Skip to content
AppSec PodcastThe Application Security Podcast — home
50 minSeason 12, episode 13

Marisa Fagan - Measuring Security Culture

with Marisa Fagan

on Building an AppSec Program, Security Culture and Careers in AppSec

Audio hosted by Buzzsprout. Nothing loads until you press play.

Marisa Fagan, Head of Product at Katilyst and veteran security culture expert joins us today to  share practical strategies for building and scaling security champions programs that actually work, from designing effective pilots to avoiding common pitfalls that can derail your initiatives. Learn how to motivate developers using the SAPs model (Status, Access, Power, Stuff), why getting management buy-in is crucial before launching, and discover the metrics that truly demonstrate security culture success. Marisa reveals why most programs fail, shares her blueprint for creating sustainable security culture initiatives, and discusses the evolution beyond security champions to include privacy and accessibility programs. 

Resources Mentioned: 

• Security Champion Success Guide

 • OWASP Security Champions Guide

 • People-Centric Security book by Lance Hayden

Mentioned in this episode

Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.

Transcript

7,472 words · assemblyai

0:00Chris RomeoMarisa Fagan is Head of Product at Catalyst, a security champions-as-a-service startup that's revolutionizing how organizations scale their security culture initiatives. She's dedicated her career to building security into the SDLC and empowering developers to own secure code. With an impressive background as a security culture expert at tech giants like Atlassian, Salesforce, Meta, and Bugcrowd, Marisa has been at the forefront of the security champions movement, helping transform how development and security teams collaborate. Marisa shares practical insights into what actually works when it comes to motivating developers, measuring program success, and avoiding common pitfalls.

0:37Marisa FaganThe Application Security Podcast is brought to you by Security Journey. We provide application security training for not just your developers, but for all roles in your SDLC. Learn more at securityjourney.com.

0:48Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. Security Podcast. This is Chris Romeo. I am a VP at Security Compass and a general partner at Curve Ventures. As always, joined by my good friend, Robert Hurlbut. Hey, Robert.

1:14Robert HurlbutHey, Chris. Yeah, Robert Hurlbut, Principal Product Security Architect and Threat Modeling Trainer at Torion. And as always, glad to be here to talk about a good topic today on Security Champions.

1:28Chris RomeoYeah, we've talked about Security Champions quite a bit, but there's always more things to uncover. I'm a student of the game, I like to say. So, joined by Marisa Fagan, who has been around the world of Security Champions for a while now at this point, but we'll let you kind of get into that here, Marisa, in your security origin story.

1:49Marisa FaganYeah, very cool. I'm also very excited to be here. Thanks for having me. I love this first question. I was thinking that my origin really, of like many of your guests, starts in high school. My first introduction to hacking was like through the culture and the community. I was a big fan of 2600 Magazine, and I would go to my local meetups in the mall. a bunch of kids in the food court, and everybody was just like a really welcoming community. And I was interested in the topic. You know, people were using computers in a way that was not what we were being taught in school. So that was, of course, very interesting. But I also just really loved the community and the intersection of these things. And so I spent a lot of time and made a lot of friends in that community. And if we fast forward a little bit, it came time for me to pick a major for college. And I was seeing a lot of my friends getting jobs in Atlanta, where I'm from. They were getting jobs at places like ISS and SpyDynamics. And those were kind of the companies that first started to bridge the gap and bring hacking into a corporate enterprise environment and really try to make make a difference, helping secure the companies that were sort of being picked on and being under attack. In those days, more like kind of an ad hoc way and underground way, there was people trading vulnerabilities and kind of a dark web scene before that was really a thing. And there were people that wanted to help the companies. And of course, this was like becoming big business, especially in Atlanta, but it hadn't quite yet. And so I actually started in college. I was the first class that did the security specialty of my Georgia State University. I was the first class and kind of like a guinea pig cohort. And it was funny because I actually asked some of my friends that were working at ISS to come be guest speakers in our lectures in college, because that's, that we were just kind of making it up as we went along in those days. I won't give you a year, but it sounds like you're nodding your head and you kind of get where we're coming from. So, again, keeping through all of that, just like the culture of security really kept me engaged and motivated and feeling connected and to go kind of above and beyond what I would have normally done for just like a job and kind of just working for a living. And I could see that my peers were also really passionate about this topic and their community and their friends and their job. It all just kind of intermingled in a really special way. And so I looked for that when I went on to work with some friends in the same group. We worked at Arata Security, a pen testing consulting company in Atlanta, and I was a project manager. And really my favorite part of that job was helping executives and the early CISOs with the executive summary of pen testing consulting reports. they would get this like raw data dump and send it to me, and I would be like, okay, so it seems very scary that we have 15 criticals here. Let's tell a story about that and what to do about that. So it was really interesting to me to help the companies that we were giving these consulting services to. And so I took that mindset with me, community and wanting to help, be targets of attacks. And because of my interest in community, I got connected with Facebook, and I had moved to California by this point, and I was working as a program manager in the security team at Facebook when they had first begun their bug bounty program. And this was right before, but definitely leading up to all of the great work that Katie Mazouras did and Casey Ellis did around basically researchers' rights and having vulnerability disclosure policies written on websites that were publicly accessible. None of that quite existed yet. And so I felt like this is a great way to help a community of people. And I was able through Facebook's bug bounty program. My role was kind of a community manager with this population, and I was getting to know researchers from places like India and Turkey, Israel, and all sorts of places that I had never traveled to myself, but I got to cross the ocean and talk to them and get to know them and learned what motivated them. to do this extra work on behalf of a company with their blessing. And we learned what motivates them as far as rewards. We had, during this time, it was Yahoo's t-shirt gate where they gave a t-shirt for a critical vulnerability as a reward. And they were given a bunch of hard time about—

7:48Chris RomeoOh, wow.

7:49Marisa FaganNo, this is not gonna cut it. So that was all just really learning. We were all kind of making it up as we went along again. And I got, I just had a lot of fun with that, learned so much, and I eventually went on to work with KCLS at Bugcrowd. And then after that, I took a jump again.

8:14Chris RomeoOkay.

8:15Marisa Faganand caught the attention of Masha Sadova at Salesforce. And she also was really on the same mindset of people and community are a key ingredient to solving security culture issues. And Masha at the time had been tasked to start a team to work on insider threat, and she really took that turned it around and said, like, no, it's insider support. How do we incentivize and grow people into having a security-first mindset because they care, not because they're threatened and worried that if they get caught doing something bad, that bad things will happen, but rather, how do we take that out of the equation, make them incentivized to do positive behaviors proactively? And so, Masha's and Trust Engagement team had started the Jedi program, which was more for security awareness and gamifying and incentivizing people to do security training and care about security. And we had this great meeting. We had some brainstorming and we talked about other areas that we could apply this model to. And around the same time, I had, I came on and joined Salesforce, and I was able to talk to the product security team about how their relationship with developers was going. And they described a situation that was untenable. They were underwater. They had so many tickets to review, and they had a help desk queue. There was an entire group of interested, enthusiastic developers that were sending them questions. I need help with this. I need a security review with that. I want security's input, but there's 5,000 of them and only 30 security team members. And so we had a scale problem. We just didn't have enough people to address everything. And so first, because it was Salesforce, they built a Salesforce tool for automating the help desk function and prioritizing which tickets were more critical than others. And that was sort of an engineer's approach to this problem. But I raised my hand and I said, I would love to start a community around this issue. Can we create a Security Champions program. And I had a little bit of foresight. Chris, I think you and I had conversations around this time, and, you know, talking to the folks at Adobe around their belt training tiered model. And that was kind of really catching fire, this idea that training was more than just checking the box. It was more than just single people having awareness, but like, really, it could be more of an engaging program. And so I took that idea, and I took the gamification from our Salesforce Jedi program, and kind of combined it with my own idea, which was a pyramid scheme. And I connected our 30 security engineers with the 250 developers that kind of raised their hand and said, we want more. And we created a one-to-many relationship between all of them. And I gave them a lot of what I had learned from the InfoSec Mentors Program around giving people structure, giving them inspiration, and like giving them expectations of what they should expect. from a relationship like this? All of that was important. So that's learned the hard way again, and I'm sure we'll talk more about this today. And then from there, I took that security champions model and just refined it for many more years. And now today, I have ended up at a company that I'm so excited about because it really is the evolution of these ideas over many years for me. And also, I get to do a new job type, which is so fun and exciting over this, you know, almost 2 decades. I get to be a product manager now, which is the other side of the fence. I am the product manager at Catalyst, and we have a product. It's software to help automate and track all of these champion activities. And we'll call it security champions as a service, if you like. So that has been so exciting for me because that really was the missing piece. for many, many years. We had it a little bit at Salesforce because we had Salesforce and that was a big developer environment. But all companies, I think, are missing this, like, how do we make it much less painful to give developers credit for what they're already doing so that we can strengthen this relationship? Because we're really good at tracking what they're not supposed to be doing. how do we track what they are supposed to be doing? So that was kind of my, my mindset.

13:35Chris RomeoYeah. So many, so many things that you brought up there kind of triggered memories for me. I've forgotten about the Atlanta security scene and, and the startups that had taken, had, had gone or come out of that space. Just, it had slipped my mind over the years that there was this big security startup ecosystem in Atlanta in the very earliest days of, Yeah. Of cybersecurity as a thing. And then certainly bringing up somebody like Masha, who's just brilliant and has went on to form her own startup, which was acquired, I believe, a few years ago now. So, yeah, lots of, lots of fun names were intersected along, along your journey there.

14:23Marisa FaganThere's a meetup in, at Black Hat in Vegas every year. for all of the old Atlanta crew. And, uh, so the X-Force, I think, is kind of the nexus of it.

14:37Chris RomeoForgotten about X-Force. ISS X-Force.

14:40Marisa FaganYeah.

14:40Chris RomeoOne of the first real vulnerability research teams that ever existed in our industry. And a lot of new folks will have never, never heard that term, ISS X-Force. Look it up, put it into ChatGPT. You'll get a nice summary of, uh, of what that was, part of our history.

14:57Marisa FaganOh, I can only imagine.

14:58Robert HurlbutSo, Marisa, we've heard you mention pilots before, but what are the key components of an effective pilot, and how do you scale it into a full program?

15:08Marisa FaganA pilot is an essential first step for any program. So this technique, I think, comes from my program management background more than anything. So the pilot is a small subset of your ideal audience. It is a small subset of the amount of tactics and rules that you want to roll out, the structure. It's kind of the best parts of all of it. Let's call it 10% of the people, 10% of the techniques and the rules and the structure. And a time-boxed amount of time. So either 6 to 8 weeks, something like that, where you can get a good feel for whether you have any bugs in the system, whether you have any processes that are really not gonna be fitting with your culture or land well with the people that you're trying to reach. It's a really good way to test your you know, you're kind of in a silo working on this program design and you think it's all going to work, but you never really know with people. People can surprise you and there are so many edge cases. So with a pilot, you get a little taste of possibly a couple of the edge cases if you're lucky, and you can decide whether you want to reorient around some of those edge cases or not as well. I find with people, Their desire to help often is one of the best ways to find bugs. They will get creative with that enthusiasm. And so a pilot, you know, you can call it an early launch and it's an exclusive group of people. And then be sure at the end of your pilot to thank those early adopters, your early launch group, because they really do help you. with getting all of the bugs worked out of your process. A lot of people skip this step or they just start, and then maybe that could have been a pilot, but actually it just sort of becomes the program. So I would say another important part of the pilot is to stop the pilot and don't just kind of keep going.

17:36Robert HurlbutRight.

17:37Marisa Faganreset, start the group over, you know, give everyone the heads up that you're going to reset the clock and then give those pilot folks an opportunity to socialize and recruit maybe other champions. And so they have kind of an honorary status as being a part of something.

18:00Chris RomeoDo you see a pilot as, or do you use this to generate a business case? Is there like a business side to the pilot, or is it really just about kind of working out the bugs in the system?

18:11Marisa FaganBy the time that you have started letting people outside of your orbit know about this, you already need to have full endorsement. I would say that it would be hard, you know, that, that would be a hard thing to have the pilot not go well, and then you're having to sell it, but you only had 10% of the data. You only had the possibility of proving anything. You're really looking for bugs, not for success stories in 6 to 8 weeks. Gotcha.

18:52Chris RomeoSo, when you think about tactics for motivating security champions, I know people have thrown around and I'm personally one of those people. Gamification has been a big thing, training gamification. What are, from your perspective, like, what are the, what are the most crucial pieces or tactics to motivate these champions?

19:12Marisa FaganIt's funny that we, we talk about them like they're not also us. It's not the mysterious other. You know, Robert and Chris, you're both, like, developer background, you've got some experience. What motivated you? Like, why did you do an extra set of steps to build security into your tools? I imagine that it was a lot because of the perception that if you didn't do that and people were looking and they would recognize that and they would call you out on it. that it would feel bad. And so part of it is to really boost up the recognition and the revealing and the socializing of what's happening with all of these security vulnerabilities that the security team is finding. So reputation improvement is kind of a part of it. And then you can socialize that people will get career advancement or career growth or, you know, maybe not at this company, but eventually in their career, they will get access to security work. Maybe they wanna go on a track towards security, and this is a good way to get that first step. You've talked about in the past, how do you break into security? What's the path to get a security career? And of course we say, well, you should build a lab in your spare time, and you can show all of the security projects that you've worked on.

20:41Chris RomeoYeah.

20:42Marisa FaganBut maybe you're quite far along in your career and you don't really have time to build a secret lab in the basement. You want on-the-job success. And this is a great way to show on-the-job cross-functional success working on security projects with the security team, with their happy endorsement. And, you know, maybe in all of this, the security team is now writing a letter of endorsement or giving you feedback on your performance review. That endorsement outside of the team, I have seen firsthand, is huge. And it's something that not a lot of developers in large organizations have access to.

21:26Robert HurlbutMm-hmm.

21:27Marisa FaganSo, really, it's actually a very special program that I have found, for people that get it, It's not a hard sell at all. And then there's a third category of motivation, which is like rewards. So you can put a carrot out. And the carrot category has 4 parts. In our profession, we say we're using the SAPS acronym, which stands for status, access, power, and stuff. So t-shirts are stuff, and there's 3 other categories that you could work with. You don't need a budget to provide people with recognition, like certificates or badges. You don't need a budget in order to write people a letter of recommendation for their promotion panel, promotion packet. It doesn't cost you anything to give the managers like a you know, this person is doing a great job. And it doesn't cost you anything to have the CISO give shoutouts in the annual or monthly town hall. So these are— there's so many things, a list of things that rewards kind of covers. And people are motivated by rewards. It's very nice to get those and it's recognition for a job well done. And so I support that. But just with the caveat, don't feel like you need to have a budget. And if you're giving out rewards, you should be fair and make sure that that was a process that you decided this situation deserves this reward, not this person because I like them, I'm going to give them this reward and then nobody else gets it. People can smell unfair and unjust practices. And so you don't want to get yourself in trouble when that was not your intent. Just make sure that you write down what your reward system is and then follow the process. Don't get creative with that. Make it public. Make it something that people can be motivated by proactively because they have seen it and they understand, oh, if I do this, then this will happen. And they can rely on that and trust the process is fair.

23:48Robert HurlbutYeah, I have a—

23:51Chris Romeojust made me think of a story when you mentioned this, the idea of people From being, you know, finding a career path, you know, first of all, if you have a lab in the basement, you're never going to meet anybody. So it's going to be hard to get a job in this industry if you don't, people don't know who you are. But it just made me think about one of the things I did at Cisco's program that I'm most proud of with the security advocates there was I worked with San Jose State to create a master's degree program that then was exclusive to, you had to be a security advocate to get into this master's degree program. Focused on cybersecurity from San Jose State. But the best part of it was over the next 5 years after I was long gone from Cisco, people would reach out and just say, hey, thanks for the, you know, for the program and for the San Jose State thing, which is not the important part. They'd say, I just got an information security job at X, or I just went, not X.com, just that was an example. But, you know, various places they'd say, I just got a, I just became a security engineer, you know, I was a developer before when I was an advocate, but now I'm a security engineer either at Cisco or they'd gone other places. And so that was, for me, one of the most rewarding things to know that this program had been a vehicle for people to change their career trajectory because they were some of those advocates that cared, champions that came in, and they had that kind of gleam in their eye about security. They were, you know, they were a developer by day, but the security was, they caught the security bug. And so that was just an example of that. Some of the pieces of that SAPS thing, SAPS acronym playing out in real the real world.

25:25Marisa FaganYeah, very cool.

25:26Chris RomeoYeah.

25:30Robert HurlbutSo, what are some common missteps or anti-patterns that you've seen organizations make when they're launching a champions program, and how could they avoid those?

25:40Marisa FaganI don't have to look far. I can look in my own history to find some of these stories. Some things we learned the hard way because the very idea of a security champions program was pretty unofficial in my beginning. And so that was the first lesson learned is the more official you can make the program, the better. So, you know, we didn't quite do our review of like, what is a security champion? I like to point out, A security champion is just a person that wants to go above and beyond for security. They are championing the concept of security in their organization. You can have security champions everywhere. A security champion program is different. It needs to be official. It needs to have structure. And to answer your question, I think 99% of problems can be settled if you have a charter and a vision statement. If you write down everything that you're thinking and then you get it reviewed by stakeholders, I really don't see how you could, without the organization itself falling apart in some unpredictable way, you can't really— we've seen this in the past couple of years, I'm not making a joke, but without external forces coming in to just wreck it all, you can get a lot of things figured out on paper first. So a vision statement, I think, is the most important part. And our good friend and colleague Dustin Lear has created a free resource for a program design vision statement template. It's called securitychampionsuccessguide.org, and I'm sure we can maybe put it in the show notes. That free resource is a step-by-step walkthrough template of all the sections that you need to have figured out ahead of time before you start, before you propose it to your leaders, to capture all the structure pieces that you need. And it also happens to be a really good introspection document. It really helps you figure out what type of culture do you even have? What type of program is your culture going to sustain? If you have a very compliance-heavy culture, maybe you work for a government or a bank, you're really not going to get a lot of mileage out of some of these fun pizza party type of things that we see some of the more vocal Champions programs talking about and running. For example, you can't give them gifts over $25, so you can't do a nice t-shirt, you can't do hoodies. If you write all of that stuff down in your vision statement, We can't do this, we can't do this, we have this restriction. What are the 5 rewards in my SAPS model that we can do, and what are the structures around those things? All of those have been approved by leadership, endorsed, feedback has been given by stakeholders. You might have an early selection of who your pilot group is going to be, and you might get feedback from them as well, interview them. You know, I, I could speak for hours about this exact topic, but I think the general idea is let's first start with writing it down. It's a very powerful technique.

29:16Chris RomeoYeah, it just made me think of probably my biggest misstep in running the Champions Program, which, you know, I'm going to share because we, we, it's good to show our failures. People always focus on your, our successes. I mean, all you have to do is log into Instagram and you'll see that in reality. But to your point about writing it down, early in my first kind of Champions Program, we didn't have a good definition of how things were supposed, what people were doing, what they were committing to. And I had a couple of folks that went rogue on their managers because their manager said, I don't want you spending time on the security thing. And they were like, Forget that. I like what I'm doing. I'm doing it anyway. And they ended up being laid off the next— Cisco was in this layoff cycle in those days and they ended up on the list and then they were gone. And I was like, yes, they went— they definitely went against what their managers were telling them to do, but they didn't— we didn't have a good definition written down as far as what we were asking for. And so what I did the next year, was I did an email opt-in thing where the email went to the manager and the manager had to say, yes, I agree that my person's going to be working at this scope at this time thing. Because I just like, I didn't, it was, I owned a little bit. Yes, they were defiant and they made a choice to not follow what their management told them, but it was my program that kind of led to their demise from the organization. So that was, I would say, is one of my biggest Pitfalls or the biggest things that I didn't, but it kind of played into, you kind of came at it from the, you explained it in the way, the way why we need to do it. And this is just an example of something that went wrong.

31:07Marisa FaganYeah. Thanks for sharing that. That's such a good example. And the, their heart was in the right place and it's just a little tweak to get established permission. And that's really reminding me of my background as well. And the bug bounty program, the rules of engagement have gotten really clear for bug bounties. You're allowed to touch this and you're not allowed to touch this. And if you stay on the path, we will reward you with wonderful money. And if you don't stay on the path, we can't really, we can't save you from what might happen. Because it's all written down and a lot of it has been ratified by legal. Pardon me. I don't think you need to get your security champions program ratified by legal, but the mindset that it should be a trustworthy agreement between 2 sides really resonates.

32:08Chris RomeoYeah. Definitely.

32:15Robert HurlbutLet's see, what are some metrics that could demonstrate success for security culture initiatives like training and security champions?

32:24Marisa FaganSo, by metrics, it could mean a lot of things. So, I like to have 3 areas, and your mileage may vary. I don't know if you have KPIs or OKRs, or if metrics are more loosey-goosey, in your organization. But I think for your own purposes, even if you're not reporting them to the higher-ups, you should be thinking about tracking metrics in 3 categories. I like to have metrics around impact. That's the exciting one we all love to have, to tell a story about how the company is better for having done this program. It's made an impact. I like progress metrics. So that's like, our goal was to have 100% coverage, one champion for every team, and we're like 70% towards that goal. And that means we've got 70% of teams have one champion and 30% has zero champions. We've got some work to do to keep hammering on this marketing and get more coverage. So I call that a progress goal, but you could also maybe limit it to coverage goals, and that's a number, so you could call it a KPI. And then I guess the third category you could call health metrics, and that's really about the program itself. So how healthy is your dashboard on the program itself? And so I have, you know, in my work, I've created programs that have pretty elaborate tracking dashboards of actions and activities that champions are doing. So an early, easy way to dip your toe into tracking actions as data is to look at your training. The training LMS has really good, what's it called, training records. So you can see the time, the person, and the completion record for each champion. So that's a good place to start and kind of give you a model of what you're looking for. But from there, I would encourage you to go to other sources and start pulling events from other sources as well. So Jira is a hotspot. You can look for Jira data, like closed vulnerability ticket is kind of the classic. I would encourage you to start with closed vulnerability ticket as a way to grow and figure out something more appropriate. Can I tell you, you won't end with that being your perfect metric. You might end, just to have a spoiler, but please do the work to make this your own and figure out what's best for you. A place that I've ended is actually the SLOs or SLAs on those vulnerabilities. How many vulnerabilities are overdue on their due date? And do those vulnerabilities live in teams that have a champion or teams that don't have a champion? What's the correlation between champion program teams and teams that are not participating? If you can tell the story that teams that have champions show faster participation in our vulnerability management process, that is a great story to tell that comes from a metric that you need to start tracking first. And so working very closely with your vulnerability management team, if you can kind of have shared goals, You could split the work up, and you could just tell the vulnerability management team which data you're trying to get access to by giving them a roster. Here are the people that are security champions, and this is an up-to-date list that we keep in real time. These are all active champions that have been vetted. Please give me all of the data around their vulnerability management history. Or perhaps you're proficient in your JQL and you could dig in and find that information yourself. But I think it's a missed opportunity if, of course, you could do it yourself, but partnering with the vulnerability management team and helping them see security champions as their tool that they can use to— it's like calling people resources, but the security champion program is a tool for them to use.

37:02Chris RomeoYeah.

37:02Marisa FaganThe champion program is a tool that red team can use to show output impact, and when they do retesting, they get the champions to do the retesting, and they have pilot groups for retests. All of this is a way to have shared metrics and shared goals with other teams to really branch out without doing extra work on how to do the tracking for that. Okay.

37:32Chris RomeoSo, I did have one more question, and this may be more philosophical than program-related or whatnot, but all 3 of us have kind of grown in our careers throughout a time when there's been tension between development and security. Yes. And so, If we were to think about, like, the best possible scenario, like, is Champions the vehicle that eventually brings development and security to the point where we're just cohesive and we're working together and we're all happy and marching in the same direction? Like, is that in your— and that's why I said it's kind of philosophical as well as related to the topic here, but, like, what are your thoughts on that? Like, is this the gateway? Is this what gets us to the point? where we reach some better state where there's no tension.

38:31Marisa FaganI love this question. There's a lot of truth today that we're sharing with our viewers. I really appreciate just calling out that this is even an issue. I know sometimes the tension between the two sides can be a little blamey, which side is not holding up their end of the bargain. And over the years, we've seen it in, especially in, in moments of breaches and ending up in the news with reporters saying or implying that there's some sort of negligence at play and somebody didn't do something that they were supposed to do. It can be easy to look at the other side and, you know, have those silos. If we could only just get the other side to do what they were supposed to do. So in a sense, if that is how you think, if that is true, absolutely, having enablement and support for the other side, help them do what they are supposed to do. And by the way, it goes vice versa. Developers have the same thoughts about security team. Why can't they just pick the right tools? Why is the WAF hurting my performance rating? All of that goes both ways. So, the very idea that we could get requirements from developers for the security team needs to have a channel for that communication that doesn't exist maybe otherwise, or if it does, it exists in a kind of leadership boardroom where the height of the conversation is just so high that it will never be as tactical as, can we use a different firewall because this one is not causing good performance. Those messages have to go through quite a chain. Or what if you created a roundtable, you built a community where everybody could just bring their grievances or their success stories together to the same place, and we could have a central location or a town hall or a meeting room where everybody could come to? And I know that that sounds a little idealistic, a little utopian, but that I do think is— I've seen it happen. Let's be honest, this does work if you work it. So the work that you put into it is rewarded. And I do think that these 2 sides should be on the same team, that the distance between these 2 silos is In fact, it is a gap. It's a deficit in the programs on both sides. And the program called Security Champions is a tool that can be rolled out to fix one of your security control gaps, to put it another way.

41:33Chris RomeoAnd when you, when you mentioned kind of a session where people are airing their, their challenges or what you know, problems they might have. I could not stop thinking about, uh, there's a Seinfeld episode because Seinfeld mirrors life to some degree, uh, the one where George's dad created the holiday called Festivus.

41:52Marisa FaganYes.

41:53Chris RomeoAnd there is a special segment called the airing of grievances where you get to tell people everything that's, everything that you've been unhappy about with them for the past year or whatever. So I just, I was imagining this session where there's an airing of grievances.

42:09Marisa FaganAbsolutely. Security Festivus.

42:10Chris RomeoThere we go. Security Festivus. That could be a new thing. The erring agreements. And then there's, I can't remember what the other, it's been a while. I can't remember what the other, there was more to it. There was a pole. It was a metal pole instead of a tree for a decoration. So we'll have to find something else to signify that.

42:27Marisa FaganSo. Maybe for Security Awareness Month, we can pull out the Festivus pole. Yeah.

42:33Chris RomeoI don't know if Seinfeld has caught on with the next generation, like some of the other, like '90s The later '90s and 2000s programs like The Office is like, everybody knows The Office. Like, it doesn't matter how old it's almost, I should say almost everybody, but I think Seinfeld has a little more refined audience than that. But Marisa, I guess, what, how about a key takeaway or a call to action, something for our audience that they can take away from this conversation and go to work to do something?

43:03Marisa FaganWhat advice would you give to them? First of all, I think that every company has more already in place than they think. I think there are champions for security in your organization already, because how could there not be? It's such a cool topic, and it has very big implications. So whether you're in it for the black hat pizzazz, or you're in it because you realize how critical it is to save the company from a billion million breaches, there's bound to be people that are here already that are interested. And so I like to say, if you've already got security champions, you don't, you don't have a program problem, you have a scale problem, you already have it, you just need to help grow it and put some Miracle-Gro on that structure. So give it legs. And so the second part that I would have you take away is we're getting really good as a community here of practitioners. We're getting really good at figuring out what the MVP version of this is. It's got a couple pieces that we've really time-tested. And so do the research, go seek out some of these case studies and examples and build a program on top of that. So you don't have to make it up from scratch at this point. It's not necessary, but do massage it to fit your culture. Not all cultures are the same. I gave a talk at BSides San Francisco about this point. There's like at least 4 different cultures, and you can find that in the book, People-Centric Security, that there's like at least 4 quadrants for security culture, and each one has a different set of success variables. So get to know your culture. And then, as we talked about before, make your vision statement, use the resources that are at securitychampionsuccessguide.org, or I would love to give a pitch for the OWASP group called Security Champions Guide. And I think that's securitychampions.owasp.org. You can Google for that one. And we are asking people to participate and help. So the OWASP group is growing and growing. We've got a good group now, and there is a maturity model that has been created by our committee, and they're going to present the maturity model for the first time at the OWASP AppSec Global conference in DC in November. So if all of this is interesting to you, one last shout out, please join us in DC in November. We'd love to see you all there at the OWASP conference. There's a big security champions population there that's having birds of a feather discussions about this.

46:09Robert HurlbutCool.

46:10Chris RomeoAnd I know I said that was a key takeaway call to action, but something else came into my brain and I wanted to see what your thoughts are on this. A good friend of Robert and I, Dr. Kim Wutz, is a big privacy threat modeling advocate. And she always makes me think about it's not just security threat modeling, it's privacy threat modeling. And it's embedded in me to think it's not just security, it's privacy. So, what about on the champion side? We've called them security champions forever. Is there a world where we have a privacy champion, or is that something that should be together? Like, what are your thoughts on that?

46:51Marisa FaganSo, yes, absolutely. This model applies to other topics. In my time at Atlassian, I saw the security champions program inspire another team to create the privacy champions. And they had a set of things that privacy champions should go through. Another really cool one that I was so excited to see was accessibility champions. Accessibility team has a specific set of things that they look for and test for. There are best practices and rules, but there are also community and a really nice vibe of like sharing experiences together. And the accessibility champions group I thought had really interesting parallels to security champions 5, 10 years ago. They feel, like, very passionate about this topic, and they feel like it's not getting enough airtime, and people aren't making enough space for it. So, the model of creating a structure for community that is providing recognition and providing knowledge sharing and all of this, the model definitely can apply and grow into other areas. mixed opinions about whether you should have a centralized system, or if grassroots pockets of programs is better. In my opinion, it depends on how big your organization is, if they can tolerate it. You know, like, really large corporations have ERGs, like employee groups for different topics. And that's not all just one group, you have your women at group and Black at group. You don't have women that are— it's not all just one group. So one champion's domain for all of trust is probably what a smaller organization would do. But if you're very large, then have different teams do different ones and let all of that just grow organically. Just my 2 cents on that.

49:04Chris RomeoYeah, I'm glad I remembered that question before the end because that's, I always walk away from these interviews having learned many things and you gave me, I didn't know anybody had ever done that before. So that was, that was cool to hear that that had actually, those privacy champions program already existed and it just never, never crossed my desk along the way. So.

49:24Marisa FaganI think talking to Kim, we had a nice debate about this. Is it, is it appropriate to make privacy its own topic, or should it be woven in and combined with security, as a really interesting question. And I think only good things can come from at least asking that question.

49:44Chris RomeoYeah, that is, that is a great question. Well, Marisa, thank you for, for joining us and for sharing your wisdom and knowledge about Security Champions. This has been just a really, really good experience, and I know I've learned a bunch of things through this conversation. So thanks for being the guest.

50:02Marisa FaganI really enjoyed it. Yeah, thanks so much.

More on Security Culture