild

The Zero Trust Playbook site is live! It currently has a summary of the series, the outline of the first book, some information on the authors, and an events page with upcoming events and recordings. Much more to come in time!

BildBildBildBild

Cybersecurity is often incorrectly seen as a 'technical problem' that can be 'solved' (it isn't!) by business leaders & others. *Security is an ongoing risk that requires ongoing work.* Security leaders often accidentally create or reinforce this misperception. a short 🧵

Bild

Think security can do it all on our own? WRONG! We must recognize that we are part of a larger team and each of us has a different part to play in protecting the organization. short 🧵

Bild