Security Champions as the First Followers of Culture Change

▶ Watch (6:23)

The diffusion of innovation curve frames every organization as a mix of early adopters, a skeptical majority, and laggards. Lehr used the “dancing guy” video to show how movements start: one person dancing alone at a festival gets labeled the lone nut, then a second person joins, and the majority follows within minutes. That second person transforms the lone nut into a leader. Security champions are those first followers. Engineers trust their colleagues more than the security team, so the security team needs allies who speak on its behalf.

Seven Principles for Presenting Security Metrics

▶ Watch (11:46)

Define SMART goals tied to company OKRs so metrics connect directly to what leadership already tracks. Name the specific actions you want champions to perform, because you can only measure what you define. Show leadership two to four metrics, not a dashboard of twenty. Track each metric as a trend over time, not a snapshot. Set explicit targets with a quarterly or annual deadline. Translate results into dollar amounts and time saved, not just reduced risk. Break results down by department and highlight the best performers, not the worst.

The Four Ordered Steps of AppSec Strategy

▶ Watch (21:20)

Lehr argues AppSec programs succeed when built in sequence. First, build relationships across engineering. Second, get good at finding production vulnerabilities. Third, get good at fixing them. Fourth, use root cause analysis to justify preventative controls like training and threat modeling. The order matters because leadership will question preventative measures if you haven’t first demonstrated production issues exist. Skip to threat modeling without evidence of real problems and you’ll face pushback. Proving issues come before selling prevention.

Concrete Metrics: Reachout Rate, Coverage, and MTTR

▶ Watch (23:22)

Three metrics map to the first three strategy steps. Reachout rate counts how often developers invite security in, tracked via Jira tickets or Slack messages. Lehr’s own example: 60 developers reached out in the design phase, up from 35 the prior quarter, with a target to maintain 50 per quarter. Coverage measures the percentage of critical assets under appropriate detection controls: 75% covered, up from 40%, targeting 90% by Q4. Mean time to remediate by severity surfaces both fix speed and whether teams fix issues at all.

Measuring Prevention in Dollar Terms

▶ Watch (34:24)

Prevention is the hardest value to quantify, but the math is tractable. Take an actual internal incident, calculate the hours spent in response and remediation, multiply by estimated salaries, and produce a dollar figure. Then ask: what preventative control would have stopped it, and what would that cost? Pentest findings work the same way: time spent fixing post-pentest versus the upfront cost of threat modeling. When rework time is saved, that time shifts to productive engineering work. Lehr has shown this comparison to leadership and says it lands.

How Measurement Evolves with Program Maturity

▶ Watch (38:37)

Data from roughly 30 security champion programs shows measurement patterns shift over time. Newer programs track attendance, participation, and extra training completion. Programs running four or more years measure those inputs less and focus more on security posture outcomes. The shift doesn’t mean participation declined. It means mature programs have moved past proving activity and now prove impact on the security posture. Lehr recommends the same progression: start with simple activity metrics, then build toward posture metrics as the program earns credibility with leadership.

Q&A

How do you isolate your program’s impact from all the other changes happening simultaneously? Lehr says you can’t prove direct causation, so aim for correlation: show a before-and-after trend line tied to when the program launched and let leadership draw conclusions from the chart. ▶ 19:07

Should MTR data go to struggling teams first or directly to leadership? Praise publicly and coach privately: bring underperforming teams their data directly to help them improve, then highlight the strongest performers broadly in leadership forums. ▶ 33:29

How do you handle high champion turnover as engineering tenure at companies shortens? Treat recruiting as ongoing rather than a one-time launch activity, so departing champions are continuously replaced by newly connected engineers. ▶ 43:32

Notable Quotes

Hey, we have 120 champions. Dustin Lehr · ▶ 13:47

cool, you suck. Don’t do that, right? Dustin Lehr · ▶ 15:50

frankly, it is good enough. Dustin Lehr · ▶ 19:43

Key Takeaways

  • Security champion programs are the AppSec program, not a supplement. Behavior change requires allies inside engineering.
  • Show leadership two to four trended metrics tied to company OKRs, not a 20-metric dashboard.
  • Correlation is enough. Before-and-after trend data tied to a specific program change satisfies most leaders.
  • Mature programs shift from tracking attendance and participation to measuring actual security posture outcomes.

About the Speaker(s)

Dustin Lehr is Director of Application Advocacy at Security Journey and co-founder of Katilyst. As a former software engineer and cybersecurity leader, he builds developer-centric AppSec programs that motivate and incentivize security-minded behaviors.