How Security Champions Can Accelerate DevSecOps | DevOps Onramp 2023
As more organizations embark on their DevOps journey and want to embrace DevSecOps from the start, they’ll need help since security people can’t be everywhere applications are developed. Help comes in the form of a Security Champions program, which can create a more security-minded culture across your company. Our panel, moderated by Techstrong Research GM Mike Rothman, will include success stories and tips about what to do (and what not to do) from those with first-hand experience with security champions.
Transcript
here Hi everybody, Mike Rossman here general manager of texturing research for our devops on ramp session about security Champions. I'm gonna give a couple of minute overview of why security changes are important. I'll introduce our people and then we'll jump in because there's lots of stuff to do especially for folks that are first getting going in devops.
You've all heard the term Dev set ups and you're probably trying to figure out what is that even mean besides I got to talk to these nasty security folks all the time. We're telling me all sorts of things I shouldn't be doing. So we're we'll get there right we'll get there.
But the fact is the concept of a security Champion is really to democratize the idea of security within a lot of the development teams within a lot of the operations teams because at least from what I know about developer training don't come out of the womb understanding how to secure code. They don't You know kind of get understand what are the best practices for, you know building their code in a secure fashion and a lot of cases. They don't understand why it's imperative to the organization.
So we found an experience that security changes program can really accelerate and put some structure around why it's important what to do to talk to when you get confused. What is you know, this thing that got kicked back from the build and I don't really understand. I don't have any comments for what I did wrong, right?
So security Champions helps to address a whole number of those days, but we will begin to that ad nauseam over the next 45 minutes or so, but first, let me introduce my esteemed panel. I'm just you really as a facilitator. I may have an opinion or two.
I've been having opinion or two, but I'm really the facilitator here. So let's go around and and get everybody introduce themselves when we start with you Dustin. How are you today?
Great. Happy to be here talking about Favorite topic, I would say security champions. So I am a senior director of platform security for five Trend.
I actually have a little side business where I help people build security Champion programs and I also run a community. Let's talk software security where people show up and we have an open discussion about security. So that all keeps me quite busy, but that's a little bit about me happy to just happy to be here.
That's great. Thanks Dustin. I love the side hustle, right?
We all have to have our side hustles nowadays because you know, We're not busy enough. So let's add some more stuff. Olivia Rose a friend of mine.
Thank you for joining us. Once you introduce yourself. Tell us a little bit about what you have going on.
Hi everyone. I'm so happy to be here security Champions have become very in Vogue lately. This is the third time I am speaking about it this month alone.
Whereas I didn't speak about it for about two years before this is something's in the water. I mean three times see so Burned out completely admit it just like a lot of ceases did late last year went and made my side hustle into a money-making business, which is what I'm doing right now. I run my own virtual siso company started in January knock on wood going extremely well, and we catered to Fortune 1000s delivering real virtual see so Services by ceases I see shows that's a great thing.
So Olivia welcome Chris Romeo. How are you today? Why don't you introduce yourself?
I'm doing great Mike. I guess I need to get a side hustle. That's what I'm learning.
I don't have enough going on and everybody else has side hustles, but I'm the CEO of curventures and I was previously at security Journey company, I co-founded and then we had an exit back in 2022 before that. I spent 11 years of my life at Cisco where I ran Cisco's security Advocate Program, which is just another word for security. So I today I consult with different companies on security Champions and really just help friends in the industry that are trying to grow their programs.
And I also created something called the security Champion framework, which I'll probably bring up in the midst of the conversation because what I tried to do there was take everything that I had learned and a number of years and just reflect it back into something that's open source that the community can just consume and hopefully add to overtime. Now, that's great. So as you can tell we have a number of folks here that have been there and done that and that's really what the approach is right try to get.
Everybody out there in the audience in front of some folks who have done this before so you can learn from both their successes as well as some of the challenges of pitfalls that they you know, kind of run into and I certainly know all three of these folks have enough road rash and scars to you know last for a couple of months. We don't have that much time to go through all of the stuff but let's kind of start at the highest level, right? Let's assume that nobody really understands alluded a little bit to what you know security Champions are about Chris talk a little bit though, since it is kind of your side hustle in terms of you know, helping organizations, you know, build out these programs when you're having a call with them and they're like, why am I talking to you again?
Right? What is it that you say, right? How do you kind of position this program within the context of their you know, kind of devops motion and give them a sense that this is really something that they should be paying attention to.
Yeah. It's a is a great question and you kind of touched on it when you first sort of introduced the whole concept, but I think the point here is Developers typically aren't trains when they're educated in coding and secure coding. Okay, so you have a pretty major.
Gap in knowledge across most organizations when it comes to developer security and it's it's really about getting the developers to the point where they are trained and they care about security and you have to do that incrementally, okay. The culture that you're walking into when you create a champion program is not one where people are taking this stuff seriously naturally, so you have to introduce that sort of culture change to the organization and one of the best ways to do that is to find your initial allies is what I call it across your organization who kind of they have an inkling to care about this like they're naturally sort of drawn to the security side, or maybe even just the quality side. Um, they care right they want to do things right they want to do things better and finding those people and having those people be initial what we would call Champions getting them more involved spending more time with them and eventually having them help and represent Security on their own individual teams is a good way to take that off.
Okay, so that's that's what I would say is the purpose behind it. And then you would mature from there. Right?
So you'd mature your security Champion program. You eventually get to the point where you have at least one developer on each development team as a security Champion, but you don't start there, you know, you really just start by find your allies start the conversation start the culture shift. And then I guess and Chris given the fact that you built this for small company that maybe has a couple of Engineers, you know, folks building code out there.
You know, where does some of the impetus come from is this was this a Bottoms Up thing where folks like oh crap. We don't know anything. We don't you know, we got to get better at this was this somebody maybe you see so type that was sitting there saying this is a total mess and it's not gonna get better unless we need to get take a more strategic view on on how we do this.
What was the Genesis of the program that you don't when you were at Cisco? So the Genesis was really Bottoms Up and so we're going back to you know, 2009 2010 when this is happening at Cisco. So, you know, the whole shift left and focus on app SEC and and all those things we just weren't there yet and Cisco wasn't there yet.
And so it was really very much a Bottoms Up approach, which is really how I like to approach these things anyway, because I like to get the people on the ground kind of excited about it. And then the funny thing is Eventually some executive will say well this I have a good idea like oh, yeah, that's a great idea. We've been doing it for two years now, but please take credit for it and and now get us budget associated with it.
So, yeah, I think the the bottoms up approach, you know kind of almost like gorilla like on the ground and you know funny story like when I first picked up the Cisco security Advocate team, I literally went out to San Jose where Cisco has numerous buildings and I went Cube by Cube. I had a list of people and I went Cube by Cuban. I literally knocked on people's Cube doors and I said, hi.
My name is Chris and I'm trying to get our security Advocate thing going again. Will you help me and you know, there was it was just it was a it was an interesting experience. I got to meet some people some people look to me kind of funny like who the heck are you why you wet my Cube door, but I did get a Core group of people that could help kind of begin that Grassroots effort to really push this thing up.
Yeah, that's good. I also I kind of Wonder now in this weirdo virtual reality that we kind of live in I mean, How does that approach really matte to it? Because are there cubes for a lot of these, you know kind of teams that were working now?
And and how do we have to start changing, you know kind of that approach now that you know kind of what interacting both, you know kind of as teams as well, as you know kind of as an organizational we'll tell that for a second because I know Olivia's built a number of these programs in her, you know Journeys at the Cisco side of things. So so again looking at it from a security standpoint right where you having to advocate for these things, was it something that Developers for talking about did it come from Executives was it bottoms up as Chris, you know talked about was his experience love to hear a little bit about kind of what you had done when this was, you know, kind of part of your purview what all depends on the specific company and each company has different needs as to why they need a reason as to why they need a security Champion program. There are many companies.
There that do have informed coding and secure practices of secops and so on in place at that point, it could possibly be that they need to integrate better with security security may have a brand reputation of being the place of no at that point that often happens. And so the deaf secops group has gone over there is now doing their own thing and is not integrated with the security team. So that's where The security Champions program comes into play but then you also have the situations.
I think Dustin mentioned it where they really don't know. They they're not even familiar with the OS top 10. So you need someone in there on the ground.
So I really find the two biggest reasons these programs fail and they fail a lot. I don't know that I don't have the specific stats. I have never been able to find them but they fail a lot because it's too specific reasons one is There the program is set up to be just not customized by the Target and users and what they specifically need.
If you're going if you're bridging out past devops marketing is very different than technical teams and how you approach and what you need to help them with. The second reason is wrong choice of security champion. It's better in my opinion and what I've seen out there it's far better to get somebody.
Who's that? I call it the nosy neighbor. There's always these people at organizations who talk with everybody and they're the connectors and then they're the ones who always go a little bird told me because they are told all these random things that nobody else is told because they talked to all these random people.
They're the people you want in the security Champions program because you can learn security. However, the drawback from that is sometimes technical teams can be extremely tough and rough on people who they think don't have their knowledge level, right? We hope all heard of them right the situations where they kind of play little games on the people who they don't perceive as knowledgeable.
They are so it's very dependent on the culture. And what you ultimately you need the the program to achieve? Yeah, well are there numbers, you know in terms of so, you know, we talked about Bottoms Up the bottoms up is great.
But but Chris you're at your point about you know, kind of at some point somebody has to take credit for the idea and and believe me. We've all been on the other side of that. It's like oh, yeah.
Hey that was a great idea my idea five months ago, right or six months ago, but you know, that's not the game is played and and we got to acknowledge that on that front. But at some point media track it based upon, you know, General reduction in security issues, you know, kind of builds that are bounced, you know, kind of folks that are trained right? So can we start thinking about again substantiating and making a case for why this is an important especially we get into some incentives, right?
I mean because folks don't like that. I mean, maybe we're all just crazy to take on side hustles because we don't have enough to do but you know, most developers aren't sitting there going. Oh, yeah through my All the time and nothing going on for me and jira.
So I'm just gonna you know, take something else on so so we do need to think a little bit about you know, kind of how we're going to send these programs. But before we get there, right, how do we kind of start talking about the actual quantifiable benefit to the organization, you know of these kind of programs. I'll just throw it out there anybody that you know, kind of wants to fire off first and can run with it.
I mean, I'll share kind of a best practice that I think enables the tracking of metrics. So one thing that I've done and that I highly recommend is have a set of goals for your Champions every year and so I think of Champions like signing up to be a champion is a year to year sign up. I'm never ask anybody to do a lifetime commitment because a lot of times that's what it feels like to them.
They're like, oh, I don't know that I want to do this for the next five years of my life. But what I like to do is I like to create a set of goals that are very much achievable and then I can provide metrics off from those goals. Like one of those goals is gonna be tied to my education program.
So if we're doing a multi-level approach to education one goal is hey Champions got a lead from the front and so you're gonna have to you're gonna have to achieve a higher level of Education than we're asking the rest of engineering to do and then we may have other goals like attend whatever whatever our functions are and then I always like to focus on one particular thing like threat modeling is always a good thing to start with like have a goal for doing some Modeling so for me it comes down to the goals tie into the metrics and then I don't have to and I have to go hunting for other Enterprise Metrics. I can metric within what the program that I'm building. Yeah show up, right?
I mean, you know, and I think what we do learn although it's debatable biasmosis, right? So around there to Olivia's point about the connectors who are always in there and that's totally not me. So I'm constantly surprised by when somebody says hey, you know, what's going on over there?
Like no. I got my head down here. I'm doing my work.
I'm not you know, I don't really, you know, kind of mess around with a lot of that, you know stuff but you do need you know, folks who do that. So so Chris I think you know kind of the, you know, give it points for showing up I think is is a key aspect of that and to provide incentives for that. I mean Dustin if you've seen, you know, some other ways to quantify these programs.
Yeah. I think that's kind of where I was headed is, you know to start by just getting them involved right start by measuring things like participation and attendance in the meetings and Providing trainings and that sort of stuff and then eventually, you know, there's really different phases of maturity here, right? Because I think eventually when people understand kind of what security is why it's important and why they should be doing things maybe slightly different then you in my view, then you can set more ambitious goals and you can actually utilize your Champions to roll out initiatives or You know contributes to the bottom line solution ultimately and I think it's important to measure that too.
I think that there's a there's a return on investment that you're gonna have to continuously show with the program like this and measuring that is not easy because a lot of things it's very much like training right? It's hard to draw the direct. Causation between someone who's involved as a champion and the contributions that they make, you know, the example, I always use is like with training, you know, you train and developer great.
But how do you show that that training actually had an effect on the code that they you know, hey, they were gonna write a poor piece of code. But because they had that training they didn't write that piece of code. They wrote a different piece of how could you ever prove that right?
So my methods are around correlation right trying to show that. Hey the Champions that are more educated, you know, you can show correlations between hey, you know, they take more training they do this and they have less bugs in their system. You know, can you can you say that's a direct causation you really can't but it is quite a case if you can draw a strong correlation.
Yep, that's it. Stop yummy. Listen, we all know you can make stats dance on you know on the head of a pin if you wanted to right so but I do think that sales concept.
I think one of you already said, you know kind of yeah Olivia things you write that you end up having to to sell at some point and I've been a big proponent of get out of your Cube. So Chris, I love your story about going around and knocking on, you know cubes and and listing for help because again, I think that, you know One technical folks and and especially a subsect of that insecurity, you know, tend to you know, be somewhere on the Spectrum at least some of us on that front. So so not you know kind of all excited about engaging with a lot of folks.
I really think that that's really a fantastic idea which is to go get that FaceTime start to build, you know, some Rapport right and and some relationships with these folks and and really kind of get them on our side one thing. I want to kind of dig into a little bits. Where do these Names fit into the organization, right?
So so Olivia's that's something that you know kind of has to be under the purview of the ciso. Is that something that's within, you know, the the CTO or the development person's organization, you know kind of residing with it devops. Is it a joint squishy type of thing that you know kind of it's not clear who's actually accountable for this at any given time again and the times you've built these things where where have these you know kind of programs lived always Under the Sea so And maybe that's because I'm controller decision, but I think that they do tend to work best under somebody who understands the value.
However, you do need to have buy-in from the executive board in general leadership team or else is not going anywhere and you also need buying from the CTS who likely oversees the the tech teams that you trying to to deal with so you do need a very strong partnership, but I like owning it. Others may not agree with that. But they're definitely needs to be an owner.
Somebody needs to keep the excitement alive things go to choke you bet. I think yeah, I mean the folks who have the largest state in its success would be the owner and I think the ciso is the natural fit for that. I think abstract teams typically run application security teams typically run programs like this because they're trying to change the development culture.
But I've also seen it on the security awareness side too. And I kind of want to expand our conversation a little bit toward, you know, is there such a thing as security awareness Champions? That should be within your organization.
Well, I would say so right if you want to reach people with the Fishing message and the file sharing message and the password message, you know, all of those awareness topics. You can utilize Champions to do that as well. Yeah, you know that that's an interesting point right because you know and listen I spend almost every day with you know, kind of devops and Cloud native folks and the security folks that are trying to understand what the devops in the cloud native folks are doing and keeping everything, you know relevant from that scene, but I do think that you know kind of give in the both high profile nature and universality of a lot of the issues that you know kind of we Face from is again folks clicking on the wrong stuff, right?
So it's not just you know, the developers and we kind of pick on them because you know again when you think about it from the devops context there, they're the root of most of the issues I say that kiddingly right? I mean, I don't really think that that's the case but for security folks it's easy to vote, you know kind of phone and almost everybody from that statement. So I think that's a great point that a lot of these General kind of tactics, you know can be used to Build out a program that's more inclusive than that.
Everybody has had any experience with like a center of excellence model where you know, you end up having a number of different resources that end up getting shared and leveraged across a number of these devopsies. And the reason I bring it up is because you know, I was doing an assessment with a fairly significant, you know Financial organization and they had over 200 different devops teams that were working on On Any Given thing, right? They had well security Architects right that we're you know, trying to work with a bunch of these teams, but the numbers just didn't work, right, you know, each of these devops teams to work on Pride three or four different initiatives and you know, you've got just 12 of these folks that are trying to handle that and and the math God got pretty ugly right so they were looking for leverage and you know, we kind of brainstorm this idea that well if we moved a bunch of these best practices into a center of excellence, then at least folks know Where to go to right?
They know who to ask. It's not like, oh, let me call Olivia. I know her she's the ciso right or I know it doesn't spill, you know kind of these programs for for us or you know help consult on that front.
Um, so I don't know is there any you know, kind of logic or leverage in in that kind of concept? I've got one example. I always done it.
Oh just real quick, Chris. where human beings if you look at the psychology of it human beings want to do the right thing, if you know, you have the rotten egg here and there right but Even you know devops they want they don't want to launch insecure code into production, right? It's not something that they wake up wanting to do human beings want to do the right thing.
They want to have structure and they want to have directions easily available and they will go to a shared repository or Center where they can get those things to do. The right thing. The only times it doesn't work is if it hinders hinders their performance Which security is sometimes known to do unfortunately or it's or the guidance is not clear or it's not it was too complicated to follow.
So I'm a big fan of it. Just make it very clear quick and easy to use and people will use it. It's the psychology of human beings of human nature.
Merry Christmas, I know you're about to jump in. Yeah, just have an example of a company that's doing the the center of excellence idea that you're talking about. So I live in Raleigh, North Carolina.
There's a company here at SAS. That's an analytics company most people have heard of them. And so they've they've created this thing called Product security leads and it's this idea that they have kind of these these product security folks that are then embedded in the business and are the conduit to the business, but they're not really Champions.
They kind of sit like at a level almost at the top of the pyramid if you're gonna make a pyramid of Champions and so Brenna Leaf is is the lady who has had run that program and so people can go dig into that. She's she's spoken about it in public. So that's just an example of that Center of Excellence model.
It's it's different. It's still it's still kind of in the Champions bubble, but it's like a different spin which is why you know, I I talk to her for a while. So I wanted to learn she was doing something different than kind of the classic Champion approach.
Yes position my own teams to be what we call like security Partners right where each at least that the architect level each member of the team kind of has their own business vertical that they support and it ends up creating the same type of thing, you know, there's sort of a center of excellence within each of those business tiers. I would also say this that I think I think we find ourselves as security teams being connectors because we have you know, we have conversations with multiple development teams. We can kind of see hey this team is doing something similar than this team.
Those teams aren't necessarily talking to each other but we're talking to them. So we start to, you know, kind of be that Central resource and I think that drives, you know, better quality overall and also kind of the center of excellence idea. Yeah, that's right.
So I love it and we'll have one more thing and then we'll go into the who because I want to make sure we're we're fairly clear about you know, when we're targeting, you know kind of who can participate in this program. What is it that we look for so I want to make sure you know, we spend a decent amount of time on that. But but you know, we talked initially and everybody kind of agreed that this Bottoms Up concept is um, you know, where you where you want to kind of try to initiate things get folks, you know, kind of bubbling up understanding building your allies, you know down at different yet.
It doesn't always end up that way right and and I'll say that, you know kind of I've had a hand or two in, you know, kind of an assessment finding that says your developers have no idea what the hell they're doing and you really need to start an initiating this kind of program and you know to see so or somebody else goes. Oh, let's do that. Right and it lands in somebody's lap that says you're gonna do Security Programs and we're gonna do it now because this dude's gonna show up and another six months that the main progress man, you know, I just don't want to have that conversation.
So what are two or three things that we can do fairly early on when the Mandate comes from on high that you are going to do security Champions, right? We don't have time to go to the cube. Right?
We don't have time to you know, kind of build it right didn't get feedback because it's been mandated, right? So so where do we start in that scenario? you know, it's it's important to not rush it because you have to take a step back.
There's a lot of human psychology that goes into an effective security Champions program and if you mess it up, If you try to launch something too fast, and you mess it up it's done. It I don't see how you can come back and try to revive a security Champions program for a what for for quite a while after because people were remember the disaster that it was and the waste of time and energy and resources and budget and all these things. So it's critically important to step back and think of it from a human psychology perspective as well, which is often missing in these these programs.
And I can add something here. Like one of the things I'm looking for right away is we need a security passionate person to lead it. We need a community Builder we need to connector because I've seen programs where the wrong person was chosen to lead it and maybe they are the smartest technical person you've ever met but they don't know how to like like this is a different skill set.
Like I hate to break it like this is gonna hurt a lot of security people's hearts out there. But if you're running a Champions program, we're in sales and marketing right? Like that's what we do.
This Champions programs are about selling people on you should be a part of this. It's about marketing. It's about communicating we're doing this.
We need to be a part of it like it's not a highly technical job. It's much more of a community building job. So you have to have the right person if you put the wrong person in that seat who maybe is the smartest technical person you have they're not gonna be able to be successful.
Yeah. That's right. That's right.
That's right. Well, let's dig into that a little bit right because you know, the who is important so they need to be connector, but they're two pieces right one is Who leads it from the security standpoint Chris? I think you did a really great job at kind of you know talking about those skills and attributes that we would want to see on that kind of person right?
They got to be a connector not can't be afraid, you know walk into a building and you know start to chat up with people and you know can kind of think in terms of positioning and and value and ultimately, you know, kind of show that you met those kind of needs but when they're talking to somebody right? What do you look for right? Is it somebody that's curious?
Is that somebody that's knocking stuff on the weekends. Is it you know, the person who fights the most when you know, something gets bounce back from the scatter the scanners wrong, right and we all have we all know those folks, right? The scanners wrong.
My code is Right. Sometimes they're actually correct about that, right? You know that that they did do things and and they got a false policy.
So so what are some of the characteristics of these folks that are again on the ground in the dev teams that really become Champions, what should we look for? Yeah, I'll jump in. I you know, I think it's I think it's important to be on the lookout for some of these qualities all the time, you know and have sort of a broad range of What I would call indicators, you know that they have an inkling to become a great champion and it's really like focused on things like quality.
Hey, how can we do things better around here? But it's also specific security focused actions, you know, maybe they're asking really good questions around security. Are we building our code base securely are we architecting this?
You know, maybe you're part of a threat modeling session with somebody who's got really great ideas thinking about security. It's all about kind of just keeping your eyes open years open frankly and inviting people accordingly, you know to join your program. I also want to you know, I think this is important to talk about because you know, I get a lot of questions around a lot.
What are the requirements, you know to be a security Champion. I think the way you design your Champion program is gonna differ, you know, based on your culture. You can have requirements.
Maybe there needs to be a certain knowledge or skill level before they can be from Champions that all depends on your Roles, but what I find most effective is more of a volunteer system. Like if you're interested you want to join the program come on in, you know, you don't necessarily have to have a high level of security skill set because again another question I get asked a lot is, you know, should we go for more experienced people to be Champions or should we go for Less experienced people and actually find that there's benefits in both, right? The more experience people are going to have more respect from their team Etc.
You're going to get a lot of grounds. You're gonna gain a lot of ground from that perspective. But the less experienced people are typically more energetic they want to jump in they want to volunteer their time and that's valuable as well.
Right? So you really can't go wrong when it comes to people who are interested in being involved. Call it what it is dusted.
They're younger. They have more energy younger and their career. the best And if you think about it, people are motivated motivated by different things.
money Promotions a better life recognition something drives everybody. So but the best ones that I've ever seen are driven by this ideal of I'm contributing contributing to a better world. A better company a better world a better life for everyone and sometimes these people to be completely honest can be a little bit annoying as well.
Right, but the bed they're the best kinds security Champions, you know, right sometimes like, you know, especially on you know, the security people's nerves right? We're kind of a little bit negative by nature and it comes this person all energetics saying I want to create a better world and we're like, go ahead. All right, that's the kind of people that you want.
And those are also the kind of people who generate trust from the teens that you're trying to Target Target with this whole program because How can you not trust someone who genuinely I can never say this word genuinely? How'd you say that word Mike Jen would you truly wants to make the world a better place? Yeah, right.
So it's you. People will start trusting this person that they're there to help them rather than report on all the bad things that they're doing and they know they're not supposed to I think it is about being constructive from that standpoint. So so, you know, I found patience is pretty important too because a lot of folks make the same mistakes over and over again and if the Champions get discouraged by that it's gonna be a long day in the office because you know, getting the same stuff keeps happening and you know Groundhog Day and and we security folks know that especially Dustin you had brought up, you know, kind of broader security awareness, like how many times that you have to click on that thing before you that's not the right thing to do.
Forget it right? I'm just not gonna you know mess with it. I'll just wipe their machine again, right and move on to the next thing.
So Chris when you go acute the cue where they're so folks. They just jump down said yeah, this is this is my person, right? They get it up front and others where you're like, they're gonna be Little bit, you know focused because they're a climber because they want to do that.
Maybe they do have, you know, kind of a complex to you know, improve things and that's Tampa but they're just like I didn't feel good. Right it didn't you know, it wasn't one of these things that I knew was gonna make sense so I could decide where to put your resources right? I mean you only have so much time in the day who you're gonna spend the time with not hopefully not all the guys are just say, yes, right, but that they've got some of these attributes that make it worth your time.
Yeah. I was the the single thing that I look for in a potential Champion is a tiny spark of security passion. It doesn't have to be big it can be a tiny spark because I can I can provide things programmatically to really build that fire inside of them about security get them more passionate, but I find that the people who are kind of voluntold into the program.
They're just their heart's not in it because they're not they don't they don't love the idea of growing and and understanding that they can become a security focused developer. You want to talk about a unicorn In our industry right now. SEC as someone that is a senior appsex senior developer.
They almost don't exist. I mean Dustin people like Dustin are in that category, but there's not a lot of folks that are in that category so but yeah, like when I was going Cube to cube there were some people that kind of looked at me and I'm like, this is not gonna be the person that's gonna be moving this program for really nice to meet you. Thanks for the time and I just like kind of put a little scratch across their name and said, I gotta find someone else in that business unit because that person was really not they didn't look happy.
Yeah. So before we kind of got it and start to wrap them thing wrap some things up that I guess those couple of Estes in a row is my you know, you know kind of my Waterloo so to speak not genuinely I'm gonna be a couple of us, um incentives, right? So we talk about folks want to build the world and their motivated to do stuff.
But is that enough right? Do they? You know, we're gonna get funding from something to do something not, you know, kind of give folks huge raises presumably but Something right?
So what are some of those incentives that really do, you know kind of engage folks and and get them, you know to make some effort in sometimes it's their free time, right? It's it's not something that you know, kind of they can just say I want to do this for, you know, 40% of my time, right? So so how do we make sure that they are properly compensated by the wrong word but incentive to you know, kind of participate in the program that doesn't look like yeah, Olivia Olivia kind of started the conversation on this because she mentioned psychology Right, and I've actually spent a lot of time kind of studying human motivation.
Gamification techniques Etc to you know, figure out how to better engage Champions how to have them better engage with the program and how to motivate them ultimately. I want to talk about a very easy to remember acronym called saps. Because what I what I find is a lot of folks, really.
Focus on like material rewards. Hey show up to the meeting you get some food if you're really awesome as a champion, you get a coin you get a hoodie, but the concept of saps is it stands for status access power and stuff and it's a gamification type concept and the whole idea is there are other types of rewards besides material rewards. Okay.
So if you think about things like like the first one status titles, you know, like a lot of champion programs use like a belt level system or sort of like a karate belt level system that expresses to others where they are in sort of the pecking order of being a champion and that can mean a lot to the security Champions other people see it other people recognize it as a status elements and it works quite effectively. You don't have to go that farther. It could be something like that Guru status even just having the security champion in your title.
If you could like work with HR get that, you know as part of their their slack title or whatever you need to do there that can mean a lot to people. Okay. I'm not gonna take up too much more time.
But there's access they're invited to certain things that they wouldn't be otherwise invited to right power the ability to make decisions and be part of the program from that aspect, you know, provide their opinion provide their feedback. That means a lot to people as well and then the last the last letter in this house acronym is stuff because stuff does also work. Yeah, I'm a big fan please.
But but first one when I when I heard to say, you know kind of the last s Nelson I thought it stood for stock options and it was just like all this stock options down down there, right? Yeah that can stop. I would think that I guess that would be stopped that would be stopped it fast because you need a little bit of fast to be a security.
Okay, and I'd like to add to that because that's a great great set of guidelines. But also never underestimate Rick Mission a call out on a team meeting Town Hall by an executive. Oh, they know my name.
It goes a long way. Yeah, and I've got one too Mike that I want to add here and it's it's really more of a very high level kind of principle that people can apply here and that is think about what's in it for the champion not what's in it for the company. Almost every program.
I look at it's all about the company with the company is getting x y z from the Champions doing these things and so my advice to people now is flip that table around flip it upside down and say okay as a champion. Here's what we're giving you. We're giving you enhanced training like to Dusty's point with the Sap's acronym here.
We're giving you these are the things we're providing for you and I find when you take that approach and you make it about the Champions, you're you're gonna your program's gonna be unstoppable because people are gonna be knocking down the door saying these people are taking care of their they're getting all this extra stuff this training this this access to people and but it really is a mindset shift and I would say nine out of 10 programs. I've looked at are still in the it's all about the company and so we got to flip it around. It's all about the champion.
Yeah, you better and and to piggy back on on Olivia's point there. I kind of call them, you know or the process right making a poster child, right? And that's really highlighting somebody back to the Mission implant the status part and and all of those and it really is kind of highlighting somebody that is making a difference right if they're making a difference you want more folks to emulate that kind of thing.
And if you throw a hoodie in there, I think you got it Unstoppable, you know kind of combination on that front. So we're about you know need to wrap up at this point again, we could probably talk all day about the these things but you know, I'll post one final question to each of you again, if there's one thing that you know, you could kind of advocate too remember the audience or folks that are just getting going on their devops, you know Journey, they're trying to figure out how to on ramp onto this, you know, kind of new and exciting future relative security Champions with one thing that you would you know, kind of tell them, you know to do to think or to you know, kind of take away from from our discussion today Olivia. Why don't we start with you?
Yeah. You don't need to raise. Your hand with the person who wrote my most favorite guide ever to setting up a security Champion program.
And then it just connected at the beginning this called I went. Oh. I send this I send this website.
To everyone asks and at the last session where I presented at where you were at there Mike, I was on security Champions I gave them this URL. This is the best step by step. org.
org. This is the best one out there. So that's what that's my recommendation.
That's fantastic. Dustin doesn't even have to you know, kind of pumpkins on stuff that I take Starbucks card you that means a lot I really oh it's the best it really is. Thank you.
I mean, I put all my thoughts there, you know learned a lot of things creating these programs and I really wanted to create a resource that was available to the world to help people build their own Champion Burger. That's what it's all about. So it's all free.
You don't need to register either. It's it's right there. It's it's just so great.
So do that Dustin you have someone else you think one thing or you know, we're all going to agree. Go to go to go to the website and get along. All right, Chris.
What about you? I'll leave the the audience with this idea of like be the spark like start with a small and maybe four people have that first meeting get that first get this thing in motion. And if you do the things that we've been talking about here, it's gonna pick up it's gonna be it's gonna be the tiny little snowball at the top of the hill.
It's rolling down and going so be that sparked started out. Yep, and and I'll also so thank you all Dustin Olivia Grace. I mean really just fantastic perspective is really helpful to understand what security Champions are about.
I'm actually gonna kind of raise the bar a little bit here in terms of my one thing that folks have to think about right if you have any concept or idea or aspiration to get to deaf secops at some point in the future. If you do not have some kind of security Champions program in place. You have a you're gonna have a very hard time getting there a very hard time getting there.
So, you know, there was kind of a little bit of method to the madness and getting you know, again world class experts about security changes for folks that are thinking about outside. I'm just trying to do devops already know pipeline is what you know, if you're not thinking because because you're you're thinking you've heard the term you're trying to understand what it means if you're serious about Black Ops at all you have to be serious about security Champions. And with that.
Thank you to our panel. Again. Dustin Lear Olivia Rose, Chris Romeo.
I can't thank you guys enough. I mean it really was fantastic. So I certainly appreciate your participation and it's almost time for the next session.





