Why AppSec Teams Lose Developer Buy-In
Developers stop engaging with security for predictable reasons. They don’t know what security wants from them. Security shows up at the end of a sprint with a stack of problems and no solutions. Budget and time constraints push security to the bottom of every priority list before developers even see the ticket. A previous AppSec lead who yelled and called developers stupid poisons the well for the next team. When the security team can’t respond in reasonable time, developers stop asking. The result: no buy-in, no reporting, no extra mile.
What Broken Trust Actually Costs
Broken trust produces measurable harm. Developers don’t report problems when they see them. They won’t stay late to fix a security bug. They stop striving to go beyond what’s required. Innovation stalls because the conversations that generate better plans only happen between people who trust each other. A defensive team culture sets in, where brainstorming sessions collapse into silence after ideas get ridiculed. Attrition follows months later, after reduced productivity and avoided meetings. Janca once crouched behind a cubicle divider when she spotted the head of security approaching.
How to Rebuild Trust
Audience members named the core moves before Janca reached her list: find a developer who understands security and hire them, listen to developers, show up with a suggested solution rather than just a problem. Janca’s frame: “you are my customer, I am here to help.” From there: ask for feedback, act on it, then close the loop by explicitly telling developers what changed. Shift security architectural reviews to before development starts. Invite developers into tool evaluations so tuning reflects what they need, not just what security prefers. One developer’s reaction after a shared SAST demo: “Can we keep it?”
Strategies for Getting Buy-In
Training produces buy-in faster than any other tactic. Janca runs sessions and one to two months later receives emails from teams that have started threat modeling and bought new tools. Beyond training: communicate what the security team is working on constantly, so developers never need to ask. Pair data with a story when reporting to leadership. C-level stakeholders want metrics, but they remember the security champion who prevented an incident. Quick wins, like finding and rotating exposed secrets during a consulting engagement, build momentum for larger investments that take longer to justify.
What Destroys Trust
Five behaviors undo trust faster than it was built. Hiding mistakes instead of doing a postmortem. Announcing a monthly lunch-and-learn, running it twice, disappearing for eight months, then restarting. Complaining about an SLA violation before checking whether you answered their last email. Running a program that can’t keep pace with developers adopting serverless or AI. And above all: ignoring feedback. When a developer says the new tool isn’t working, book a meeting. Act on what they say. Consistency alone won’t fix broken trust, but inconsistency guarantees it.
Q&A
How do you build relationships with developers you have no daily reason to interact with in a remote environment? Janca recommends being intentionally social: drop memes in developer Slack channels, join their team meetings, use the Donut app to set up randomized virtual coffees, and create team-building events with physical kits shipped to remote employees. ▶ Watch (39:38)
Notable Quotes
don’t come with a problem only come with a suggested solution of how we can fix the problem Tanya Janca · ▶ Watch (16:37)
you are my customer I am here to help Tanya Janca · ▶ Watch (17:06)
loop back around and tell them what you did with it Tanya Janca · ▶ Watch (17:51)
Key Takeaways
- Security teams that can’t name a single developer have already failed at the most important part of their job.
- Shifting architectural reviews before development starts removes friction instead of adding it after code is written.
- Closing the feedback loop explicitly, telling developers what changed based on their input, separates listening from just hearing.
- Consistency in a security program builds more trust over time than any single impressive initiative.
- Recognizing good developer security work publicly changes team culture faster than finding more vulnerabilities.
About the Speaker
Tanya Janca, also known as SheHacksPurple, is the CEO and founder of We Hack Purple, an online learning community focused on teaching secure software development. She is the best-selling author of “Alice and Bob Learn Application Security” and has spent over twenty-five years coding and working in IT, from public service to tech. Her second book, covering secure coding for developers, was released February 5th.