Security Champion Worst Practices
Download resourcesAbout this session
Tanya Janca, secure-coding trainer and author of the Alice and Bob Learn books, argues that security champion programs are fashionable but that more than half of them fail, usually because the security team never sets specific goals: of the 53 organisations she has advised, only two had any. After a short case for running one (less friction with developers, culture change, scaling a small team, better hires, and measurably lower turnover and absenteeism among champions), she works through eleven worst practices and how to avoid each: an unsustainable pace, undefined responsibilities, voluntold champions, failure to recruit, unrealistic workloads, no management support, no metrics, unplanned education, unmotivated champions, awkward social settings and high turnover. Concrete fixes include planning six months of one activity a month, attracting volunteers with demos and pizza, a belt system and coverage metrics, replaying conference talks as group discussions, and rewarding champions visibly. A closing Q&A covers how to get business-driven developers to weigh security, using risk sign-off sheets and demonstrated exploits.
Security champion programs are all the rage right now, but they aren’t a magic bullet; they are a lot of work and more than half of them fail. We want to scale our security programs and improve security culture and communication, but what happens when are champions are less-than-enthused? There’s no support from management? We can’t get enough buy in? Let’s look at when things go WRONG with security champions programs, with this list of WORST practices, and how to avoid each one.
Key takeaways
- Write down specific, repeated goals for champions (triage the SAST results weekly, attend every threat model, relay one lesson a month); vague 'do some security' programs fail.
- Plan six months ahead at one activity per month so a security incident does not silently kill the program.
- Never voluntell champions; attract volunteers with demos, sneak peeks at tools, lunch-and-learns and a clear personal benefit such as a path to senior developer.
- Track metrics from day one: champion coverage per team, training completed, participation, questionnaire completion rates and inbound questions to the security team.
- Get real management support (budget, time, policy) with a project plan and ROI case, not just verbal approval.
Speakers
Tanya Janca, aka SheHacksPurple, is the best-selling author of 'Alice and Bob Learn Secure Coding’ and 'Alice and Bob Learn Application Security’. She is currently a full time secure coding trainer at She Hacks Purple Consulting. Over her 28-year IT… Read moreRead less
Tanya Janca, aka SheHacksPurple, is the best-selling author of 'Alice and Bob Learn Secure Coding’ and 'Alice and Bob Learn Application Security’. She is currently a full time secure coding trainer at She Hacks Purple Consulting. Over her 28-year IT career she has won countless awards (including OWASP Lifetime Distinguished Member and Hacker of the Year), spoken all over the planet, and is a prolific blogger. Tanya has trained thousands of software developers and IT security professionals, via her online academies (We Hack Purple and Semgrep Academy), and her live training programs. Having performed counter-terrorism, led security for the 52nd Canadian general election, developed or secured countless applications, Tanya Janca is widely considered an international authority on the security of software.