Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Security champions programs: how do you attract the right people?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Security champions should be attracted, not assigned, because voluntary participation, manager support, and visible outreach determine whether the programme gains real influence or becomes performative, according to Semgrep. The governance lesson is that engagement design matters more than headcount when security teams need distributed advocacy across the business.

NHIMG editorial — based on content published by Semgrep: Building Security Champions

Questions worth separating out

Q: How should security teams recruit security champions without forcing participation?

A: Recruitment works best when teams create repeated opportunities for people to opt in, then watch who consistently shows up, asks questions, and follows through.

Q: Why do manager-approved security champions programmes perform better?

A: Manager approval removes the most common failure mode: the champion being asked to contribute security work without any protected time.

Q: What do security teams get wrong about champion programmes?

A: They often confuse coverage with effectiveness.

Practitioner guidance

  • Recruit volunteers through observable engagement Track who attends security sessions, asks questions, and returns for follow-up events.
  • Make champion work opt-in and visible State the role clearly, explain the time commitment, and invite people to self-select.
  • Secure manager approval before launch Confirm that each champion’s manager understands the role, the expected effort, and the business value.

What's in the full article

Semgrep's full article covers the practical outreach tactics and programme setup details this post intentionally leaves for the source:

  • Specific outreach ideas such as lunch-and-learns, email signatures, fridge notices, and all-staff messaging.
  • The author’s step-by-step approach for spotting likely champions by watching who keeps attending and asking questions.
  • The next-stage engagement guidance that follows selection and helps keep champions active.
  • The practical manager-alignment advice that reduces role conflict once volunteers are identified.

👉 Read Semgrep's article on attracting security champions →

Security champions programs: how do you attract the right people?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Security champions are a governance mechanism, not a title programme. The article shows that distributed security influence only works when participation is voluntary and locally credible. That makes the programme closer to stakeholder governance than workforce allocation. For IAM teams, the lesson is that trust and participation signals matter more than directory labels or org chart placement.

A question worth separating out:

Q: How do you know if a security champions programme is actually working?

A: Look for repeat attendance, questions from non-security staff, local security issues being escalated earlier, and better follow-through on team-specific guidance. Those are stronger indicators than headcount alone. A working programme changes conversations inside teams, not just attendance records.

👉 Read our full editorial: Security champions programs work only when participation is voluntary



   
ReplyQuote
Share: