Once a Marine, always a Marine.
That’s certainly true for Doug Pierson, a recently retired US Marine Corps Major General who manages our Microsoft Executive Support Team. As part of that role, he works with our company’s senior leaders and created an Executive Cyber Defense service offering to assist them with protecting themselves and the company from Malicious Cyber Actors (MCAs).
“Yes, this is a different situation, but not so much that the lessons don’t apply. We need our executives to be very vigilant.”
Doug Pierson, senior director of IT Service Management, Microsoft Digital
While serving in the U.S. Marines, one of his assignments was deputy commander of Marine Corps Forces Cyber Command, U.S. Cyber Command, where he led multiple Joint Task Forces protecting the United States worldwide from cyber and asymmetric threats via nonstop offensive and defensive cyber operations. At Microsoft, he and his team have created a service offering that is founded on his time in direct contact with near peer and other adversary MCAs to help our executives protect themselves and the company from cyber threats that they face.
The attackers and battlefields may be different, but the concept is the same.
“Yes, this is a different situation, but not so much that the lessons don’t apply,” says Pierson, now a senior director of IT Service Management in Microsoft Digital, the company’s IT organization. “We need our executives to be very vigilant.”
As technology advances and proliferates, so too do the different ways that MCAs hack into businesses.
Executives—and the people around them, such as executive assistants, chiefs of staffs, and other closely aligned administrators—are particularly vulnerable to cyberattacks. As criminals look to access trade secrets, impersonate individuals, and use sensitive or confidential information for malicious means, we’ve seen an expansion in their unique approaches to finding and exploiting vulnerabilities.
Recently, Pierson and our Executive Support Team saw an opportunity to scale up how we protect our leaders’ communications and data, with approaches tailored to each person’s workflows and potential vulnerabilities.
They tackled the problem from three angles:
- People. Besides Microsoft executive leadership, we advise support staff, clients, client stakeholders, and anyone else who might unintentionally create access vectors that lead bad actors to our executives.
- Places. Many of our executives travel to high-risk locations that require proactive security measures. We also take into consideration whether a destination has Microsoft infrastructure in place, making it safer. Areas without Microsoft infrastructure might leave someone vulnerable. Airports, for example, might require you to sign onto a public Wi-Fi network or put you at risk of “shoulder surfing,” meaning someone looking at your laptop and gaining access to sensitive information. Our Executive Support Team provide awareness of how to safely navigate through these locations, while partnering with our Executive Protection Unit to enable a multilayered virtual and physical cyber shield while on the road.
- Things. No matter who the staff member is and where they’re located, we ensure they have devices that are updated with the latest software, functional for mobile use, and include secure measures like cloud backup or VPN. We set them up with travel routers, provide insight on IoT home network devices, and offer support for other tools that secure communications and internal information.
As we continue to refine and build out our operating principles for executives that allow them to conduct business safely from any device and location, we learned several key lessons along the way. In simplest terms, executive support regularly ties in with an internal partnership on executive cyber protection in a “triad”:
- Our Executive Support Team maintains cyber security in proximate access: coordinating directly with the executives and their teams on IT security practices, devices, travel, and immediate concerns.
- Our Executive Protection Unit maintains physical security overwatch for executives in the office and during travel—most notably when in a high-risk area.
Lesson 1: Partner with your CISO team
Our team works with the Microsoft Office of the CISO to monitor and consistently review network and account activity on-net, and off-net for anomalies.
Our initiative has been a success in large part because we set clear, easy-to-follow guidelines and invested time and resources into educating staff on those guidelines. As an example, we deliver quarterly Protect Your Tech upskilling sessions that routinely attract 20 executive assistants (EAs), who learn about things not readily apparent as well as how to find cyber protection capabilities via Executive Support or other teams within Microsoft.
“It started with a foundational set of tips and tricks due to very real and specific need, given active targeting of the Executive Admin community and how much passion EAs have around protecting their executive on multiple levels,” Pierson says.
In newsletters, informational booklets, and the regularly offered Protect Your Tech sessions, we discuss the foundational importance of using multifactor authentication (MFA), strong passwords, keeping devices updated, and avoiding untrusted Wi-Fi networks. We then go from there into more specific measures.
“We provide executives with a secure physical device enabled with Cloud PC, a system that essentially mirrors their primary computer within a highly secure virtual environment.”
Nolan Mitchell, IT service manager, Microsoft Digital
We also regularly educate support staff on how to manage their devices with Entra ID or Intune, save files to OneDrive and SharePoint, and identify scam links or fake accounts.
In addition, we meet with executives prior to travel to high-risk locations, setting them up with a secure environment in advance of their trip.
“We provide executives with a secure physical device enabled with Cloud PC, a system that essentially mirrors their primary computer within a highly secure virtual environment,” says Nolan Mitchell, an IT service manager in Microsoft Digital.
That means that if a device is lost or stolen, data is designed to remain accessible through the cloud rather than being stored locally on the device.
“We’re seeing governments put laws and policies in place that enable them to view what is on your devices, so we remind our folks that those laws and policies exist, and that they should be mindful or give very specific guidance related to traveling with their devices.”
Elias Gonzales, director of executive protections, Global Security
We also might advise them on what they shouldn’t bring with them.
“We’re seeing governments put laws and policies in place that enable them to view what’s on your devices, so we remind our folks that those laws and policies exist, and that they should be mindful or give very specific guidance related to traveling with their devices,” says Elias Gonzales, a director of executive protection in Microsoft Global Security.
This strong foundation has led to our team being more proactive before a threat emerges, rather than being reactive to attacks that might have already impacted them.
“The fact that folks are engaging us regarding security, for high-risk travel briefs, and to understand the environment they will be operating in before they start moving around—that’s a good thing,” Mitchell says.
Lesson 2: Collaboration is the way
It’s all about working together.
“We realized early on that leveraging our expertise and collaborating across organizations would make our initiative way more effective,” Pierson says.
Much of Pierson’s work at Microsoft Digital, for example, is informed by his extensive experience commanding offensive and defensive cyber units in the Marines.
Likewise, Asaf Kashi, a Microsoft vice president and deputy CISO, taps into his deep knowledge and experience leading teams that maintain Microsoft capabilities, systems, and tool security.
“We notify and involve executives on threat actors and actions around areas of ownership. We tell them,‘Here’s how to keep yourself and your team secure in an agile environment.’”
Asaf Kashi, vice president and deputy CISO
Collaboration across physical and digital security is crucial.
“I think sometimes the can be very siloed, but increasingly, there’s this understanding across Microsoft that it’s a blended threat—you can’t be good at one and ignore the other,” Gonzales adds.
Equally as important is the third arm of the triad: executive support.
Our Executive Support Team also works closely with other executive teams, both within the Microsoft universe (LinkedIn Executive Support as an example) and at other companies via showcase opportunities, to trade best practices.
“We notify and involve executives on threat actors and actions around areas of ownership. We tell them, ‘Here’s how to keep yourself and your team secure in an agile environment,’” says Asaf Kashi, a Microsoft vice president and deputy CISO.
Lesson 3: Stay vigilant and proactive
Cybersecurity is a rapidly moving target, which means we have to stay on top of the latest hacks and trends.
“It changes fast,” Mitchell says. “You need to be dynamic to keep ahead of MCAs.”
One way we do this is by reviewing case studies of attacks and benchmarking our security protocols against our peers and partners.
“It really does involve engagement with the industry and having a pulse on what’s going on there,” Gonzales says.
We also have to remind staff to remain vigilant in even the safest of environments.
“People are the easiest and most vulnerable link in the chain,” Pierson says. “You have to constantly remind yourself to be alert.”
This may mean trading some conveniences for peace of mind.
“Security is intended to be an inconvenience,” Gonzales says. “If it’s an inconvenience for you, it will be for bad actors. And so we need to accept the criticality of it, and do as we’re asked to do when it comes to our devices and our data.”
Key takeaways
If you’re looking to implement or upgrade your cybersecurity protocols, consider these tips for a comprehensive approach:
- Set clear guidelines and establish best practices. Information around updating your devices or signing into the network should be easily digestible and applicable to a broad audience. Getting everyone onto MFA solutions like Passkey will reduce your risk of account compromise by greater than 99%.
- Vigilance means making cybersecurity an ongoing initiative. Your efforts shouldn’t stop with one attack or executive event. Use every opportunity available to keep cybersecurity at the forefront for your team while learning about the latest trends, updating current policies, and expanding security measures.
- Share information widely and consistently. Make sure leaders and admins alike have access to resources for securing their devices and accounts. Consider hosting educational seminars or office hours.
- Partner with other teams. Take advantage of expertise across your organization to beef up your security measures, keep tabs on potential cyber threats, and spread knowledge.
- Adopt the latest technologies. Increasing velocity of AI-enabled cybercrime as well as highly sophisticated nation-state MCA activity means that the use of the latest OS and cybersecurity tools offer the best layers of IT protection possible.

