The Human Side of Cybersecurity: Building Resilient Teams
Expert strategies for managing talent and thriving under pressure. Expert strategies for managing talent and thriving under pressure. Cyber Resilience Blog | Dell
Expert strategies for managing talent and thriving under pressure. Expert strategies for managing talent and thriving under pressure. Cyber Resilience Blog | Dell
Since 2019, Microsoft and OpenAI have shared a vision to advance artificial intelligence responsibly and make its benefits broadly accessible. What began as an investment in a research organization has grown into one of the most successful partnerships in our industry. As we enter the next phase of this partnership, we’ve signed a new definitive agreement that builds on our foundation, strengthens our partnership, and sets the stage for long-term success for both organizations. First, Microsoft supports the OpenAI board moving forward with formation of a public benefit corporation (PBC) and recapitalization. Following the recapitalization, Microsoft holds an investment in OpenAI Group PBC valued at approximately $135 billion, representing roughly 27 percent on an as-converted diluted basis, inclusive of all owners – employees, investors, and the OpenAI Foundation. Excluding the impact of OpenAI’s recent funding rounds, Microsoft held a 32.5 percent stake on an as-converted basis in the OpenAI for-profit. The agreement preserves key elements that have fueled this successful partnership – meaning OpenAI remains Microsoft’s frontier model partner and Microsoft continues to have exclusive IP rights and Azure API exclusivity until Artificial General Intelligence (AGI). It also refines and adds new provisions that enable each company to independently continue advancing innovation and growth. What has evolved: Once AGI is declared by OpenAI, that declaration will now be verified by an independent expert panel. Microsoft’s IP rights for both models and products are extended through 2032 and now include models post-AGI, with appropriate safety guardrails. Microsoft’s IP rights to research, defined as the confidential methods used in the development of models and systems, will remain until either the expert panel verifies AGI or through 2030, whichever is first. Research IP includes, for example, models intended for internal deployment or research only. Beyond that research IP does not include model architecture, model weights, inference code, finetuning code, and any IP related to data center hardware and software; and Microsoft retains these non-Research IP rights. Microsoft’s IP rights now exclude OpenAI’s consumer hardware. OpenAI can now jointly develop some products with third parties. API products developed with third parties will be exclusive to Azure. Non-API products may be served on any cloud provider. Microsoft can now independently pursue AGI alone or in partnership with third parties. If Microsoft uses OpenAI’s IP to develop AGI, prior to AGI being declared, the models will be subject to compute thresholds; those thresholds are significantly larger than the size of systems used to train leading models today. The revenue share agreement remains until the expert panel verifies AGI, though payments will be made over a longer period of time. OpenAI has contracted to purchase an incremental $250B of Azure services, and Microsoft will no longer have a right of first refusal to be OpenAI’s compute provider. OpenAI can now provide API access to US government national security customers, regardless of the cloud provider. OpenAI is now able to release open weight models that meet requisite capability criteria. As we step into this next chapter of our partnership, both companies are better positioned than ever to continue building great products that meet real-world needs, and create new opportunity for everyone and every business. The post The next chapter of the Microsoft–OpenAI partnership appeared first on The Official Microsoft Blog. Since 2019, Microsoft and OpenAI have shared a vision to advance artificial intelligence responsibly and make its benefits broadly accessible. What began as an investment in a research organization has grown into one of the most successful partnerships in our industry. As we enter the next phase of this partnership, we’ve signed a new definitive… The post The next chapter of the Microsoft–OpenAI partnership appeared first on The Official Microsoft Blog. Featured, The Official Microsoft Blog, AI The Official Microsoft Blog
Over the past few years, we have driven remarkable progress accelerating AI innovation together with our customers and partners. We are achieving efficiency and productivity at scale to shape industries and markets around the world. It is time to demand more of AI to solve humanity’s biggest challenges by democratizing intelligence, obsolescing the mundane and unlocking creativity. This is the notion of becoming Frontier: to empower human ambition and find AI-first differentiation in everything we do to maximize an organization’s potential and our impact on society. Microsoft’s technology portfolio ensures our customers can go further with AI on their way to becoming Frontier firms, using our AI Transformation success framework as their guide. Our AI business solutions are dramatically changing how people gain actionable insights from data — fusing the capabilities of AI agents and Copilots while keeping humans at the center. We have the largest, most scalable, most capable cloud and AI platform in the industry for our customers to build upon their aspirations. We remain deeply focused on ensuring AI is used responsibly and securely, and embed security into everything we do to help our customers prioritize cybersecurity and guard against threats. We are fortunate to work with thousands of customers and partners around the world — across every geography and industry. I am pleased to share some of the customer stories being showcased at our recently opened Experience Center One facility — each exemplifying the path to becoming Frontier. Driven by a commitment to innovation, sustainability and operational excellence, ADNOC is helping meet the world’s growing energy demands safely and reliably, while accelerating decarbonization efforts. To empower its workforce, the company introduced OneTalent — a unified AI-powered platform consolidating over 16 legacy HR processes into a single, intelligent system that furthers its dedication to nurturing talent, aligning people with strategic goals and turning every member of its workforce into an AI collaborator. Partnering with Microsoft and AIQ, ADNOC applied AI across its operations to reimagine everything from seismic analysis to predictive maintenance. ENERGYai and Neuron 5 — AI-powered platforms built natively on Azure OpenAI — turn complexity into actionable insights. The platforms use predictive models to reduce downtime — by as much as 50% at one plant. They are also using autonomous agents to optimize energy use; unlocking data-driven insights that have accelerated energy workflows from months or years to just days or minutes. Asset manager and technology provider BlackRock has been on a journey to infuse AI to level up how its organization operates across three key pillars: how they invest, how they operate and how they serve clients. To accelerate this mission, they partnered with Microsoft to transform processes across the investment management lifecycle by integrating cloud and AI technologies alongside its Aladdin platform. Embedded across 20 applications and accessed by tens of thousands of users, the Aladdin platform’s AI capabilities deliver functionally relevant tools to help redefine workflows for different types of financial service professionals. Client relationship managers are saving hours per client, reducing duplication and improving accuracy by evaluating CRM and market data to generate personalized client briefs and opportunity analyses using natural language processing — supported by verification and review methods that facilitate accuracy and compliance. Investment compliance officers are streamlining portfolio onboarding and compliance guideline coding, saving time on more straightforward tasks to focus on complex, investigative tasks. Portfolio managers can access data, analytics, research summaries, cash balances and more through AI-powered chat capabilities; enabling faster, more informed decision-making aligned with client mandates. With accelerated insights, improved data quality and enhanced risk management, BlackRock and its clients gain an advantage while enhancing client service, compliance and portfolio management. To build on its culture of innovation and enable hyper-relevant messaging at scale, multinational advertising and media agency dentsu built a cutting-edge solution using Azure OpenAI: dentsu.Connect — a unified OS for its applications. By leveraging the power of AI across the entire campaign lifecycle, clients can build and execute campaigns while predicting marketers’ next best impact with confidence and precision. This end-to-end platform drives data connectivity and ensures seamless interoperability with clients’ technology and data stacks to maximize and drive brand relevance across content, production and media activation while aligning every action with business goals. dentsu.Connect helps minimize the gap between insights and action with speed and precision. Since launching, users have increased operational efficiency by 25%, improved business outcomes by 30% and quickened decision-making and data-driven AI insight generation by 125X. Water management solutions and services partner Ecolab is harnessing the power of data-driven solutions to enable organizations to reduce water consumption, maximize system performance and optimize operating costs. Using Microsoft Azure and IoT services, the company built ECOLAB3D: an intelligent cloud platform that unifies diverse and dispersed IoT data to visualize and optimize water systems remotely. By providing actionable insights for real-time optimization across multiple assets and sites, Ecolab partners with global leaders such as Microsoft to collectively drive hundreds of millions in operational savings — while conserving more than 226 billion gallons of water annually; equivalent to the drinking water needs of nearly 800 million people. Delivering solutions across diverse industries, Ecolab is also a trusted partner for foodservice locations, helping balance labor costs with customer satisfaction. Its cloud-based platform Ecolab RushReady transforms data into an AI-enabled dashboard that improves daily operations by delivering actionable insights. In an Ecolab customer case study, this helped improve speed of service and sales labor per hour, resulting in increased profit of more than 10%. From data centers to dining rooms, Ecolab delivers intelligent, scalable solutions that transform operations for greater efficiency and measurable impact. Leveraging Microsoft’s AI solutions across its portfolio, Epic built agentic “personas” to support care teams and patients, improve operations and financial performance and advance the practice of medicine. By summarizing patient records and automatically drafting clinical notes, one organization found that “Art” decreased after-hours documentation for clinicians by 60%, reduced burnout by 82% and helped them focus more on patient care. Care teams can also track long-term patient health and better plan treatment for chronic conditions, while nurses can perform wound image analysis automatically with 72% greater precision than manual methods. At one hospital, AI review of routine chest X-rays led to earlier discovery of over 100 cases of lung cancer, increasing the detection rate to 70% compared to the 27% national average. To support back-end operations, organizations are using “Penny” to improve the revenue cycle — resulting in $3.4
Exploring the Intersection of Artificial Intelligence and Cybersecurity Exploring the Intersection of Artificial Intelligence and Cybersecurity Artificial Intelligence Blog | Dell
Shopping for the perfect tech gift can be overwhelming, but Dell’s got you covered with options and our Price Match Guarantee. Shopping for the perfect tech gift can be overwhelming, but Dell’s got you covered with options and our Price Match Guarantee. Dell Premium Blog | Dell
Discover how leaders can stay ahead in the evolving cybersecurity landscape with insights on post-quantum, AI, and resilient strategies for the future. Discover how leaders can stay ahead in the evolving cybersecurity landscape with insights on post-quantum, AI, and resilient strategies for the future. Cyber Resilience Blog | Dell
Dell and NVIDIA showcase innovations to accelerate agentic AI and enable secure government AI deployments at NVIDIA GTC this week. Dell and NVIDIA showcase innovations to accelerate agentic AI and enable secure government AI deployments at NVIDIA GTC this week. AI Solutions Blog | Dell
Take IT performance to new heights with Dell PowerEdge and latest NVIDIA AI infrastructure. Take IT performance to new heights with Dell PowerEdge and latest NVIDIA AI infrastructure. PowerEdge Blog | Dell
From 6G development to AI-RAN deployment, Dell empowers telecoms from the developer’s desktop to the Edge and the data center. From 6G development to AI-RAN deployment, Dell empowers telecoms from the developer’s desktop to the Edge and the data center. Telecommunications Blog | Dell
Dell and Nutanix now offer a simple, secure path to enterprise AI. See how we’re accelerating your generative AI journey. Dell and Nutanix now offer a simple, secure path to enterprise AI. See how we’re accelerating your generative AI journey. AI Solutions Blog | Dell
Discover how The Guthrie Clinic is using the Dell AI Factory with NVIDIA to transform rural healthcare, enhancing patient care and operational efficiency. Discover how The Guthrie Clinic is using the Dell AI Factory with NVIDIA to transform rural healthcare, enhancing patient care and operational efficiency. Customer Blog | Dell
Named one of Texas’ Most Reputable Companies, Dell powers the Lone Star State with AI, education and innovation. Named one of Texas’ Most Reputable Companies, Dell powers the Lone Star State with AI, education and innovation. Awards Blog | Dell
Bridge the gap between AI strategy and execution. Join Dell and NVIDIA at ODSC West for powerful insights and hands-on experience. Bridge the gap between AI strategy and execution. Join Dell and NVIDIA at ODSC West for powerful insights and hands-on experience. Artificial Intelligence Blog | Dell
Inside the Dell AI Data Platform Event Inside the Dell AI Data Platform Event Launch Blog | Dell
Unlock IT flexibility. Dell APEX combines subscription and pay-per-use models for ultimate scalability and cost control. Read more. Unlock IT flexibility. Dell APEX combines subscription and pay-per-use models for ultimate scalability and cost control. Read more. APEX Blog | Dell
Explore the latest updates to Dell AIOps and its AIOps Assistant—now with context awareness, PowerStore agent and smarter IT insights. Explore the latest updates to Dell AIOps and its AIOps Assistant—now with context awareness, PowerStore agent and smarter IT insights. Observability Blog | Dell
Dell is committed to working with the open source community to make AI more accessible, efficient and impactful. Read more… Dell is committed to working with the open source community to make AI more accessible, efficient and impactful. Read more… AI Solutions Blog | Dell
When Christian Grobmeier went to help his son with a Minecraft problem, he found the game displaying a warning: “We are suffering from a security hole from Log4J, please be careful and update immediately.” I stared at the screen and told my son, ‘I’m sorry, it’s my fault.’ Christian Grobmeier, Log4j maintainer This is the untold story of how one maintainer and the Log4j team navigated a crisis that exposed critical gaps in our digital infrastructure and demonstrated the importance of open source security and sustainability. Now, initiatives like the GitHub Secure Open Source Fund are working to make sure it never happens again. It all started a few hours earlier on a cold November day, when Christian, who is a maintainer of the open source project Log4j, planned to spend time playing games with his son. Instead, he found himself staring at his phone, watching notifications pile up in his inbox—10, then 20 emails flooding in. When he saw the words “remote code execution,” his first thought was: “Maybe I’m on the wrong mailing list.” He wasn’t. And within hours, Christian would be at the center of what became known as Log4Shell: the most severe vulnerability in internet history, affecting billions of devices from Fortune 500 companies to Minecraft servers worldwide. “I told my son, I will play with you in like five minutes,” Christian recalls. “But he didn’t see me for the next couple of days.” Watch the full interview with Christian Grobmeier and Gregg Cochran, staff program manager at GitHub, above. 👆 The ubiquity that made Log4Shell a perfect storm Log4j is foundational software. This 20+ year-old Java logging library quietly powers system events in applications worldwide, like user logins and calculation results. But this small piece of software had quietly become a dependency in thousands of projects across the Java ecosystem. Log4j is such a small, tiny library. But everybody can use it in their software. Christian Grobmeier That ubiquity made Log4Shell devastating. Financial services companies relied on it for compliance auditing. E-commerce systems used it to track security incidents. Insurance companies needed it to monitor their software behavior. In a 2022 Tidelift survey, 49% of open source developers reported that their organization relies on Java—and most of them were using Log4j without even knowing it. When Christian realized the scope of the vulnerability, the weight hit him immediately: “Literally all Java applications in the world could be affected. Even 10% would be a major problem. This would be catastrophic.” A vulnerability that scored a perfect 10 Log4Shell reveals how a seemingly innocent feature became an attack vector. Log4j used Java’s Naming and Directory Interface (JNDI) to provide flexibility, allowing developers to load software components from remote servers. But the library didn’t validate whether JNDI lookup strings were coming from trusted sources. “How can a string break the internet?” Christian asks. The exploitation was frighteningly simple. An attacker could input a malicious JNDI string into any application field that gets logged—a username field, a search box, even a Minecraft chat message—and execute remote code on the target system. jndi:<protocol>://<server-name>:<port>/<path-to-object> “You don’t even need to have special knowledge,” Christian notes. “You just run around and push the string wherever you want it.” The Common Vulnerability Scoring System (CVSS) gave Log4Shell a perfect 10: the highest possible score. “The first time I heard about this score, I thought, maybe it’s not so bad,” Christian remembers. “And then after a couple of days, I thought, yeah, maybe we should extend this to a score of 15 or 20.“ The human cost of maintaining critical infrastructure The personal toll on maintainers during the Log4Shell crisis reveals the hidden human cost of our software supply chain. Christian and his team, mostly volunteers, suddenly found themselves responsible for patching a vulnerability affecting half the internet. The pressure was immense and deeply personal. Some of us stopped sleeping. We all felt that either we fix it right now in the next few days, or we close this project. Christian Grobmeier Fixing the initial vulnerability led to the discovery of additional issues, creating what Christian describes as “a bag of water with a hole. When you patch the hole, you see another one.” Meanwhile, the community response was mixed. “On the one hand, you have people who really hate you, and on the other hand, you have people who are really behind you,” Christian explains. Perhaps most telling: Nobody stops in to check on you. They check on the project. There’s also nobody standing up and saying, ‘hey, thank you for the good work you’re doing to remediate this issue.’ Christian Grobmeier How the GitHub Secure Open Source Fund is strengthening security The Log4Shell incident highlighted a critical gap in open source security: Maintainers often lack the training and resources to build security into their projects from the ground up. This realization sparked initiatives like the GitHub Secure Open Source Fund, which provides both funding and security training to critical open source projects. The fund has been effective and efficient as a form of proactive protection, pooled resources, and shared responsibility. Think of it as “insurance” for the open source supply chain—helping make the digital ecosystem safer and reducing risks that could impact billions of users. Christian participated in the GitHub Secure Open Source Fund security training program, and the impact was transformative. The training didn’t just provide technical knowledge—it shifted his perspective. Christian explains, “With this training, developers are no longer the weakest link. Instead, they’re the first line of defense.” This change in mindset is crucial. As Christian puts it: Ignorance is by far the worst and most critical security hole. It will basically break all software. Christian Grobmeier When asked if the GitHub Secure Open Source Fund training could have prevented Log4Shell, Christian is direct: “If this training had existed five years ago, maybe Log4Shell wouldn’t be here today.” Technical lessons: Building security by default The Log4Shell incident taught the industry several critical lessons about secure development practices: 1. Validate
Cybersecurity Awareness Month is a reminder that in today’s threat landscape, attackers don’t just aim to break in — they aim to break your ability to recover. Cybersecurity Awareness Month is a reminder that in today’s threat landscape, attackers don’t just aim to break in — they aim to break your ability to recover. Cyber Resilience Blog | Dell
We started building our accessibility governance program in 2022 when we adopted accessibility as a GitHub Engineering Fundamental, along with availability and security. Since then, we’ve continued to optimize and scale accessibility governance processes. This post explains how GitHub Copilot empowered an accessibility program manager to build a working prototype of a critical accessibility governance process improvement and enlist engineering resources to move it from prototype to production in record time. Context The primary construct of our accessibility governance program is services: A service may represent an entire website, an entire application, or a collection of pages, features, or backend functionality. The accessibility compliance of each service is tracked and visible to program leads. The compliance status for each service is updated weekly and service owners are notified of changes. The challenge When new services are added or the compliance status of existing services is changed, service owners are notified. However, the problem is that we did not have an effective mechanism to prompt service owners to plan, schedule, and complete the work required to reach compliance. This shortcoming had the following consequences: Service owners sometimes delayed accessibility remediation work, extending potential negative impacts for users with disabilities. Leadership could not quantify and manage accessibility compliance risk due to the lack of target dates for remediation. The solution We used GitHub Copilot to automate a workflow that increases accountability for service owners, increases visibility for leadership, and reduces barriers for users with disabilities. Our workflow now: Uses GitHub Actions to auto-create GitHub Issues that track accessibility remediation in service repositories when a service falls out of compliance. Includes all relevant information and guidance for service owners within remediation issues. Cross-references remediation issues with a GitHub Projects board that provides a global view for program managers and leadership. Syncs assignees between remediation issues and the project board. Mentions stakeholders for transparency without repo spam. Auto-closes remediation issues when services are acceptable. How Copilot changed the game The traditional approach to building an internal automation like this would have meant drafting detailed requirements, prioritizing them into a team backlog, waiting for engineering capacity, and cycling through multiple sprint iterations before we saw working end‑to‑end value. That could take weeks, if not longer. Instead, we spent five to six hours in direct conversation with Copilot, rapidly prototyping and testing ideas. Our working loop was intentionally lightweight. For each iteration, we roughly followed this pattern: Framed a single rule in plain language (e.g., detecting sustained non-compliance and ensuring an issue existed or was updated with current context). Asked Copilot to scaffold or adjust code (e.g., new helper, data parsing tweak, API refinement) instead of writing everything from scratch. Used a small synthetic fixture of accessibility compliance snapshots (e.g., initial drop, continued drop, recovery) to exercise the logic locally. Reviewed the output (e.g., issue body, labels, assignees) and refined prompts to tighten naming, thresholds, or branching. Added guardrails: idempotency (i.e., skip if a valid issue was already open), simple dampening to avoid flip‑flop closures, and defensive handling for incomplete data. Logged high‑level decisions (e.g., “updated existing issue” vs “no action – compliant”) to quickly verify intent. Re-ran the fixture (plus a variation) to confirm no regressions, then commit and move to the next rule. Because each iteration was scoped to a single behavior, Copilot’s suggestions stayed relevant and we avoided big refactors. When new edge cases emerged, like transient score dips or duplicate issue creation due to renamed services, we added another short loop instead of scheduling a meeting. This rapid cadence enabled us to converge on something production‑ready without a formal project plan. From prototype to production We first built a quick prototype to reliably detect a non‑compliant service, create or update a remediation issue, and keep ownership visible. We also wanted to prove we could achieve this without any human triage. The initial goal was a controlled rollout to a small set of services in a staging environment with historically known volatility. This way we could watch behavior under real conditions before rebuilding the workflow for broad deployment in a production environment. Our planned rollout path was incremental: Prototype using a personal access token in a staging environment. Observe a handful of test weekly cycles in staging with mock service repositories and adjust thresholds or labels. Refactor the code and migrate to a GitHub App for proper security and scoped permissions. Deploy to production and roll out to all services that we track for accessibility compliance. Formalize governance reporting once noise was minimized. To validate, we recorded a concise end‑to‑end demo showing an input change triggering automatic issue creation, cross‑linking, assignee sync, and subsequent update on a repeated failure. That artifact gave stakeholders the ability to evaluate the full experience asynchronously. The reaction was decisive. Seeing live issues appear with clean structure and traceability accelerated approval to move beyond the prototype stage. We secured engineering partnership to productionize the flow, established a sandbox environment for hardening, and began implementing the GitHub App version with appropriate security and scale considerations. The real impact The impact came from two layers: the automation we introduced and the way Copilot changed who could build and iterate on it. Automation outcomes: Remediation issues now appear (or update) promptly instead of waiting on manual triage, allowing service owners to immediately understand the policy requirements to resolve those issues and to hold themselves accountable when exceptions are requested. Ownership, status, and cross-links live in one place, giving leadership a trustworthy snapshot without ad‑hoc spreadsheets or pings. This also strengthens the partnership between accessibility program owners and engineering teams. Duplicate or stale outreach dropped because idempotent logic and dampening prevent noisy close and reopen churn. Governance effort shifted from clerical tracking to higher‑value analysis of systemic accessibility patterns, and enabled tighter governance controls. Copilot-enabled delivery outcomes: A domain expert built the prototype, allowing engineers to stay focused on their critical roadmap work. Reduced context-switching for engineering. Partnership time was spent on security, scale, and production hardening instead of basic scaffolding.