Making Cyberattacks Harder by Design

Summary: The Microsoft article addresses opportunistic attacks, which are launched by attackers who find vulnerabilities in systems. It presents best practices to mitigate these risks in the digital infrastructure.

Microsoft bets on “Security by Design” to curb the wave of opportunistic cyberattacks

REDMOND – In a strategic move to shift the balance against cybercriminals, Microsoft has announced a series of structural changes under the premise of making cyberattacks “harder by design.” The initiative, detailed this April 20, 2026, seeks to neutralize opportunistic attacks that exploit common vulnerabilities and default configurations to compromise thousands of organizations globally.

The end of ripe fruit: Fewer opportunities for the attacker

For years, attackers have relied on “opportunism”: looking for outdated systems or those with weak configurations that allow quick and low-cost access. Microsoft's new approach, according to its security blog, does not just focus on patching errors but on eliminating entire classes of vulnerabilities through deep changes in software architecture.

Key facts

  • Security is the foundation upon which infrastructure is built.
  • Opportunistic attacks are those that find weaknesses in systems.
  • Dynamics 365 and Power Platform are enterprise application suites integrated into Azure.
  • Prevention requires aligning defenses with principles such as SFI.

Why it matters

Opportunistic attacks represent a constant and highly adaptable threat. They are not based on zero-day flaws, but on exploitable weaknesses that can be simpler to find. Not addressing this risk can lead to significant security breaches and compromise business continuity.