Three Groups That Decide Your Program’s Fate

▶ Watch (6:53)

Jenn Gile broke the internal audience into three groups: technical champions, budget holders, and influencers. Technical champions (engineers, architects) directly engage with the tool. Budget holders (CISO, CTO, head of product) control funding. Influencers (legal, trust, procurement, operations) can kill the deal even if not enthusiastic. Gile used an application security team example: developers triage findings, CISO signs off, procurement slows purchase. Knowing these groups lets you tailor messaging per role.

Understand Stakeholders Through Research and Personas

▶ Watch (13:43)

Research combines qualitative (hopes, fears) and quantitative (engineering data, trends). Gile recommended interviewing 3–5 people per focus area, asking about role, goals, pain points. Record interviews for synthesis. Then build personas around five areas: motivators, attitudes, responsibilities, metrics, pain points. Sample persona: an engineering leader who dislikes security due to past friction, cares about DORA metrics, uptime, and team retention. Personas are written narratives, not bullet lists.

Write a Messaging Guide for Each Stakeholder

▶ Watch (18:12)

A messaging guide frames communication for a specific persona. It includes a problem statement (e.g., current SCA tool is disruptive and inaccurate), impact (delays releases, increases MTR), business value (reduces time developers spend on security), technical value (features like reachability and fix recommendations), evidence (testing results or vendor claims), and a call to action (support a POV). Gile emphasized leading with business value before features.

Validate and Use AI as a Force Multiplier

▶ Watch (24:10)

Validation means going back to interviewees to confirm the persona and messaging are accurate. Gile warned that AI cannot replace human interviews because it lacks empathy and nuance. However, once research is done, AI can synthesize interview trends, challenge assumptions, and create “skills” (e.g., in Claude) that automatically map AppSec metrics to engineering metrics. Gile demonstrated a prompt that generated a matrix translating mean time to remediation into engineering-focused language.

Q&A

How can a first security hire build trust with engineering managers who hold negative views of security? Pitch in with their team, remove problems from their plate for a couple of months. ▶ 29:09

How to get metrics from vendors when people don’t trust sales? Understand the metric deeply, then ask the vendor to explain how they got it; if it’s smoke and mirrors it falls apart. ▶ 30:06

Have you seen stakeholders use AI to justify cutting security spending? Not yet; security leaders more often use AI to show they can do cool new things with existing resources. ▶ 31:03

How many interviews are enough? Focus concentric circles on the biggest friction point; three to five interviews within that group, then diminishing returns. ▶ 32:21

What if people agree in interviews but their support fails later? That’s why you test — put the assumptions into practice and see if they hold. ▶ 33:14

Notable Quotes

it’s not about getting people to care about what you care about. It’s figuring out how to talk about what they care about. Jenn Gile · ▶ 1:19

security has what we would call a messaging problem. Jenn Gile · ▶ 4:10

your security program is a product. Jenn Gile · ▶ 19:08

AI can’t do empathy. Um, AI doesn’t do nuance very well, right? Jenn Gile · ▶ 25:18

start by doing things for them rather than asking them to do things for you. Jenn Gile · ▶ 29:37

Key Takeaways

  • Identify three groups: technical champions, budget holders, and influencers.
  • Interview stakeholders to learn their metrics and pain points before pitching.
  • Use AI to synthesize interviews and map metrics, but do the human work yourself.

About the Speaker(s)

Jenn Gile is a community builder and tech educator in the Security and DevOps fields. She’s Co-Founder of OpenSourceMalware.com, on staff with BSides Seattle, and is an advisor at Endor Labs. Jenn previously worked at NGINX, F5, and the U.S. Department of State. Outside of work, she’s…