Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Security champions communication gaps: how do teams keep momentum?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security champions programs often fail because security teams start strong, then stop communicating, leaving champions disengaged and the program to fade, according to Semgrep. The practical lesson is that lightweight, regular contact matters more than bursts of training, because cadence sustains participation and keeps the program visible.

NHIMG editorial — based on content published by Semgrep: Security champions: Communication is key

Questions worth separating out

Q: How should security teams keep a security champions programme active over time?

A: Use a predictable cadence rather than sporadic bursts of activity.

Q: Why do security champions programmes lose momentum?

A: They usually lose momentum when communication stops after the initial launch.

Q: What do security teams get wrong about champion programmes?

A: They often confuse coverage with effectiveness.

Practitioner guidance

  • Set a fixed monthly cadence Schedule one 30-minute 1:1 with each champion every month, plus one short group update, so the programme has a predictable operating rhythm and no one has to guess whether it is still active.
  • Limit each session to one practical topic Choose a single current issue for each lunch and learn, such as secure coding, threat modelling, or tool configuration, and keep it tightly tied to work champions will actually influence.
  • Track follow-up actions in writing Send notes after every meeting, highlight action items in bold, and revisit them in the next touchpoint so ownership does not disappear between sessions.

What's in the full article

Semgrep's full article covers the practical operating detail this post intentionally leaves for the source:

  • Monthly communication templates for keeping security champions engaged without creating meeting fatigue
  • Example lunch and learn topic ideas that map to secure coding, policy review, and tool usage
  • A sample monthly email that maintains programme visibility during quiet periods
  • Practical note-taking and follow-up habits that keep action items from disappearing between touchpoints

👉 Read Semgrep's guidance on keeping security champions programmes active →

Security champions communication gaps: how do teams keep momentum?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Security champions programmes fail when communication becomes episodic. The article correctly identifies the most common failure mode as loss of momentum, not lack of interest. That is a governance problem, because a programme without recurring touchpoints cannot maintain ownership or visibility. For identity and security leaders, the lesson is that operational cadence is a control, not an administrative detail.

A question worth separating out:

Q: Who is accountable when a security champions programme fades?

A: Accountability sits with the security team that owns the programme. If there is no cadence, no follow-up, and no visible value, the programme will drift regardless of how engaged champions were at the start. Governance only works when someone is responsible for maintaining the loop.

👉 Read our full editorial: Security champions programs fail when communication lapses



   
ReplyQuote
Share: