Building an Engaging Security Champion Program | DevOps Connect: DevSecOps 2023
Thinking about building a security champion program but not sure where to start? Do you have an existing program but want to take it to the next level? Looking for ways to maximize the engagement and motivation of your champions to take action to protect your company? If so, this is the session for you.
This session will draw on real-world experience building multiple security champion programs within AppSec teams and for clients. You’ll learn why you need a champion program, hear firsthand success stories and gain important tips from the Security Champion Success Guide (https://securitychampionsuccessguide.org/) for building a highly-motivating experience.
Dustin Lehr also discusses how the energy of your champion program can spread, tipping the scales to create a more security-minded culture across your company. CISOs, security leaders, application security pros, and security awareness advocates will all want to hear this!
Transcript
I am excited today to talk about security champions. This is, like Jennifer said, just something I'm very passionate about. Um, it's very, uh, interesting to me and fascinating.
Um, so how many of you know what a Security Champion program is? Let's start here. Okay.
Quite a few people. Um, I'll just give a brief overview just so you, we can all get on the same page. Um, basically it's, uh, contacting and, and being in touch with non-security people, um, to represent security on the different teams, right?
So those could be development teams. We also have a concept of security awareness champions too, so it's not just limited to development teams. Um, and there's, you know, kind of back and forth, uh, information sharing that goes both ways, right?
So you train up your security champions and then, uh, you can utilize your security champions to roll things out, um, support, DevOps, DevSecOps, et cetera. Um, like Jennifer mentioned, I'm actually gonna talk a little bit more about, uh, how to motivate your security champions, right? So this is beyond just what is the program, but more how to run and create a successful program.
So, let's dive in. Uh, but first of all, who am I? Um, so I was a developer for 13 years, so I wrote a lot of code.
Um, that basically means I avoided talking and meetings, uh, completely as much as possible so I could be heads down, right? So I did that in a variety of different industries, like I have listed up here. Um, when I was at Staples, I got the opportunity to join security and head up their AppSec program.
What does that mean? It means lots of talking, right? So I went to basically becoming a salesperson for security.
Once you become an AppSec person, you basically become a salesperson, right? Um, so I learned that pretty quick. Um, today I work for five Tran.
I'm their senior director of platform security. So we combine cloud security and AppSec into one team that I run. Uh, I also co-founded a company where we help, uh, build security champion programs.
No surprise. And then I do run that meetup that Jennifer mentioned as well join us. It's, it's actually different.
It's a, uh, open discussion, right? So it's not someone speaking at you, you're part of the whole conversation. Um, so definitely check us out.
We're on Meetup if you're looking for us. Um, alright, so I've spent a lot of years building Security Champion programs, uh, both helping clients, like I mentioned, but also, um, uh, in the companies that I've worked. And I took all those lessons.
You know, there's a lot of ways to kind of do things wrong. I took all those mistakes, um, and actually built a guide. Uh, it's completely free to use.
There's the website. Um, highly recommend checking it out if you're trying to build your own security champion program. Um, uh, yeah, just kind of distilled all my lessons down into that guide.
Um, so check that out. There's a lot of other great guides out there too. You've probably heard of these.
Um, security Champions Playbook is, is an old oldie, but goody o OSP thing. Um, there's actually another O OSP Security Champions guide that's popping up right now, just recently. Safe Code's, got information.
And then Chris Romeo actually built a, a fantastic framework that's ac uh, it's actually out on GitHub. It's free to use as well, and you can actually contribute to that one too. So that's another good one.
Um, there's a theme, okay, between all of these, uh, guides and, and playbooks, and that's how do you actually motivate champions, right? So you've recruited champions, they represent security on the different teams, but how do you engage them? How do you actually get them to be involved and excited and inspired by what, what, what you're doing?
Um, so that's what we're gonna dive into today. So the question is, how do we motivate champions? Okay?
Well, we're gonna kind of step back and talk about what motivates us as humans. Okay? What actually drives us, and I want to get into the concept of what I actually like to call human focused motivational design, okay?
You might know it as gamification, okay? Um, the whole idea behind it is, how many of you play video games to yourself? Some hands.
How about your kids? How many of your kids play video games? Okay, so that's probably everyone in the room games have touched our lives, right?
Um, the whole idea behind gamification is that, uh, the, uh, uh, the games that you play, you don't have to play them, right? But somehow you're motivated to play those games. Why?
What are some sort of techniques that these games are using to draw you in, to motivate you, to keep you coming back, et cetera? Um, the whole concept of gamification is taking those techniques and concepts and applying them in non-game situations, okay? So it's all about psychology, it's all, it's fascinating.
It's about human behaviors, what it comes down to. So, um, I'm actually gonna share my kind of secret weapon. Um, I discovered this framework a few years ago.
Uh, it's written by, uh, Ukai Chow, uh, and it's ba it's called Lysis. And, uh, it's fascinating because it, it basically captures eight different core drives that all human beings have. So we're gonna dive into each of those eight ones today.
Um, so let's go, uh, quick note on the framework itself. Uh, he didn't just make it up, right? It's actually refined by a lot of the concepts that you've probably already heard of, right?
From Flow Theory to, uh, the book influence to, uh, Daniel Kahneman's work. Um, so it's pretty neat. All right, so let's dive in.
So, core drive one is epic, meaning and calling. So the basic idea behind this is, you know, you're drawn to something that's higher purpose, okay? Um, as an example, the sign at your hotel that says, Hey, save the planet by reusing your towels, it doesn't say, Hey, save the hotel some money to wash your towels, right?
It says Save the planet, which makes you feel okay, like, I'm contributing, right? I'm contributing back to the world. Um, so how does this apply to your security champion program?
As you're recruiting folks, emphasize, you know, their calling make it feel like, hey, there's more meaning in what they're doing. Um, maybe you noticed something that they did that was security focused. Um, and say, Hey, you know what?
I noticed what you did. That's fantastic. You clearly have an eye for security.
Come join us. Security Champion Program, right? The other thing you should emphasize is, uh, the higher purpose of security, right?
Why does this security champion program exist? Cuz we're trying to protect the company, right? So kind of introduce those larger concepts in order to motivate people.
Core drive two is development and accomplishment. Grab some water here. Um, so the idea here is, uh, kind of the dopamine hits that we all get when we achieve things, right?
So the example I like to use is actually Fitbit. I have one myself. When this thing buzzes and tells me I did 10,000 steps, I get a little, you know, dopamine jolt.
I'm like, okay, cool. I'm actually accomplishing something today. Fantastic.
Um, so how does this apply to your champion program? Um, highlight wins, you know, as people are, as accomplishing things, as they're doing things. Maybe, uh, helping, maybe identifying phishing emails, whatever it is.
Um, recognize that, right? Uh, you could also kind of gamify it using points and levels. We'll get into that later.
But, um, so that's a, that's a human drive motivator. Uh, core drive three is empowerment of creativity and feedback. Okay?
Emphasize the word empowerment. We like to feel like we're in control of something, right? So how many of you recognize what that image is?
This is Minecraft, okay? Uh, what would possess somebody to spend so many times you have to, you actually, you actually have to build that block by block. What would possess somebody to spend so much time to do that, right?
Because it's a creative outlet. You feel like you're in control. You feel like you're empowered to build something like that.
Um, uh, so how does this apply to your security champion program? Consistently request feedback from people, right? Make 'em sort of part of it, uh, uh, make them feel like their ideas matter.
Um, and then, uh, I see, I see a little trick that that's used in presentations sometimes. And that's add what kind of fills to your presentations. What would you, uh, put there?
It's actually blank fills. Okay? So the reason that it's recommended to add those types of things to your presentation is because it engages people's minds, right?
Makes you think, oh, what word should go there? Hopefully most of you experience that just now. Uh, cord drive four is ownership and possession.
Uh, there's this thing called the Ikea effect, um, which basically means when you spend the time to build something that you bought from ikea, you now feel a stronger sense of ownership, right? About it. You're prouder of it, right?
You, you brag about it, it's in your living room. Every time you see it, you think about all those hours you spent to put it together. Um, so you have a strong sense of ownership.
Um, how does this apply to a security champion program? Um, have your champions build something together, you know, make 'em feel like they own it. You know, it could be like a shared library for off and off or something like that.
Um, and also emphasize pride in your, in, in their own team's security, right? So they're representing security, uh, for their team. You know, make 'em feel that sense of ownership.
Like, uh, emphasize wins for that team and, and, and emphasize the fact that because they're a security champion, that they had something to do with it, right? It gives 'em a stronger sense of ownership. All right?
Next one is core drive. Five, social influence and relatedness. Um, we're social creatures, right?
Is what this comes down to. We care about what other people think. Um, we care, you know, if there's like a mass move towards something, et cetera.
Um, we're gonna notice that. And the concept that I, uh, like to use for this is called the Petrified Wood principle. All right?
Petrified forest, they're having issues because people are stealing the petrified wood, right? And they want people to stop. So they put up a sign that says, many people, a lot of people are stealing the petrified wood.
Okay? What do you think happened? More people stole the petrified wood.
Okay? Why? Because they normalized the behavior, right?
They said, Hey, there's many people doing it. There's a lot of folks doing it. So naturally people say, well, okay, if a lot of people are doing it must be socially acceptable to do it, and more people end up stealing the petrified wood.
Okay? Fascinating. This is like, humans are just kind of silly sometimes with the things that we do.
Um, one of the examples, uh, that I actually like to use here for security champion programs is a lot of times what you'll do for champion programs is, uh, you'll have like a monthly meeting, like a brown bag. You get all the champions together. You talk about security concepts.
Um, there's a lot of cases, and this doesn't just apply to security champion programs. It could be like, there's a quiet audience, but once you say, Hey, everybody seems quiet today, how come nobody's responding? You've just normalized that behavior, okay?
People are less likely now even less likely to say anything at all. Okay? So instead, flip it around.
Emphasize when people are speaking up, right? Normalize that side of it. Okay?
Um, yeah. So let's move on to cord drive six. This gets interesting.
So cord drive six is scarcity and impatience. And, uh, the idea here is that abundance is not motivating. Okay?
If you have enough of something, you're not gonna be motivated to go get more naturally, right? Um, there's this fascinating thing that stores, uh, like grocery stores will take advantage of. Let's say you need a bunch of bananas, right?
You show up to the store, you're like, I need one bunch. Uh, otherwise they get all brown and, you know, soggy, right? Um, but there's a sale, okay?
Half off bananas limit three, how many do you buy? Three period. You only need one, right?
But because they're on sale and because there's a limit, we're drawn to get as many as we can because we feel like, hey, they're more scarce, et cetera, right? So, um, so in terms of security champion programs, reward the first few to attend, right? Use something like that.
Like, hey, you know, limited time if you show up, you, you get this thing, whatever it is. Um, you could also use concepts like VIP invitations, right? Maybe only certain champions who have demonstrated that they're involved in the champion program get invited to certain things, okay?
Core drive seven is unpredictability and curiosity. How many of you recognize that? Where's my laser?
That button right there. Anyone app? What app is that?
Netflix or whatever, right? Um, uh, how many of you have pushed that button way too many times into the night? Yes, I know we've all done it.
I've done it. Uh, how do you feel about it the next day? Basic regret, right?
Like, I binged watched again. I, I regret it, right? Um, so how do they do that, right?
They, they, they give you those cliff hangers. They make you curious what's gonna happen next, right? Um, so they kind of hook you that way.
Um, how do you apply that to a security champion program? Think about your invitations to the meetings, right? Are you saying, are you just telling 'em what you're gonna talk about?
Or are you trying to draw their interest? Um, you know, through questions like, Hey, have you ever wondered how a phishing email actually leads to an attack? You know, you kind of peak people's curiosity in that way.
Um, and also there's some randomness, right? So having random prize winners, right? For just showing up, whatever it could be.
Um, core drive eight, this is the last core drive, is loss and avoidance. Um, this is a fear of losing something, right? So there's actually an alarm clock that will shred your money if you snooze too many times.
Okay? So motivated to get outta bed at that point. Absolutely, right?
You don't wanna lose something that you already have. Um, so there's a little trick I like to use with, with the security champion programs that I recommend, and that's having people start with an a hundred percent attendance badge or booster or status and say, Hey, you already have an a hundred percent attendance, right? Booster.
Uh, now if they miss a meeting, they're actually gonna lose that, right? So they're more driven to actually show up to the meetings in that way. All right?
Um, so what's kind of fascinating to me about this whole framework is that it's actually laid out in a way that's smart as well, right? So the left side, these are all extrinsic motivators, okay? There's has to be something outside of yourself, um, to actually be motivated.
The right side are intrinsic motivators. You don't need some sort of extra reward. Like we talked about Minecraft before.
Somebody builds something that's beautiful, uh, within Minecraft, or you build something with Legos or you do some piece of art, whatever it is, you don't need someone to give you five bucks and say, Hey, nice work that looks good, right? If anything that might detract from the effort that you put into it, cuz you're like, this is only worth five bucks. I thought it was beautiful.
Um, so that's smart. The other, uh, the other thing that's that's, uh, laid out here is there's actually a difference between the top and the bottom core drives as well, right? So the top ones are more sustainable.
Um, they, but they don't create urgency, okay? So, you know, you take your time when you're building Minecraft or whatever, uh, you take your time when you're sort of accomplishing something. Um, the bottom ones are urgent.
They create a sense of urgency. So let's go back to the Netflix example, right? There's a cliff hanger.
You want to know what happens next to that character. Uh, you need to know right away. You're not just gonna say, oh, I'll just figure that out tomorrow.
I don't really care, right? So it creates that urgency, but it's also unsustainable because you feel uncontrolled, right? Like you're out of your control, right?
Um, so a lot of times you'll end up start starting to avoid getting into that, uh, spiral. All right? Let's talk about rewards.
Cuz these are also motivators. I find a lot of people who build security champion programs, they just use swag, okay? Which is fine.
Uh, you know, hoodies or hey, show up to the meeting and have a meal, we're gonna provide a meal for you. That's fine. But we can go beyond that.
Okay? So there's a concept in gamification called SAPs. It's very easy to memorize.
Stands for status, access, power and stuff. These are different types of rewards that also work very well. Status, pretty straightforward, right?
You give someone a title, you call 'em a guru at something, makes 'em feel important, makes 'em feel like they're part of something. Um, access, we talked about that with scarcity. Uh, so v i p events, et cetera.
You know, you can earn your way basically based on your contributions into something, whatever that is. Um, power, the ability to make decisions and be part of it. We talked about that with feedback and then stuff of course.
Alright, so I wanna kind of break down. The, uh, company I work for is, uh, security champion program. Five, trans security champion program.
Um, pretty basic gamified setup that we have. We, we have points that you earn for each security focused action that you do. That could be identifying an email.
It could be showing up to those brown bags that I was talking about earlier. And then your points actually determine your level. Okay?
So we use a karate belt level from white belt all the way up to black belt. Um, when you level up, you basically get some sort of SAPs reward, right? That could be a material thing, it could be an invitation to something, whatever that is.
Um, points last a year, okay? Why points actually expire. And the reason is because if someone reaches the highest level, what, why would they be motivated to continue, right?
They've already reached the highest level. So there's a little bit of a maintenance involved in that. Um, but that also means that your level might drop, right?
If your, if your points are expiring, you could go from black belt down to brown belt. That's demotivating, right? Oh, I spent all this time and now I'm just brown belt again.
Um, so we actually have a booster where you earn twice as many points to get back up to your highest level quicker, okay? So it's a way to kind of motivate people again. Um, and then we actually have a mentor program as well where, you know, you basically pair up between mentor and mentee and mentors get half the points of their mentees.
Um, so that's a motivating thing as well. All right? So I want to share a few success stories.
Uh, it's amazing, uh, some of these things. Um, we get people to request to join our program without invitation. We used to have to go recruit people, you know, Hey, can you please join our new program?
I know you know nothing about it. Now people are reaching out to us, right? Cuz they've heard about it, they've seen the levels, the points and all that stuff that other people are acquiring.
They want to be part of it. Um, so we have very active security champion, uh, meetings as well. Um, as well as a, as a very active slack channel.
People are contributing. They want to contribute, you know? Uh, and it's great to see because these are non-security people, again, getting involved in a security initiative.
Amazing. You know, as a security person, this is like a dream come true. Um, a couple of black belts have done a few amazing things.
One of 'em is some, one of 'em started a, a focus group and they meet every single, uh, month. And they talk about security. Again, non-security, people talking about security.
Uh, we have a black belt, uh, who also started a book club. Nobody asked him to do it. He's, he set it up, he picks the books, he runs the whole thing.
Uh, it's amazing. Um, so, and then, uh, we also have managers asking, you know, how, how can I get my whole team up to black belt? Um, which is great too.
So the point here is you can't force this, right? You, if the CSO or some security leader came up to somebody and said, Hey, can you start a security focus group? They're not gonna care, right?
They're gonna say, uh, okay, you know, maybe they'll do it because the C level asked them to do it, but they're not gonna care beyond that. Um, so they, this all has to be inspired, right? Which you can do with the techniques that I shared before.
Um, so yeah, the takeaway today would be that you can change your culture toward security through your security champions, but it requires engagement, which you can inspire through gamification. So that's all I have. Thanks very much.
Appreciate it. Hey, do we have any questions? That's what I was for Dustin, if anyone has questions come on up to the mic.
Does your organization tie compensation or bonuses to the level that security champions? Are there any financial incentives and what do you think about that practice? Yeah, Uh, we do not do that.
Part of it is because there's a lot of organizational hurdles to try to create something like that. You have to work with hr, you have to kind of set all that up, right? Um, so we've not had success there.
I, I think it's a good idea, but I think you have to be careful as well, because if it's not the right amount, you know, it, it could be somewhat demotivating, right? Like, hey, good job, you're a security champion. You did these things.
Here's 50 bucks. It's like, uh, that doesn't help, right? Um, but I have heard of other companies do that successfully.
And one other thing I've seen done successfully is, um, adding like a, a title as well, like official title. Like, Hey, I am this position, but also I'm a security champion. So yeah.
Dustin, do you have problems getting security champions involved in the program itself? Yeah. So this kind of goes to some of the, that's a great question.
Uh, this kind of goes to some of the concepts of um, how do you initially create a security champion program? Um, you know, when you're recruiting, it's, it's really all about finding your allies, right? Finding folks who are out there that are kind of naturally inclined to be involved in the security champion program.
It could be a very small amount of people to start with, okay? But then you're rewarding their behaviors. It starts to become part of the culture.
It starts to catch on. Um, it's a diffusion of innovation thing. Have you, have y'all heard of this concept?
Um, there's a sort of n normal curve. I might actually have a slide on this. Uh, cuz I do like to talk about this a lot.
I don't today, but I typically do. Um, so you start with innovators and first adopters, right? And then as the culture sort of catches on to the idea that you're doing, you reach a tipping point that actually ends up reaching the masses.
So yeah. Any other questions? Yes.
Um, so the question is really around, um, did you have initial metrics that you set up that you're tracking and how long did it take for the people to actually demonstrate the actions that we wanted them to do? Is that right? Um, yeah.
So, so we did set up metrics from the beginning. Um, and it actually goes to a slide that I just flashed up here because, um, one thing that we kind of try to think through is how does this type of program evolve over time? We do want to get to the point where the security champions are influencing the organization enough to make a difference to the security bottom line, which really goes to shift left and sort of preventing security issues, right?
But you don't start there, you start at the bottom. Okay? You start just by connecting with folks, getting out there, talking to them about security, starting to educate them and train them, which takes a while.
Um, and then eventually getting them, them more involved in the rest of your security program. Okay? Multi-year easily.
Okay. First year is typically connecting educating folks. Um, I've been into programs that are, you know, three plus years.
You do get to the point where you can utilize your champions to make a bigger difference. Um, but I do recommend, uh, measuring this stuff all along the way. You know, measure participation or connection actions.
Are people showing up? What's the attendance like? Uh, we have surveys as well, uh, that we send out to understand what people thought of the sessions, that sort of stuff.
So yeah, that answer your question. Okay, cool. So Dustin, what do you see as the return on investment to the business for security champions?
That's a bomb that Chris just dropped on me. It is, uh, it's difficult to measure perfect causation between the actions that your champions are taking and the security bottom line. So let me talk about that a little bit more if I have time here.
Um, what you can show though is correlation. So what I like to do is set up metrics from the very beginning to understand not just what the champions are doing, but what, how the environment looks. You know, are people doing threat modeling?
Are people doing certain actions that you want them to do? Um, and also what, what does it look like in prod? How many prod issues are there?
What are their root causes? Like understanding kind of the environment and then introducing things like training and security champions, et cetera. And watching the needle move, right?
And making, uh, making conclusions based on, hey, you know, it could be even like fishing as an example. Is there a correlation between the fishing reports and the points that people might have earned, right? If there is a correlation, you can show that there's a strong correlation between the two, then you know that the more people that are involved in your program are less likely to fall for phishing emails, right?
But it's always gonna be a correlation. You can't show a direct causation. It's the same thing with training as Chris knows too.
Um, you know, you really can't say, Hey, you know, this developer, he was about to write a bad piece of code, but since he took that training last week, he didn't write it. He wrote a different piece of code. How could you ever approve that?
Right? But we, you can show correlation between the two. The people who are more trained are less likely to have those security bugs in their code.
That's what it comes down to. So thanks everybody. Really appreciate it.
Yeah.





