How to Build an Elite Security Champions Program

TL;DR
Build a security champions program by recruiting product-adjacent people who already show passion for security, then give them foundational knowledge, practical experience, and access to security tools and processes. A virtual community of champions helps address the staffing imbalance between developers and security specialists, while an aspirational ratio of one champion for every eight developers can extend security influence across product teams.
Transcript
Wow, it's really good to be back in a room full of people. It's just an incredible experience. Um, we were laughing up here before. You know, in a virtual world, I can't tell if people are groaning during corny jokes. I can only... You know, but in the real world, I can tell when people are like, "Ugh, come on." All right, let's, uh, let's get goin... Read More
Key Insights
- Security champions are product-adjacent people who extend the reach of the security team by influencing the products they build or support. They can come from development, architecture, management, testing, or another role close enough to affect product decisions.
- Security passion is the primary quality to seek when recruiting champions. A person's current job title matters less than having genuine interest, because even a small spark can grow through engagement with the security team, relevant knowledge, and practical experience.
- A security champions program is a virtual team rather than a large dedicated organization. This structure brings together people across product-related roles without requiring the company to create hundreds of full-time security champion positions.
- The champion mindset includes foundational security knowledge, awareness of attacks against what the organization builds, acknowledgment that products will be attacked, and the practical ability to use the tools and processes required for security work.
- Security champions reduce organizational chaos by helping teams manage security requirements, processes, and limited resources. Without champions, developers and security specialists may depend on last-minute efforts to improve the security of products and applications.
- Security staffing is insufficient without broader developer participation. The cited BSIMM 12 ratio was one software security group member for every 135 developers, even among assessed companies that already treated software security seriously.
- The program's aspirational coverage goal is one security champion for every eight developers. The presenter describes this ratio as an experience-based target rather than the result of a formal or profound calculation, and acknowledges that achieving it can be difficult.
- Security champions should learn to think like security professionals, with attention to risk, threats, tools, and processes. The stated objective is not to make developers think like hackers or attackers, but to help them make informed security decisions.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How do you build an effective security champions program?
Start by identifying product-adjacent employees who already show passion for security, regardless of their formal roles. Engage them with the security team and provide foundational knowledge, practical experience, and instruction in relevant tools and processes. Organize them as a virtual community that can influence product work, and adapt the program's tactics to the needs and constraints of the company.
Q: What qualities define an elite security champion?
An elite security champion is passionate about security, connected to the security team, and equipped with the knowledge and experience needed to contribute effectively. The person understands foundational security concepts and attacks relevant to the product, accepts that the product will be targeted, and can use the organization's security tools and processes. The champion may work in development, architecture, management, testing, or another product-adjacent role.
Q: Why are security champions needed in DevSecOps organizations?
Security champions are needed because central security specialists cannot directly support every developer at sufficient depth. The transcript cites a ratio of 135 developers for every software security group member among companies assessed in BSIMM 12. Champions distribute security awareness and capability throughout product teams, helping the organization handle requirements, processes, risks, threats, and security work without relying entirely on a small specialist group.
Q: What is the recommended ratio of security champions to developers?
The presenter's aspirational goal is one security champion for every eight developers. He states that this figure comes from his experience rather than a formal study or profound calculation, and he recognizes that it may be challenging to reach. The ratio serves as a practical program objective for extending security influence much more deeply than the central software security group could manage alone.
Q: Who should be recruited into a security champions program?
Recruit anyone close enough to influence the product who also demonstrates an interest in security. Suitable participants can include developers, architects, managers, and testers, as well as other product-adjacent employees. The presenter places greater importance on a person's security passion than on job title. Even someone only a few years into a development career can grow through the program and potentially move into a full-time security role.
Q: What should security champions learn?
Security champions should acquire foundational security knowledge and understand the attacks directed at the products or applications they help build. They should acknowledge that those products may be attacked as soon as they are released, or possibly before release. They also need practical competence with the tools and processes used to complete security work, along with an understanding of risk and threats.
Q: How can a security champions program survive leadership changes?
The Cisco example shows that champion programs can rise and decline when an enthusiastic owner starts the initiative and later leaves the company. A practical recovery step is to locate the people who remain passionate about security and reconnect them with the program. In the presenter's experience, approximately twenty returning advocates became the foundation for rebuilding a community that eventually grew to approximately five hundred participants.
Q: Should every company use the same security champions framework?
No. The presenter explicitly describes the framework as descriptive rather than prescriptive. It collects tactics that succeeded across Cisco and other companies, but some practices may fit one organization and fail in another. Teams should identify ideas that can provide a foundation or help reboot their existing program, while rejecting or modifying approaches that do not suit their company's structure, culture, or circumstances.
Summary & Key Takeaways
-
Security champions help transform a chaotic development environment into a more orderly security practice. Without them, teams chase requirements and processes, lack sufficient resources, and rely on last-minute interventions. A strong program creates a foundation for improving the security of products and applications while extending the reach of the central security organization.
-
Cisco's Security Advocate Program had experienced repeated cycles of growth and decline as program owners changed. After reconnecting approximately twenty people who remained enthusiastic about security, the presenter helped expand the community to approximately five hundred advocates and supported security conferences around the world that were specifically tailored to those participants.
-
An elite champion is a security-passionate person from any product-adjacent role, including development, architecture, management, or testing. Champions should gain foundational security knowledge, understand relevant attacks, acknowledge that their products will be targeted, and use established tools and processes. The presented framework is descriptive, allowing each organization to adapt its tactics.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator