--- title: "Security Champions" url: https://appsecpodcast.com/security-champions/ date: 2026-09-07 duration_seconds: 2883 season: 13 episode: 11 topics: ["Building an AppSec Program", "Security Culture"] audio: https://www.buzzsprout.com/1730684/episodes/19758551-security-champions.mp3 video: https://www.youtube.com/watch?v=r8ypN0Kyixs transcript: true --- # Security Champions *September 7, 2026 · 48 min · Season 13, episode 11* on [Building an AppSec Program](https://appsecpodcast.com/topics/appsec-programs/), [Security Culture](https://appsecpodcast.com/topics/security-culture/) [Audio](https://www.buzzsprout.com/1730684/episodes/19758551-security-champions.mp3) · [Video](https://www.youtube.com/watch?v=r8ypN0Kyixs) ## Show notes What makes a security champions program successful—and why do so many fail? Lisi Hocke explains how psychological safety, cognitive load, power sources, and community can help create sustainable programs. We also explore reducing security wait times, gaining organizational support, the role of AI, why champions meetings shouldn’t be recorded, and the importance of putting people first. **This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more:** [**https://bit.ly/4wMCNUf**](https://bit.ly/4wMCNUf) **About Corgea** Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. **Learn more about Corgea →** [**https://bit.ly/4wMCNUf**](https://bit.ly/4wMCNUf) ## Transcript *8,296 words · assemblyai* **0:00** That kind of shared belief among a team that it's safe for interpersonal risk-taking. I can dare to, for example, put the very uncomfortable topic, like to address the elephant in the room and not get like that retribution or like getting punished for it. So, it's not like just keeping everything nice and friendly and no conflict and whatnot, but actually rather the opposite of like really putting the things on the table. but then not having to fear that this costs me my job or this costs me my reputation or whatever it might be, or I lose that relationship to another person. So, having people really perceiving that kind of safety, we felt, is extremely crucial in a Security Champions program. **0:45 Chris Romeo:** Lisi found her place in tech in 2009 and has grown into a specialized generalist. Now focused on product security, she's passionate about quality, collaboration, and helping teams build more secure, resilient solutions. She also enjoys continuous learning and giving back by sharing her experiences with the wider tech community. Hey folks, welcome to another episode of the Application Security Podcast. My name's Chris Romeo, and I am joined by Robert, the man who needs no last name. In application security. There's not a lot of Robert in application security though. A few, a few, but not many. No, not many. Hey, uh, Robert Hurlbut and, uh, threat modeling trainer and architect. And, uh, as usual, glad to be here. Uh, I've been doing some traveling and so glad to be home finally again. So yeah, excited for this podcast. Home in that fancy penthouse apartment that you live in. I mean, look at that design behind you. Come on. That's a thing of beauty. So, uh, yeah, we are certainly very lucky today to have Lisi with us. And we're going to talk about a topic that both Robert and I have, have been involved with for, seems like decades at this point, but also something that we need to learn a lot more about because this is one of those areas, Security Champions, where there's just a lot more to learn. But Lisi, before we get into that, we always love to hear our guests' Security Origin Stories. If your life was a comic book, what would we find in episode number 1, or book 1, I guess? **2:19** So, hi everyone. I'm, first of all, thanks for having me. It's great to be here. My origin story, what would be in that book? I think that would be a conference that I joined in 2017 that had a a separate day where they had the conference structured as an open space, which means people bring the topics and everybody can also contribute and chime in and you can join whatever session is to your liking. And one person turned out to propose a security session in the sense of, let's hack the OWASP Juice Shop. Now I would say very classical. Back then I was like, what's that? Never came across that. At that moment in time, I've been working in software development teams for quite a while already. I've been usually in testing and quality roles, which means I'm sort of like all over the place, whatever is currently needed, I'm going to be there. So, I often called myself like a specialized generalist. So, I definitely was intrigued, like, oh, security. I always wanted to learn more about that, but I sort of like always hesitated because I felt like, Maybe that's more for experts, you know, it's like a separate role. Maybe, maybe not for me in that sense, which is funny in hindsight because yes, I was all over the place for everything else, so why not security? But anyways, I joined that session and it turned out it was just 3 of us and we basically happily gathered around a laptop and started working on those challenges together. And I really felt like even in the first exercises, I was like, Wait, this is a lot more closer, like a lot closer to what I'm already doing than I ever thought. So maybe there is a way for me into security because it's not that far away. So suddenly I had like that kind of gate that I kept for myself as well taken away from me. And I was like, okay, I wanna learn more. I was intrigued. So from then on, I started A, well, actually it was the year following, I started a journey where I paired with a lot of people from the community on all kinds of topics. And now I knew security could also be one of those topics. And I had a lot of security sessions as a peer working through the OWASP Top 10, learning more about those things. Also wanna see it, how it plays out in real life. So we practiced on deliberate practice applications and so on. And anything that I learned, I also could contribute back to my software team, right, as I went. But then in, I think it was 2021, no, yeah, end of 2021, I slowly started to looking outside of my current job back then. And I got an offer to join a company or a different company basically. And that company happened to have a Security Champions program. Now, At that moment in time, I have read about those things already because, again, I was like educating myself, following the people, learning from blogs and podcasts and whatnot. So, I knew about those programs, but I've just never seen one. We hardly had any security folks in general at the companies that I worked at. So, when I joined that company, I was like, okay, where can I sign up? But then I learned, oh wait, there's already another person on my team who is already a champion. So, sort of that place was taken and I felt like, don't let me. let's not have that stop me in that sense, because I can still invite myself in. I was that senior already at that moment in time that I knew sometimes you have to invite yourself in. The good thing is I met with a lovely security team there who was definitely like a, I would say they were leading by example in a sense of they welcomed people, anybody who had interest in learning more, they welcomed them with open arms. They made it really safe for me to just chime in and also push myself in there. They encouraged learning. They were everything but condescending. So that was a really good time. I think we'll, we might go into that deeper later, but after 3 years, it was time for another company switch. And back then, so that company had layoffs. My whole team was affected, which was actually okay at that moment in time due to other reasons. But it was definitely a moment in time then to think, okay, what next? Where do I go from here? I have this champion experience now as well. I'm pretty, pretty senior in the testing quality space. I have different avenues I could now pursue. And back then my security lead also encouraged me like, hey, why don't you just apply as a security engineer? Because hey, you're there. And I was like, oh, really? I don't know, maybe. And I had talks with people and it turned out there was options actually for me. I was very, very open, of course, where I'm coming from and what I bring and whatnot. But it was sort of a really good moment in time for me, although the whole market was already pretty bad, that this avenue was very open. I was like, okay, let's try this out. So I joined the company as a full-time security engineer. Now, for the first time working in a central team, like an enabler team, instead of like a, we deliver everyday parts of the whole product. And I'm now there for like over 1.5 years. And I happened to build my own Security Champions program here because, well, it's a thing. And they of course knew about the history and they wanted to look for that anyways for a long time. So it was a perfect match. And now I'm gathering my own experiences and that's bringing me here. **7:59 Chris Romeo:** This episode's sponsored by Corgia. Design it, build it, ship it. Corgia secures it. Corgia is an AI-native app security platform covering your whole software lifecycle, from the first architecture diagram to code in production. It brings design reviews, AI-powered code scanning, and autonomous pen testing into one platform, so your team spends less time chasing noise and more time fixing what matters. Visit corgia.com. C-O-R-G-E-A.com. .com. Corgia, one security platform for the entire SDLC. Very cool. Very cool. I have one follow-up question. Have you connected with Bjorn Kimmenich, the project lead of Juice Shop? Because like, this is the type of thing that like, this is why he does what he does, right? It's your story. **8:53** I actually, that's lovely that you say that, because I did have that chance. And it happened to be at the, because I'm also co-organizing a conference, a security conference, and we had him as our first keynote speaker. So I met him in person for the first time and obviously I had to tell him like, look, you're part of why I'm here. **9:13 Chris Romeo:** That's so awesome. **9:14** Yeah, that was amazing. Very cool. **9:17 Chris Romeo:** Well, Lisa, I think you and Mireia had also put together a talk where You'd stage it as role plays, security versus champion, opposite trenches. Why role play instead of just talking? **9:32** So, I met Mireia Cano also at other conferences. We, we joined together like as a CTF team and more, and we really had this idea, hey, maybe we make it to OWASP AppSec Global EU. Is, would there be any chance that we we get there as speakers. And Mireia came up with that topic of how about security champions? Because we're basically representing both sides of, as we called it, the trenches of, of course, obviously it doesn't have to be trenches. And well, we did talk about that because she was coming from the security side of things from the start. And I was going the champion way into security. And she felt like, okay, but we have to Like, how do we present this? Because we are presenting these very distinct perspectives. We had a draft, of course, already on submission to say like, okay, maybe we can do this more like as a dialogue on stage to really not only showcase the different perspectives, but also make it engaging and lively and interactive even nearly. Then the proposal was taken and accepted and we were like, okay, okay, now we have to do it. And while we worked on it, we really figured that kind of roleplay is a key element to make things more tangible, to convey the messages that we have in a way that hopefully doesn't let people fall asleep, provides a reason that 2 people are actually on the stage. So the talk can't be done by just one. What I personally also really despise is if you have like several speakers on stage and one person hands over the slide to the next one, like, okay. slide 2, person X is going to tell you. And like, they just go ping pong or like half the talk, half the talk. And I'm like, but why isn't just one person presenting this? Like, what's the reason? Because there was surely potential to make it a bit more, like to bring the message home. **11:34 Chris Romeo:** Was there any controversy between the two of you? Like, did you create some controversy so that emotions could bring Could, could raise high from the stage? **11:45** Yes, we actually did. And until the very moment we finished the talk, we weren't sure, would it be too cringe if we do it like that? So it was definitely a risk we took to say, we're gonna do this more dramatic in a sense, or like not overly over the top, but still hopefully in a way that's relatable. Or people like, like look at this and see like, oh wait, oh, I've been there. Yeah. Right. Or I heard that from a champion or like just something to connect to. But again, we weren't really sure because we started with the drama, like people, like champion and security being disconnected. Again, not really at war in that sense, but more like frustrated, emotionally loaded. not understanding each other truly, also not trusting each other at all, but sort of in that relationship together. And from there, based on the matters that we presented, we tried to showcase through the role play on, okay, how can things change for the better, but also for both sides, not only for one, so that it actually becomes like, or gets a chance to become more sustainable and long living in the end, because— Well, most programs don't make it that far. **13:07 Chris Romeo:** Yeah. I like how you use that word disconnected versus at war. I think that's a really good way to describe what a lot of champions programs, like the tension that exists in there. It's not that we don't like developers or developers don't like security people or something. It's just a disconnection of scope, of effort, of, of all of those things. And so many programs get that wrong and they, they never embrace, like, how do we close the gap between there? And so I think we'll get into that a little bit as we go forward. I want to deal with a couple of, uh, we're going to call labels that you shared with us earlier. The Department of Waiting, which I'm familiar with the Department of No, which is because I've been in security a long time. And for the first few decades of my life in security, we were the Department of No. But I'm curious about department of waiting and the problem of later. So, where do these come from? And then how, what are the mitigations against them? **14:08** So, they're coming both from different times. Let's start with the department of no, sorry, of waiting actually, because of course it's like the pun is intended in that sense. This is what I encountered now in my first full-time security role, when I entered, I mean, background information is also, they started out small with individual contributors to somehow build up security all over the place for the whole company, also corporate security, product security, everything at the same time. So it was a very different history where people were coming from. And now suddenly when I joined, also another person joined and suddenly we grew into a team of like 6. So it was, really changing the circumstances. But what I observed, or what I felt extremely problematic as well, from coming from that software development background, was like how long people needed to wait until they got any feedback from us. And that made me really uncomfortable because now I'm on that team and like, this, this, like, this doesn't work for me. I can't have them suffer and wait for so long. And then I know that feedback will be useless because things will have moved. They will have made decisions because they had to. There's all the incentives against keeping them waiting. And it really made me also, it really surprised me. Like, okay, maybe there's also a disconnect here actually, like from the reality of like everyday software development and how fast things have to change. And actually fast feedback is an asset, right? It's a really, really good thing. **15:42 Chris Romeo:** Yeah. **15:43** And also for security. But then we kept them waiting for months and months. And I felt like, okay, let's address this elephant and really bring this on the table also with my own team. Like, okay, what can we do? What are the problems actually here? Why people wait? Or maybe they don't even reach out to us because they would just wait, right? So no, no means, there's no sense in even reaching out to product security if you know Either you would just be kept waiting or then shortly before you have to release because of, you know, business goals, then suddenly you would get the no, which is also horrible. And nobody wants to suffer in that and feel miserable. I really felt, okay, let's, let's talk about this. It turns out also this team, obviously, I mean, I'm very lucky. I'm very fortunate with my team. They're lovely people. also very mature, actually, from a human point of view. So we all put together and said, okay, what is the problem? Like, how people reach us, how do we want to respond, how much closer do we need to get to people's realities to really understand why they right now need that feedback? How can we encourage also people or share our circumstances on let us know earlier? Maybe it's not a checkbox shortly before release, the day before or something, because then obviously we— can really give that feedback in time and things pile up and we have a huge backlog, but maybe we can get that input earlier. Also, maybe a threat model doesn't have to take, I don't know, 6 weeks. Maybe we can have a lightweight approach and yes, maybe it's not perfect, but it's way better than nothing. And people will come back and we do a lot more and more frequent and more smaller. And we have way more positive impact compared to just keeping people waiting because then they will not even come to us. So yeah, the department of waiting came from that. We did turn the ship around. **17:43 Chris Romeo:** What did you get down to? Like how, what was your turnaround time once things got kind of normalized? **17:49** So I think we're not perfect yet, by far not. There's definitely potential for improvement, but we do manage to now Depending on the topic. So sometimes just give instant feedback on demand. Like if it's a small thing, people learned, okay, they can reach out. Maybe we can schedule like a half-hour call in the afternoon, get it figured out. If we, if we see, okay, that takes longer, then we plan it in, but people know what to expect. And that's also a lot of part of it. They have the transparency, they have the clarity where we are also coming from and they know what to expect. But for other topics. They now have like a centralized way to also reach the whole team because that was also part of the waiting. The communication structure was like people reached out to just single people that they knew, and then they kept waiting because not even the whole team knew that this request even existed. So to increase the resilience in the whole team, we have now like a central income of like, like a service desk in that sense, like with tickets that we actually work on. So it's not only like, okay, now I have a ticket system and I keep waiting, but They also see then through the feedback, okay, wait, we're on it, or, hey, we can't work on it right now because we have X, Y, Z, but hey, let us know if it becomes urgent. So expectation management did a lot of the turnaround, as you just said. Again, are we perfect right now? No. We often say like, hey, we would love to be even more on time. There are still a few blockers in that way, but we came far. Already. Yes. Great. **19:24 Chris Romeo:** So, you were a champion for 3 years before you became a security person. What did you believe back then that turned out just completely or dead wrong? **19:33** So, dead wrong from a program point of view or advice? **19:40 Chris Romeo:** Any of those. I mean, what you believed to be a champion and maybe security, and then you became a security person. And, and so maybe various beliefs or practices or any of those that just turned out to be wrong in what you originally believed. **19:55** It's a very intriguing question, but I have to say, I haven't spotted like a complete misconception yet, which is probably due to my previous work role because, so I've been working in testing quality, which often means like, okay, Yes, you can fix waiting times because that's also a big part of if you can provide quality products, feedback cycles, all these things, you can fix basically your local system in the team, but you often have to then move higher to see, look at the underlying organizational dynamics. How do teams communicate? What about the structure? Where are the incentives, the reward system? Like actually fix the organization culture so that you can do your work in the team. And now that I moved to security, I feel like this sounds so familiar. It's just coming from that lens and that angle. And that's also what I felt as a champion already, in parts, because I felt, okay, we're talking about the same things like prioritization, transparency, collaboration, communication, all the basic things to enable good work. And what that type of work then is might differ, but it's still those foundational layers of fostering a culture where good things can happen. So coming from that standpoint already, I think I had more misconceptions back when I was a tester because I was the police as well. That misconception is long gone, and I did not take this with me to security because been there, done that. Learned that already before. **21:34 Chris Romeo:** So, in the talk, you covered 4 things that make champions programs actually work. So, can you walk us through those 4 things and just give us some thoughts and guidance on each one? **21:47** I'm happy to. So, we started out with security and champions, well, already in that established relationship of like a program running for a while. Maybe some things are working, others are not, but they're disconnected, right? Like, things are off. Everything is working and you're wondering why. So that was sort of the starting position. We started then with the most foundational measure that we advise people to really look into, and that is fostering psychological safety. If, and maybe to explain what we mean by that, it's basically that kind of shared belief among a team that It's safe for interpersonal risk-taking. So I can dare to, for example, put the very uncomfortable topic, like to address the elephant in the room and not get like that retribution or like getting punished for it. I might still need to take the courage, most likely. So it's not like just keeping everything nice and friendly and no conflict and whatnot, but actually rather the opposite of like really putting the things on the table, but then not having to fear that this costs me my job or this costs me my reputation or whatever it might be, or I lose that relationship to another person. So having people really perceiving that kind of safety, we felt is extremely crucial in a security champions program because we're talking about security here. So whenever something happens, And maybe your team or you yourself might have been the person enabling that thing to happen. That can like come with a lot of shame. That can come with a lot of like all kinds of emotions actually, right? Also, especially depending on the background you're coming from, also what kind of privilege you bring, right? It really, really is different. So having that kind of safety to say like, okay, I made a mistake, or my team made a mistake, or something is wrong here. Let's look at it together. This is so essential for anything that follows, because if we don't have that trust and that safety that people won't hold it against me that maybe I missed that or I've seen something, where, what else should we work on? Honestly, this is, I've seen cultures that were really blame-driven, and what usually happens is like, oh, you don't have any incidents anymore because nobody reports any because you would get blamed. **24:16 Chris Romeo:** Of course. **24:17** You won't, right? **24:18 Chris Romeo:** So, I have a question based on this fostering psychological safety. I think I got it right. **24:25** Yes. **24:25 Chris Romeo:** Because I have an example of where we didn't do that and it caused a really big problem in a champions program. And I'm curious, so that's, that's what my ultimate question is. Does this concept adapt or expand to the organizational context as well? But let me tell you what happened and then that'll give you some context. Early days of the first champions program I ran was a lot more Wild West. So I had champions distributed across business units and product teams. They didn't all have the blessing of their management to be champions. And so some of them were specifically told not that they were not allowed to be champions and work on this stuff. And they did it anyway. And they eventually got fired as a result of That being a part of the reason why they got fired. At least that's what I understand. So does that, like, did I have a, did we have an environment like, I mean, how do you read that? And listen, you can, I mean, you're not going to hurt my feelings. Just give me an assessment. I just, I'm just curious, like, this was 15 years ago and I wouldn't do it the way, and I made a change after this that in the program to fix it. So it never happened again. But I'm curious, is that— what you mean? Like, does that fit into the bucket of fostering psychological safety? **25:39** I think partly because it does sound that that person who was told not to contribute to the Champions Program, but still did, that the relationship between them and their manager was definitely broken because some, like there, I don't think there was any trust or safety there. They dare to still do nonetheless, but that risk was not safe because in the end also they got fired, right? **26:10 Chris Romeo:** Yeah. **26:10** What we speak of here is also, especially the safety with, I mean, the safety can be between 2 persons like that. That's where my partly comes in because often it's like, it's about the safety feeling in a group. It could be a software development team, it could be A champions group. It could be the security team as well. So within that kind of bounded context, how safe am I to take a risk to say like, look, X, Y, Z is not working, or I feel not heard, or whatever it is, right? Like to bring up the deeply uncomfortable topics and not get, you know, the retribution that you just shared. This is, so having that like as a symptom would be an indicator for me, yes, to look into the culture and how much, there might be more things to observe, obviously. So just from like the one example, I might have a hunch like, okay, safety might not be there. Maybe it is there in other bubbles. Could be. Maybe that person was totally safe within their teammates, but not with the manager. It can differ. It's also not like, it's not like a continuum. It's something we have to invest continuously in to keep it up. Even if we reach like a good level of safety and people are happy, doesn't mean the next, you know, bad behavior or bad action basically can completely destroy it because trust is also very, very easily destroyed and hard to build up. And the same is with psychological safety. **27:46 Chris Romeo:** So just to close the loop, and then we'll go to the second, the second thing. After that happened, I put in an opt-in that went to the champion and their manager, and they both had to agree on a yearly basis that this is okay. This, this, the manager had to say, I agree, my employee can be a champion. And so that was the control that I put in place, unfortunately, after some issues occurred, but that was my, my response to it. So, so what's your, so what's the second thing? So like, Fostering psychological safety. I'm going to remember that one. That's sticking in my head already. What's the second one? **28:23** So, the second one is, okay, maybe you're having a way better relationship right now, right? You can also be vulnerable in front of each other and not like be open, but it might happen, or maybe you've seen it happen, that security comes and just overloads the champion with like, oh, and you can do this, and I need your help there, and maybe the feedback that, and whatnot, or just like tries to do a training, but starts at a level that's just not digestible basically for the people because it's not where they are right now. So the second point that we presented is cognitive load. So cognitive load comes, so this comes from, I think, learning theory or cognitive. I'm not, I can't remember, recall correctly, but in general, what cognitive load means is whatever, when we learn new information, so all this information needs to go first through our working memory before we can store that information into long-term memory. And that kind of effort, well, is needed to digest things, but also our working memory is pretty, you know, short-lived in that sense. So it doesn't, it doesn't really hold much information for long. And that's where, which is our limiting factor when we learn new information. Cognitive load theory basically tries to approach this to help us, to give us a model what to consider for more effective learning. They differentiate 3 different types of load. One is intrinsic, it's basically inherent in the nature of the topic, whatever you want to learn, it comes with a certain complexity. That's not really something we can change, but we can break things down. We can make things smaller, go smaller steps. There's also extraneous load, which is basically how we convey the information. Maybe we are in a very noisy environment and that actually creates stress that's really unnecessary. So we can shape the environment. We can also make sure we present the information in a way that's actually digestible and also go those small steps. So we can, for those both loads, we can try to reduce them as much as possible. So the third type of load is actually optimized for, because that's the the actual learning, that's called germane cognitive load. Sorry. And that's really when we connect the dots so that, okay, we got it. We have this existing knowledge. There's a new piece of information. We can connect the dots. We can store it. That's what we want to optimize for by holding the other 2 types as low as possible. And yeah, we face this in Security Champions programs all over the place by, through trainings, through we present information to stakeholders. Also, our champions actually need to manage the cognitive load of their team members when they need to advocate for security in their teams. It's all over the place, not only from security champions, but also how we communicate to the organization maybe, right? Or to stakeholders. So, call to action is consider cognitive load in all those actions and think about, okay, can we maybe reduce the unnecessary stuff and make it more... **31:23 Chris Romeo:** They're trustable. **31:24** Okay. **31:25 Chris Romeo:** How about the third one? So, let me just recap them real quick. Fostering psychological security, cognitive load. What's the third one? **31:34** Third one is, well, the security in that sense is not the manager of the champion. The champion is not the manager of the team they should, where they should advocate for security in, right? So, they won't lead with that kind of formal authority of for example, being a manager, but we still need to influence people, right? And convey information and hopefully get people to change behavior, do better things so we can increase our security posture. But how to do that? Here's where, again, I mean, there's many models out there, but what we presented is one of them on a, like a tip of the iceberg level, which is the power sources or power bases from French and Raven, which is one of those social power models that is Around for ages. It's actually pretty old. It's been revised a few times. It's probably still flawed, even though through science we still learn. It's a model in the end, and no model is perfect. But if it helps us find new ways and inspiration how we can actually have positive impact and drive change, because that's what we ask from champions, and that's what we try through champions, then maybe it's helpful. So tapping into more power sources, Instead of just saying like, oh, I'm helpless. I don't have that formal authority. I can't do anything. And having those kind of new pathways open for you, that's what we emphasize in our 3rd step. Okay. **33:02 Chris Romeo:** So that adds power sources is the way we can kind of summarize that one. Okay. How about the 4th one? **33:09** Well, finally, maybe Between security and champion, right? Everything's pretty good now. They have trust, right? They are not overloading each other. So mental overload is prevented. They also know how to drive change, influence people in a good way. So we see that change, but it's still between security and champion all the time. So what if security is not available or, you know, like maybe just on vacation? What? ever happens, then does the security champion program stop? Is nobody there to help? Are they left alone? Hopefully not. And our proposal here is to build a champions community so that we're not overly relying on like a central security team, which is probably also like a lot less people. That's why we use champions often, right, for scaling. But they actually have their fellow champions. So why not ask them and also get inspiration from each other, tackle challenges together, maybe also solve organizational problems together and find something that actually works across teams. So to bring people really together on that shared interest in a community of practice, really, where they frequently meet and they also frequently practice together. This is what we advise for to make this long-term sustainable, resilient, and not have security people also burn out in just the manner of trying to drive this program and always bring something new. No, actually the champions are there and they can do a lot of things as well. **34:47 Chris Romeo:** So, here we go. I'm going to recap. Tell me if I got any of them wrong. Fostering psychological safety, cognitive load, power sources, and community. Those are kind of the 4 pillars that you laid out there. So yeah, I could see how a lot of those could work in much further than champions, right? Like the, like the, these aren't champion-specific, but they're things that are very applicable to champions, especially because in like your example of power sources, you often have managers in play and maybe an individual contributor, and they can't just tell the manager, Well, this is what I'm going to do. They have to find a way to almost business case or ROI. Like, you know, I can, I won't do it, but here's what we're going to lose as a result of it. They can, there's other things they can show data, they can do other things to help with a decision. And then if the manager says no, all right. I mean, we try, I did my best. I tried everything I could, and you're making a risk decision, risk management decision now. And hopefully you don't carry a little notebook around with you and just document that down on your manager. Like, let me just take a note of that, how you made a bad risk management decision. Not that I get to review you, but in case anyone ever asks me, probably not a good plan. **36:03** But yeah, that sums it up. And of course, we connected everything with concrete examples for Security Champions programs. But as you just said, no, these are not specific to Security Champions programs, and you can actually apply them to other scenarios you're working together with other people in just as well, because they're rather fundamental for doing good stuff together. Okay. **36:26 Chris Romeo:** Let's talk about AI, and we've, we've seen how much it's impacting development and security. What about security champions programs? How is AI changing those programs, maybe in who you recruit, what you need from them, and how you run it? **36:43** I think that's a great question. So far, my answer right now that I'm now driving like a rather freshly new program, so it's living for half a year now, so we don't know yet, it's still a pilot. It has good indicators, but from that experience, nothing changed so far. So from my point of view, because that's a lot of work on the human side of things, on getting people together in In a good environment where they can actually speak openly, safely, where they really can start to get to know each other and trust each other so much that they actually work together. That's for me the realm of like actual human effort. Maybe some people could use AI here for helping them to, to think about new ways or like to inspire them. Personally, Again, maybe because of my background, could be. It's, I could like tap into a lot of the previous experience already to come up with, okay, what is the intentional design of this specific program? How does it fit to this specific company culture? And I might still be wrong, right? Because we don't know yet. **37:53 Chris Romeo:** So, the good news with AI is it's all changing every week. So, you know, a wrong this week could be a right 2 weeks from now, depending on how the models evolve. **38:03** That's so true too, right? So even if you get help from models in some ways, it would be a really good question for people who actually try to use this and see what they really got out as, not as output, but really outcome in that sense. **38:18 Chris Romeo:** Mm-hmm. **38:19** Right now, maybe, so we, of course, we're talking about tooling in sessions, for example, or we are talking about how does it fit into, how can we support our security development lifecycle through all kinds of tools. And some might be also AI tooling, but it's more like a, I don't know, it's not like a key driver of the program itself, at least for our case. Again, might be different or is very likely different in different companies. And hopefully it is different because there's no one size fits all. **38:51 Chris Romeo:** Yeah, I was, I was kind of thinking about this as well. And the, the, it, it's, it made me think of a, of a kind of a different example, which plays right in with, with champions programs. Like, how is AI impacting local meetups? I think the answer is it's not. A local meetup is a community gathering. You get to see people that work at other companies, share ideas, talk, have the human connection. Like, Exactly. And even if the, even if the meetup is about AI, AI isn't changing how we do meetups as humans. And so I'm kind of, I'm almost backpedaling on the question here because is the AI even supposed to change Champions programs? And I don't, I don't, I don't, I don't think, I mean, it becomes, like you said, it's a vehicle for how do we use AI well, but it's the community that's the core of it. AI is just on the outer edge as, as another thing we have to deal with. But it doesn't, like, I'm not envisioning a, a world where you join a Security Champions meeting and there's a host and you're like, wait, who is this? It's, it's Champion Bot. Hi, I'm Champion Bot. I'm here to instruct you on SQL injection. **40:06** You know? Exactly. **40:06 Chris Romeo:** Like, I don't, like, that's, that takes the whole human element out of this. And that's what makes Champions programs thrive is the connection, the relationships that we have amongst a shared group of people with a shared passion. or some amount of spark for security. So yeah, I'm, yeah, I'm not seeing it either at this point. And I wrote the question. So. **40:27** I mean, it would be really interesting, um, also how it could fit in in a way that still fosters psychological safety, for example, as we just talked about, because so right now what we have as a working agreement is we don't even record meetings because just to set the ground for people being really free to speak up and not fear that that recording gets out of hand and somehow someone else, maybe their manager, finds it and then they get the retribution. So if you would have like an AI bot take notes or something, that would be super strange in that setting. **41:02 Chris Romeo:** I've been a part of a couple of champions programs over the years, and I've, I've advised some other ones along the way, and I've never seen anybody not record. **41:11** Mm-hmm. **41:12 Chris Romeo:** The monthly meetings, but it's brilliant. I don't know why we did, like part of the, the, the benefit of Champions Program is being there. **41:19** Exactly. **41:20 Chris Romeo:** As part of the event. And now I was dealing in, in the big program, I was dealing with people on multiple continents and a lot of time zone drift and stuff. But yeah, that, like, that, that's one of the key, one of the big takeaways. I'm, I'm, my eyes have opened, like you shouldn't record these things. They should be an open space where you can say something where you don't have to worry about somebody's going to listen to it later. I love that. I didn't, I've never thought of it. **41:45** I'd also rather repeat myself and still have that human connection. I'm totally fine with that compared to, oh, but you could be more efficient or whatever through like sharing a recording. But is that really getting watched? They don't get the atmosphere. They cannot, like, it's about also not just consuming. It's about really try to build a community, right? Where the people co-create and also co-shape that program. So that's like the endeavor that's not just imposed, but we actually build this thing together that it benefits all of us. And one part of that, how to bake it in, is what we currently try and so far worked pretty well. We don't record. Yeah. **42:24 Chris Romeo:** I love that. I'm going to tell people, I'm going to tell people that in the future, don't record the meetings. I'll tell them that you told me though. So I'll pass on the attribution. **42:32** You might also see some videos someday showing them. **42:36 Chris Romeo:** So the last thing that we want to deal with is one of the challenges with champions programs is a lot of them die on the vine. So that big one that I was a part of started and stopped. I was the 3rd phoenix rising from the ashes of the program. It had started and stopped, started and stopped, and then I got asked to pick it up. And so it was a very common rhythm in the organization as it would get some traction and then it would, whoever was running it would lose interest or leave the company and all of a sudden it would fall back down to zero. So like, what is the real reason that these things fail and what should we do to mitigate those failures? **43:17** So I also read about like so many programs Not making it in that sense. All, I haven't witnessed one yet before because the one I was on, right, then also lived on after me. The one that I'm currently driving, well, it's still pretty fresh. It's still a pilot. We don't know yet its future, so it might also still fail. We currently do our best to not make it fail, obviously. And that's also, that was also part of my intention. How do I design this program so it has better chances at succeeding and being valuable and not just like a checkbox exercise that, you know, nobody needs. And part of what I read about was, it was actually all over the place from like lack of expectation management, lack of buy-in from managers, also, as you shared before, from stakeholders who didn't know what this is and shut it down, no measurements or metrics or like any kind of like signals to know where you are right now and where to steer next, right? So that you couldn't even really adapt because you couldn't observe even. So all these kind of different points of potential failure points, let's say, is what we currently try to avoid, but likely there might be more. I think the core parts are also nicely described by the Security Champions guide From Dustin Lear, which I actually really like, which also links to a bunch of other resources. And there's also parts on like how to not make it fail in that sense. But I do think in the end, it probably still boils down to the main point that Mireia and I tried to convey in our talk, that lack of safety, like that still maintaining that kind of disconnect. That kind of like, it's, I don't even know what I signed up for as a champion or like, oh, something else gets more interesting or like, I'm not really that invested or whatever it is. Or maybe I'm super invested, but I don't get any support, encouragement, help because they're so far away, maybe. Whatever it is, I think this is the first point really to, to whatever happens to ensure that We go together. So even if it then would still fail, maybe we have a lot more insight because people are daring to share it with us. So we know if we don't go to second round, what to fix. So I would say most likely, but that's my hypothesis, it was a lack of psychological safety. **45:49 Chris Romeo:** I could see that as well. Definitely. Now that I understand that concept better, I could see how that's, that's a, that's a leading cause of Programs falling apart along the way. Well, Liesl, how about a key takeaway or a call to action for our audience? Is there anything you wanna leave our audience with as homework? **46:07** Well, with our talk, once it's out, it's not yet published, so I expect it in like a few months. I hope it will then convey the concepts we just talked about even close, even more closer to the point. Maybe you can then also judge if that role play was cringe or not. Right. And we also include like a bunch of resources in our slides. Um, the slides are already out there so people can— **46:32 Chris Romeo:** Okay. We'll put a link to the slides in the show notes so folks can see. **46:35** Exactly. So they can read up on the resources that we mentioned and also go a bit deeper, which would actually be part of my call to action. But I think if I boil it down to one point, put people first. That would be my, my main call to action. **46:52 Chris Romeo:** That's a t-shirt right there. T-shirt idea. Put people first with your Champions logo underneath it. **46:59** Exactly. **47:00 Chris Romeo:** I will have those available on the AppSec Podcast merch site, which doesn't exist. No, it doesn't exist. Well, Lisi, thank you so much for sharing your, your knowledge and expertise with Champions programs. I know I, like I said, I've been doing Champions programs for a long time, and I took a lot of nuggets out of this that, that I can apply in the future. And so that's, that's why we do this. That's why we do this podcast, because we want to share new thoughts, new ideas so that other people can get better as a result of it. So definitely appreciate your expertise. For those listening, if you wouldn't mind, please subscribe, click like, do, do something nice towards wherever you find the content that you're listening to. And with that, we'll say goodbye from the Application Security Podcast. **47:43** It was a pleasure. **47:45 Chris Romeo:** That's it for this episode of the Application Security Podcast. If you found this useful, share it with someone on your team. And if you're on YouTube, subscribe and drop a comment. On Apple or Spotify, a quick rating helps new listeners find us. We'll be back next week with another conversation. Until then, keep building secure stuff. --- Source: https://appsecpodcast.com/security-champions/