Skip to playerSkip to main content
  • 2 years ago
At a House Homeland Security Committee hearing last week, Rep. Marjorie Taylor Greene (R-GA) questioned Microsoft President Brad Smith about cyber security.

Fuel your success with Forbes. Gain unlimited access to premium journalism, including breaking news, groundbreaking in-depth reported stories, daily digests and more. Plus, members get a front-row seat at members-only events with leading thinkers and doers, access to premium video that can help you get ahead, an ad-light experience, early access to select products including NFT drops and more:

https://account.forbes.com/membership/?utm_source=youtube&utm_medium=display&utm_campaign=growth_non-sub_paid_subscribe_ytdescript


Stay Connected
Forbes on Facebook: http://fb.com/forbes
Forbes Video on Twitter: http://www.twitter.com/forbes
Forbes Video on Instagram: http://instagram.com/forbes
More From Forbes: http://forbes.com

Category

🗞
News
Transcript
00:00The gentleman's time has expired. I now recognize Ms. Green for five minutes.
00:04Thank you, Mr. Chairman. Mr. Smith, this has been a very engaging, intriguing conversation.
00:12I'm a business owner, so I've been listening to this and taking it in and thinking about
00:18it through that lens. You started with something that I find impressive. You said you accept
00:25responsibility. I just want to commend you for that. I appreciate it. We don't hear that
00:31very often here, but I think it's valuable and I think it's right. I just wanted to say
00:38thank you. I understand that Microsoft has a unique role to play in our cybersecurity
00:43landscape as it's responsible for nearly 85 percent of the productivity software such
00:48as Word, Excel, and PowerPoint used by the U.S. government. Given the company's presence,
00:55Microsoft is, of course, at significant risk of cyberattacks, over $300 million a day.
01:01Is that true, $300 million a day? We detect $300 million a day against our customers.
01:08That's what we get to see given all of the telemetry we have. Last year, if you look
01:12at phishing attacks, we had $47 million against ourselves over the year.
01:18Wow. That's far more than I could have even comprehended. Of course, these are serious.
01:28Everyone here on the committee is recognizing that. As you stated in your testimony, cyberattacks
01:34have become more prolific, just as you stated. As a result of the attack that your company
01:42went under, in May of 2021, the Biden administration released an executive order
01:47on improving the nation's cybersecurity, which required the establishment of the Cyber Safety
01:53Review Board under DHS. I want to talk to you a little bit about the board. I think, of course,
02:01oversight is important, but I think there should be more action taken by our government to prevent
02:09cyberattacks. Could we talk a little bit about the board? My understanding is the Cyber Safety
02:15Review Board is a mix of government and industry representatives. Is it true that Microsoft is not
02:24represented on the board? That's correct.
02:28Is any of your competitors on the board? Yes, they are.
02:32Essentially, how did this work? When this attack happened, the board ... Can you talk a little bit
02:40about that process? Yeah. You're getting at such a critical question, because I will say, first,
02:45I think we benefit from having this kind of organized effort. I think it's probably a mistake
02:52to put on the board people who work for competitors of, say, a company that is the subject
03:00of a review. The spirit of this, when it was created, was to create a community of people
03:06who could learn together. I'm less concerned about the way the process worked, and I just worry that
03:14where people want to take it in the future and just make hay out of others' mistakes. I'm just
03:20not sure that's going to do us that much good. Right. Did CSRB, did it share with Microsoft what
03:29your competitors said about their own security practices? I don't believe so. I don't know. I
03:35don't believe so. I could be wrong, but I don't believe so. Okay. With your competitors on the
03:43board helping produce the report, was this used in any other way in the marketplace?
03:51Yeah. I want to say two things, because first, I think the most important thing for me to do
03:56and for Microsoft to do is what you said at the outset. I just want to be here and accept
04:00responsibility, and I don't want to deflect any of that responsibility, because we have the highest
04:05responsibility. But second, the words that I would offer, and I'll offer it to the folks in the back
04:11who work for our competitors, because there's a bunch of them here. It's fine. Go tell people
04:17that you have something better, but we have to have a higher cause here. We are not the adversaries
04:26with each other, even though we may compete with each other. The adversaries are our foreign foes.
04:31So let's try to exercise a little self-restraint about how we work in these processes,
04:40because I don't think that the next company that gets an invitation from the CSRB is likely to be
04:47necessarily as willing as we were to share everything, which we did.
04:51Mm-hmm. Well, I agree. I think competition is healthy in the business world. I think it's
04:57great, actually. I enjoyed it for years and years. But I think oversight is also extremely important,
05:04and of course, I think everyone in this room agrees that we do not want any foreign country
05:10gathering any of our information, whether it's from an American citizen to our government,
05:17of course. CISA also has a bad reputation, especially among Republicans. They colluded
05:25with big tech, and social media companies stripped many Americans of their First Amendment rights. So
05:31that was another reason why I wanted to ask you a little bit about the board and how that worked.
05:38But furthermore, I have more questions, but I'm out of time. I think it would be extremely
05:44important for there to be assistance from the federal government in protecting not only
05:50companies like yours, but mom-and-pop companies. I mean, across the board to regular citizens
05:56from cyberattacks. It's a serious problem, and it will continue. I'm out of time.
06:01The gentlelady yields.
Comments

Recommended