Normal view

There are new articles available, click to refresh the page.
Yesterday — 23 July 2026GeekWire

Microsoft 2.5: New security business chief Hayete Gallot on the company’s push into the agentic era

23 July 2026 at 10:43
Hayete Gallot, now executive vice president of Microsoft Security, speaks at a Microsoft event in France in 2024. (Microsoft Photo)

GeekWire is profiling over the next few weeks some of the people and teams that are shaping the evolution of Microsoft in what we’re calling its “Microsoft 2.5” era.

AI has had an impact on just about every tech-product category, but especially security. Attackers are using AI; customers are looking to defend with AI. The goalposts keep shifting. “Agentic security” is now the holy grail, and Hayete Gallot, the newly minted executive vice president of Microsoft Security, is leading the charge toward it.

Gallot, a 16-plus-year Microsoft veteran who rejoined the company in February after a 1.5-year Google detour, replaced Charlie Bell, who came to Microsoft from AWS in 2021 and continues at the company as an individual contributor focused on engineering quality.

“Customers care about two things: solving for security and being able to afford it,” Gallot said when I asked during our interview this week why she came back to Microsoft.

“I am a problem solver. And an engineer at heart (and by training). Security is the most important problem right now — and Microsoft is the only place with all of the puzzle pieces to help our customers.”

Since her return, Gallot hasn’t been shy about shaking things up. As noted recently by The Information, at least nine corporate vice presidents who previously reported to Bell have left the company this year.

“We’re making changes to ensure we’re in the best formation to go after this opportunity,” she acknowledged.

“I’m motivated by doing the right thing for our customers, my teams, and tech outcomes,” she said. “I like to move quickly: days and weeks, not months and years, learning through execution, iterating rapidly, and adjusting based on real customer signals.”

The company isn’t starting from scratch. As of 2021, Microsoft claimed security was a $10 billion business for the company. By 2023, security had reached a $20 billion annual revenue rate, officials said.

Those claims haven’t been without controversy. Microsoft has built a huge business in finding and fixing security problems which some customers felt were of the company’s own making.

Microsoft has a wide-ranging and rather unwieldy security portfolio, encompassing identity management (Entra), endpoint protection (Defender), endpoint management (Intune), security information and event management (Sentinel), and compliance (Purview), among others.

In 2023, Microsoft introduced its Security Copilot set of AI analysis services that integrated with some of its existing security offerings. But a portal-based solution like Security Copilot doesn’t offer the kind of end-to-end coverage that an agentic security platform can, Gallot said.

The problem is that attackers are using agents, too. Customers need real-time insight into what’s happening in their environment, and the ability to act just as quickly, Gallot said.

Agentic security is about “taking the signals and turning them into a graph that is useful,” Gallot said. “If you’re trying to reason about 100 trillion signals, it’s not really effective.” The graph, she said, lets agents pick the right model for each threat and close the loop.

In practice, that means the system can quarantine a device or revoke access on its own, for example, rather than waiting for a human.

Microsoft’s core existing security products will continue to play a role as the landscape evolves, both spotting the problems and acting on them. Security Copilot isn’t going away in the process: “You’ll have Copilot and you’ll have agentic security,” she said.

The company’s new Agent 365 “control plane” — a central console for tracking every AI agent a company runs — fits in by letting customers see the “blast radius” of an agent, meaning everything a hijacked agent could reach, Gallot said. It’s similar in concept to Zero Trust, the “never trust, always verify” security model that limited how far an attacker could get with a stolen employee login, but applied now to agents rather than people.

So what exactly is this ‘agentic security’ thing? Microsoft has a whole website dedicated to the very topic.

Traditional AI security and agentic AI security are fundamentally different, Microsoft says. Agentic security doesn’t just protect models and training data; it also can protect tools, workflows, memory, connected systems and more. Because agents can take action, the potential positive and negative stakes are higher.

While AI has helped businesses make strides in finding and fixing vulnerabilities, it hasn’t gone much beyond that. Microsoft introduced its multi-model agentic scanning harness (MDASH) as its first step into the agentic security space, Gallot said.

The company used MDASH internally to boost finding and fixing Windows security issues, and it is now making it available to select customers in an expanded preview. MDASH will allow customers to use the best model for the right task to secure all different types of code bases, she said.

Microsoft is rumored to be readying a more comprehensive agentic security offering, of which MDASH is likely just one piece.

Microsoft is far from the only one doing this. AWS, Anthropic, and OpenAI are offering security tools on their platforms, and dedicated security vendors are building their own agentic platforms.

Microsoft has the advantage of scale in the enterprise. The question is whether Gallot and her new leadership team can turn that scale and emerging AI tools into both a bigger business for the company and better protection for its customers.

Before yesterdayGeekWire

Veteran Microsoft security executive joins AWS amid broader reshuffle in Redmond

20 July 2026 at 13:32
Rudra Mitra will lead Amazon security services in his new role. (LinkedIn Photo)

Rudra “Rudy” Mitra, who spent more than 27 years at Microsoft and most recently led its Purview data-security business, is joining Amazon Web Services as vice president of security services.

Mitra will oversee an AWS portfolio that includes tools such as GuardDuty and Security Hub, which companies use to track security risks across their cloud accounts. AWS recently added AI-specific threat detection to GuardDuty and, perhaps notably given today’s news, extended Security Hub to monitor AI workloads and security inside Microsoft Azure. 

He will report to Chet Kapoor, the former DataStax CEO whom AWS hired last year as vice president of search, security and observability, a role that reports to AWS CEO Matt Garman.

“Rudy brings decades of security experience, a passion for building, and a deep understanding of what customers need as the security landscape continues to evolve,” Kapoor wrote on LinkedIn

Mitra joined Microsoft in 1999 straight out of college, working on early efforts to deliver Office as an online service before launching Purview, the company’s data-security and governance product, in 2014. He announced his exit from Microsoft last week, addressing what was next at the time by saying only that there was “more on that soon.”

His departure comes amid a broader reshuffling of Microsoft’s security leadership this year under Hayete Gallot, who returned from Google in February to run the group and has been reshaping its executive ranks in recent weeks and months.

Gallot replaced Charlie Bell, who had joined from AWS in 2021 and continues at Microsoft as an individual contributor focused on engineering quality. She’s been overhauling the group’s product lineup, according to The Information, which reported last week that at least nine corporate vice presidents who reported to Bell have left the company this year.

Rohan Kumar left for Salesforce in June, Vasu Jakkal stepped down after six years. Krishna Kumar Parthasarathy departed this month after 28 years. Joy Chik, president of identity and network access, announced her retirement in April.

On the inbound side at Microsoft, Naseem Tuffaha returned in June to fill the corporate VP role Kumar had left, after nearly two decades at the company and a stint away.

When Gallot arrived, Microsoft named Ales Holecek, a longtime engineering leader, as the security group’s chief architect, reporting to her. David Weston, another veteran Microsoft executive, also reportedly shifted into the security unit earlier this year.

JPMorgan Chase bets on Seattle to build its AI control layer

15 July 2026 at 12:25
Lori Beer, JPMorgan Chase’s global chief information officer, at the JPMorganChase Center in Seattle. (GeekWire Photo / Todd Bishop)

JPMorgan Chase is building out a new AI software infrastructure team, anchored in Seattle, focused on running AI across its data centers and outside providers in a way that controls costs, protects its intellectual property, and avoids tying its fortunes to any one vendor.

Lori Beer, the bank’s global CIO, discussed the effort as part of a broader interview Tuesday during a stop in Seattle. She said the bank is being “careful about lock-in, strategic risk, financial risk, all those things.”

The move comes as business and tech leaders — including Microsoft CEO Satya Nadella and Palantir CEO Alex Karp — publicly warn about the risks of letting a small number of AI vendors accumulate control over costs, data, and the choice of which AI tools businesses can use.

Beer described the new group as an AI infrastructure team but said it works at the software level, separate from JPMorgan groups that build data centers or procure hardware.

She said the group will, for example, develop systems to determine when to route different types of AI workloads to JPMorgan’s own data centers, when to tap into public cloud providers, and when to use newer specialty computing suppliers.

AI agents are one example of where the bank is drawing a line.

Beer said JPMorgan will build and own the software that runs its agents, while treating the underlying AI models as interchangeable. The agentic layer is specific to JPMorgan’s business, whereas the underlying models are general-purpose, and JPMorgan wants to be able to switch among them as the market changes. 

Cost is another focus. Given the option, Beer said, engineers naturally reach for the newest and most powerful model, even when a cheaper one works as well. Systems built by the new team will route specific workloads to different types of models.

The new AI infrastructure team will be spread across multiple JPMorgan locations, but Beer said the Seattle area offers a high concentration of the required skills, including engineers who built cloud infrastructure at Amazon, Microsoft, and other tech platforms before joining JPMorgan. 

It’s part of a broader focus on AI at JPMorgan’s Seattle Tech Center, which has grown to about 400 people since opening in 2018, with a heavy emphasis on cybersecurity.

JPMorgan said this week that it has named Ture Armas, the bank’s CTO for Commercial Bank Lending Technology, to lead the Seattle Tech Center. Armas will continue in his existing role while adding oversight of the tech center’s strategy, talent, and community engagement. He replaces Mamtha Banerjee, who left in March.

The Seattle Tech Center is preparing to move next month into an expanded space at the JPMorganChase Center, the skyscraper that was renamed from the Russell Investments Center in January. The tech center is currently located in a smaller space in a nearby building. The move will put engineers closer to business teams, which Beer called critical as AI accelerates the pace of product development.

Beer, who started her career as a software engineer at a nuclear facility, joined JPMorgan in 2014 from health insurer WellPoint. In 2017, she became the first CIO to sit on the bank’s Operating Committee. She oversees a technology division of about 70,000 people, including 45,000 engineers, with a $20 billion annual budget. 

JPMorgan reported record second-quarter results Tuesday morning, topping Wall Street expectations. On the earnings call, CEO Jamie Dimon said the bank has almost 1,000 AI use cases across the business, with about 50 he described as the most important, in areas including risk, fraud, marketing, note-taking, and document reading.

In what turned out to be a preview of Beer’s comments later in the day, CFO Jeremy Barnum described the bank’s AI priorities: “Use the right model for the right purpose, be smart about open source where appropriate, and ensure that you’re getting value out of it ultimately.” 

❌
❌