Skip to content
CISO Spotlights

Career profile

Igor Tsyganskiy

Chief Information Security Officer, Microsoft

Status
Current role, per sources checked 9 December 2025
Appointed
Not stated in the sources
Published

Compiled 27 September 2026 from public records. Each statement below is drawn from the sources listed at the end.

Igor Tsyganskiy is Microsoft's chief information security officer, credited by the company as a co-author of its sixth annual Digital Defense Report.

Career path

Tsyganskiy joined Microsoft in late 2023.

Before that, SecurityWeek reports he spent seven years at Bridgewater Associates, managing the technology stack for what the outlet describes as the world's largest hedge fund, and is credited with overhauling the firm's trading and back-office systems.

Earlier roles, per the same report, include senior vice president of product management at Salesforce and senior vice president of engineering at WideOrbit.

Growing Microsoft's security organization

In December 2025, Tsyganskiy announced several leadership changes across the security organization he leads, promoting Geoff Belknap and Michael Srihari to newly created Operating CISO roles that report directly to him.

Under that structure, Belknap became Operating CISO for Core and Enterprise, responsible for Microsoft's core infrastructure, corporate applications and merger-and-acquisition security, while Srihari took the Operations and Compliance side, covering the cross-cutting work needed to defend the organization.

All cyber intelligence, counterintelligence, red-team and cybersecurity software teams continue to report directly to Tsyganskiy.

The October 2025 Digital Defense Report he co-authored covers trends from July 2024 through June 2025 and found that more than half of attacks with known motives were driven by extortion or ransomware, with attacks focused solely on espionage making up just 4 percent.

The same report found that in 80% of the cyber incidents Microsoft's security teams investigated over that period, attackers were seeking to steal data, a pattern the report describes as driven more by financial gain than by intelligence gathering.

It also found that more than 97% of identity attacks are password attacks, and that phishing-resistant multifactor authentication can stop over 99% of that category even when an attacker has the correct username and password.

His organization's restructuring builds on a Deputy CISO strategy Microsoft introduced in 2024 as part of its broader Secure Future Initiative, an effort SecurityWeek reported was meant to deliver faster cloud patches, better management of identity signing keys, and products with a higher default security bar.

Sources

  1. 1.
    Microsoft On the Issuesblogs.microsoft.com · published 16 October 2025 · checked 27 September 2026 · tier A
  2. 2.
    SecurityWeeksecurityweek.com · published 9 December 2025 · checked 27 September 2026 · tier B

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.