TL;DR: Security champions programs often fail because security teams start strong, then stop communicating, leaving champions disengaged and the program to fade, according to Semgrep. The practical lesson is that lightweight, regular contact matters more than bursts of training, because cadence sustains participation and keeps the program visible.
At a glance
What this is: This is a practical guide on keeping a security champions programme alive through steady communication, monthly check-ins, and targeted learning touchpoints.
Why it matters: It matters to IAM and security practitioners because programme decay is often a governance failure, not a tooling failure, and the same cadence discipline applies to identity, NHI, and broader security ownership models.
👉 Read Semgrep's guidance on keeping security champions programmes active
Context
Security champions programmes usually fail for the same reason many governance efforts fail, which is that the operating rhythm disappears after launch. The article argues that the problem is not lack of intent but lack of steady communication, so the real control is programme cadence.
In identity and security programmes, champions are a force multiplier only when the work is lightweight, regular, and tied to useful outcomes. That is true for secure coding, policy rollout, and identity governance alike, where attention decays quickly if leaders only appear at kickoff.
The starting position described here is common rather than exceptional: teams over-invest early, then leave a long gap where the programme becomes invisible. That pattern creates the same sort of control drift seen in identity and access programmes when ownership is not actively reinforced.
Key questions
Q: How should security teams keep a security champions programme active over time?
A: Use a predictable cadence rather than sporadic bursts of activity. Monthly 1:1s, a short group update, and tightly scoped learning sessions keep the programme visible without overwhelming participants. The goal is to reinforce ownership, capture follow-up actions, and show that the programme still matters in practice.
Q: Why do security champions programmes lose momentum?
A: They usually lose momentum when communication stops after the initial launch. Champions already have full-time jobs, so if security disappears for months, the programme feels optional. The fix is regular contact, relevant content, and a clear record of what each champion is expected to do next.
Q: What do security teams get wrong about champion programmes?
A: They often confuse coverage with effectiveness. A long list of assigned champions can look impressive, but if those people were not willing participants, the programme will not change behaviour. The real measure is whether champions are active, informed, and trusted by their peers.
Q: Who is accountable when a security champions programme fades?
A: Accountability sits with the security team that owns the programme. If there is no cadence, no follow-up, and no visible value, the programme will drift regardless of how engaged champions were at the start. Governance only works when someone is responsible for maintaining the loop.
Technical breakdown
Why security champions programmes lose momentum
Security champions programmes fail when they are treated as a campaign instead of an operating model. If security sends a burst of training, then goes silent for months, champions lose context, managers stop seeing value, and the programme loses organisational weight. The technical issue is not technology, but governance throughput: there is no steady mechanism for feedback, prioritisation, and follow-up. Monthly 1:1s, a short update email, and one focused learning session create a repeatable control loop that keeps work visible without overwhelming participants.
Practical implication: set a minimum communication cadence and assign ownership for follow-through so the programme does not drift.
How targeted enablement beats broad training
The article makes a clear distinction between useful enablement and generic content. Champions should get the specific material they need to support their teams, such as secure coding, threat modelling, tool configuration, or policy consultation. That approach works because it aligns learning with actual decision points. Broad, unfocused training burns time and erodes trust, while targeted sessions create relevance and a clear line from learning to action. In practice, the programme needs a content strategy, not a content dump.
Practical implication: tailor each session to a current engineering or governance problem, rather than recycling general awareness material.
Why feedback loops matter in security governance
The monthly email and 1:1 notes are not administrative extras. They are the feedback loop that tells champions the programme is alive, captures action items, and surfaces where support is needed. In governance terms, this is how you prevent a programme from becoming a name only. The same principle applies across identity, PAM, and NHI programmes: if decisions are not captured and revisited, accountability fades and the control ceases to operate as intended.
Practical implication: record actions, revisit them on a schedule, and use the programme as a living governance channel rather than a static mailing list.
NHI Mgmt Group analysis
Security champions programmes fail when communication becomes episodic. The article correctly identifies the most common failure mode as loss of momentum, not lack of interest. That is a governance problem, because a programme without recurring touchpoints cannot maintain ownership or visibility. For identity and security leaders, the lesson is that operational cadence is a control, not an administrative detail.
Lightweight, recurring engagement is more effective than event-driven training. Monthly 1:1s, one lunch and learn, and a short email create a sustainable support model that respects the champion's day job. This is consistent with how effective identity programmes work: repeated reinforcement outperforms one-time rollout energy. The practitioner conclusion is to design for endurance, not launch spectacle.
Security champions need relevance, not volume. The article's advice to teach only what champions need to know mirrors a broader security principle: content must map to actual work. Whether the topic is secure coding, policy review, or tool use, value comes from immediate applicability. The practitioner takeaway is to align enablement with the decisions champions are expected to influence.
Programme decay is a signalling problem before it becomes a control problem. When updates stop, participants infer that the programme no longer matters. That is why a short monthly email can carry outsized governance value. The practical conclusion is that leaders should measure continuity of communication as part of programme health, not treat it as optional admin.
What this signals
Programme health in security is often measured too late. The better signal is whether communication still has a rhythm, because cadence is what keeps ownership visible and prevents initiatives from collapsing into one-off events.
Communication drift: when updates become irregular, participants infer that the programme is no longer a priority. That same drift shows up in identity and NHI governance when ownership exists on paper but not in day-to-day operating practice.
For practitioners running identity-heavy programmes, the lesson is to treat recurring touchpoints as control mechanisms. Regular reviews, written actions, and short updates do more than maintain engagement. They preserve accountability across the programme lifecycle.
For practitioners
- Set a fixed monthly cadence Schedule one 30-minute 1:1 with each champion every month, plus one short group update, so the programme has a predictable operating rhythm and no one has to guess whether it is still active.
- Limit each session to one practical topic Choose a single current issue for each lunch and learn, such as secure coding, threat modelling, or tool configuration, and keep it tightly tied to work champions will actually influence.
- Track follow-up actions in writing Send notes after every meeting, highlight action items in bold, and revisit them in the next touchpoint so ownership does not disappear between sessions.
- Use monthly email as a programme signal Send a short monthly update when there is no event, because silence makes the programme feel abandoned and weakens engagement across the group.
Key takeaways
- Security champions programmes usually fail because communication stops, not because champions stop caring.
- A steady cadence of monthly touchpoints, focused learning, and written follow-up is more effective than an early burst of activity.
- Programme visibility is itself a governance control, because once the rhythm disappears, accountability quickly follows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | The article is about sustaining governance and oversight through recurring communication. |
| CIS Controls v8 | CIS-5 , Account Management | The programme depends on clear ownership and consistent participation management. |
| NIST SP 800-53 Rev 5 | AU-6 | Regular notes and follow-up create an audit trail for programme actions and accountability. |
Assign named owners for champion follow-up and track participation so accountability does not drift.
Key terms
- Security Champions Programme: A security champions programme is a model for embedding security advocates inside business or engineering teams. Champions are not replacements for the security team. They help translate guidance, surface issues early, and improve adoption by using trust and context that central security groups often lack.
- Governance cadence: The regular rhythm at which identity controls are reviewed, enforced, and evidence is collected. In practice, it is the tempo that keeps access reviews, offboarding, and exception handling from drifting when workload rises or the team is under stress.
- Programme Drift: Programme drift is the gradual loss of momentum, ownership, and relevance in a control or awareness effort after the initial launch. It usually appears when communication becomes irregular, responsibilities are unclear, and participants stop seeing the programme as part of normal work.
What's in the full article
Semgrep's full article covers the practical operating detail this post intentionally leaves for the source:
- Monthly communication templates for keeping security champions engaged without creating meeting fatigue
- Example lunch and learn topic ideas that map to secure coding, policy review, and tool usage
- A sample monthly email that maintains programme visibility during quiet periods
- Practical note-taking and follow-up habits that keep action items from disappearing between touchpoints
👉 Semgrep's full post includes example communication patterns and monthly email content
Deepen your knowledge
NHI Mgmt Group's NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners building identity controls that need durable operating discipline across their programmes.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org