By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: SemgrepPublished July 31, 2026

TL;DR: Security champions should be attracted, not assigned, because voluntary participation, manager support, and visible outreach determine whether the programme gains real influence or becomes performative, according to Semgrep. The governance lesson is that engagement design matters more than headcount when security teams need distributed advocacy across the business.


At a glance

What this is: This article argues that security champions programmes succeed when organisations actively attract volunteers through outreach, not when they force nominations.

Why it matters: This matters because IAM, security, and governance teams need sustainable participation models that create trust, avoid token compliance, and make shared security ownership workable across the business.

👉 Read Semgrep's article on attracting security champions


Context

Security champions programmes fail when they are treated as an assignment exercise rather than an engagement model. The article’s core point is simple: people perform better when they opt in, and security teams must create visible reasons for them to volunteer. That is a governance problem as much as an internal communications problem, because forced participation weakens accountability and erodes credibility.

The practical challenge for identity and security leaders is less about finding advocates and more about designing the conditions that surface them. In IAM and broader security programmes, that means understanding who responds to training, who asks questions, and who already influences peers. The article’s starting position is typical of effective champion programmes: participation, manager support, and recognition matter more than title allocation.


Key questions

Q: How should security teams recruit security champions without forcing participation?

A: Recruitment works best when teams create repeated opportunities for people to opt in, then watch who consistently shows up, asks questions, and follows through. Use those signals to identify credible advocates. Forced nomination usually produces compliance without commitment, while voluntary participation creates the trust needed for the role to have influence.

Q: Why do manager-approved security champions programmes perform better?

A: Manager approval removes the most common failure mode: the champion being asked to contribute security work without any protected time. When managers understand the role and accept it as part of the job, the champion can participate consistently. That makes the programme more durable and prevents enthusiasm from collapsing under competing priorities.

Q: What do security teams get wrong about champion programmes?

A: They often confuse coverage with effectiveness. A long list of assigned champions can look impressive, but if those people were not willing participants, the programme will not change behaviour. The real measure is whether champions are active, informed, and trusted by their peers.

Q: How do you know if a security champions programme is actually working?

A: Look for repeat attendance, questions from non-security staff, local security issues being escalated earlier, and better follow-through on team-specific guidance. Those are stronger indicators than headcount alone. A working programme changes conversations inside teams, not just attendance records.


Technical breakdown

Why voluntary participation beats forced nomination

A security champions programme depends on intrinsic motivation. When people choose to participate, they are more likely to share security feedback, raise issues early, and act as credible peers inside their teams. When someone is forced into the role, the programme gains a name but loses energy, which turns the role into administrative overhead rather than a multiplier for security engagement. The underlying mechanism is social trust, not formal authority. Champions work because they translate security into local context that central teams often miss.

Practical implication: recruit for willingness and influence, not just coverage.

Outreach as a discovery mechanism

The article treats lunches, training sessions, email signatures, and all-hands messaging as discovery channels. That is less about marketing than signal detection: security teams watch for repeat attendance, active questioning, and consistent engagement. Those behaviours identify people who can sustain the role over time. In governance terms, outreach is the front end of a selection process. It surfaces volunteers with social reach, curiosity, and enough organisational credibility to influence local behaviour without formal enforcement power.

Practical implication: use engagement signals to identify candidates before assigning any role.

Manager sponsorship and operational permission

Even motivated champions fail if their manager does not support the time commitment. The manager’s role is to remove ambiguity about whether champion work is part of the employee’s responsibilities or an extra burden. Without that sponsorship, the champion is pulled between security tasks and their primary role, and the programme loses reliability. This is a workflow and accountability issue, not a morale issue. A champion programme only scales when leaders explicitly recognise the role as part of normal work allocation.

Practical implication: secure manager buy-in before treating champion participation as a formal programme dependency.


NHI Mgmt Group analysis

Security champions are a governance mechanism, not a title programme. The article shows that distributed security influence only works when participation is voluntary and locally credible. That makes the programme closer to stakeholder governance than workforce allocation. For IAM teams, the lesson is that trust and participation signals matter more than directory labels or org chart placement.

Forced participation creates a false sense of coverage. A champion who has been assigned, but not engaged, does not improve security outcomes in practice. The programme may appear broader on paper while delivering less influence in the business. That is a control failure in programme design, because the appearance of coverage is mistaken for actual adoption.

Security outreach is how organisations discover latent influence. The article’s emphasis on events, questions, and repeat attendance points to a practical reality: the best champions are often already behaving like informal connectors. Participation signal discovery: security teams should treat engagement patterns as a selection control, not just a communications metric. Practitioners should build programmes that identify and support those signals rather than trying to manufacture commitment.

Manager sponsorship is the difference between a side project and an operating model. The article correctly highlights that champions need permission, not just enthusiasm. In identity and security governance, that means the line manager becomes part of the delivery chain. Practitioners should formalise this support so the role survives competing priorities and does not collapse under workload pressure.

What this signals

Security champions programmes should be treated as a distribution problem, not a recruitment quota. The teams that succeed create low-friction ways for people to signal interest, then they invest in the ones who already influence peers. That approach also fits broader identity governance thinking: the most durable controls are the ones people can actually adopt.

Participation signal discovery: the next maturity step is to measure engagement quality, not just champion counts. Attendance, questions, and follow-through are more meaningful than organisational charts. For identity and security leaders, the programme becomes more effective when champion selection is based on evidence of involvement, not managerial convenience.


For practitioners

  • Recruit volunteers through observable engagement Track who attends security sessions, asks questions, and returns for follow-up events. Use those signals to build a candidate pool instead of asking managers to nominate people blindly.
  • Make champion work opt-in and visible State the role clearly, explain the time commitment, and invite people to self-select. That approach improves credibility and reduces the risk of disengaged participation.
  • Secure manager approval before launch Confirm that each champion’s manager understands the role, the expected effort, and the business value. Without that agreement, the programme becomes fragile as soon as workloads increase.
  • Use outreach channels to widen the funnel Run lunch and learns, all-staff announcements, targeted emails, and informal events to surface interest across teams. The goal is discovery, not mandatory attendance.
  • Define how champions are supported after selection Give selected champions a cadence for check-ins, enablement, and feedback so the role stays active instead of becoming symbolic.

Key takeaways

  • Security champions programmes fail when they are forced, because credibility depends on voluntary participation.
  • Manager support is not optional, since champions need protected time to contribute consistently.
  • The best way to find champions is to observe engagement signals such as attendance, questions, and follow-through.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01Security champions support organisational security culture and shared ownership.
NIST SP 800-53 Rev 5AT-2Awareness training and outreach underpin the article’s champion recruitment approach.
CIS Controls v8CIS-14 , Security Awareness and Skills TrainingChampion outreach and lunch-and-learns align with ongoing awareness and skills building.
ISO/IEC 27001:2022A.6.3The article’s manager-sponsorship theme aligns with security awareness and role support.

Pair outreach with role-based awareness activities so champions understand their security responsibilities.


Key terms

  • Security Champions Programme: A security champions programme is a model for embedding security advocates inside business or engineering teams. Champions are not replacements for the security team. They help translate guidance, surface issues early, and improve adoption by using trust and context that central security groups often lack.
  • Manager Sponsorship: Manager sponsorship is the explicit support a line manager gives to an employee performing a cross-functional role. In champion programmes, it protects time, reduces role conflict, and turns participation from an extra burden into a recognised part of the workday.
  • Engagement Signal: An engagement signal is an observable behaviour that indicates interest, commitment, or influence. In champion recruitment, signals include repeat attendance, questions, follow-up actions, and voluntary participation. These signals are more reliable than self-declared interest or forced assignment.

What's in the full article

Semgrep's full article covers the practical outreach tactics and programme setup details this post intentionally leaves for the source:

  • Specific outreach ideas such as lunch-and-learns, email signatures, fridge notices, and all-staff messaging.
  • The author’s step-by-step approach for spotting likely champions by watching who keeps attending and asking questions.
  • The next-stage engagement guidance that follows selection and helps keep champions active.
  • The practical manager-alignment advice that reduces role conflict once volunteers are identified.

👉 Semgrep's full post covers the outreach methods and manager alignment guidance in more detail.

Deepen your knowledge

NHI Mgmt Group covers identity security, NHI governance, and agentic AI through independent research, practitioner guides, and the NHI Foundation Level course, the industry's only accredited NHI security programme. It is a fit for practitioners building governance, access, and lifecycle discipline across identity programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org