In this episode of Cyber Security Inside What That Means, Camille talks with Roman Zhukov, Product Security Manager at Intel about Security Champions and their roles in product development.

The conversation covers:

  • What a Security Champion is, and what they do in a product team.

  • How the role of a Security Champion has changed over time with new security needs.

  • How to encourage Security Champion and cybersecurity training effectively by using the carrot over the stick.

  • Who is responsible for what parts of security in product development.

... and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The definition of what a “security champion” is evolves over time. The purpose is to put security first and incorporate it into every part of a company. They educate, they adopt policy, they communicate, and they help enable positive security change.

  • A security champion can be a liaison between a product division and a security group.

  • Their job is to ensure their team is ready to meet security needs.

  • You can be trained to become a security champion, even if it isn’t your formal role. They can spread knowledge to teammates.

  • This is so important because users often will trust big companies or services to provide security - so much so that they won’t do anything in securing themselves. So, we need someone on the product team reminding people of that and making sure security is a first priority.

  • Companies that have been doing this a while and have made good strides in security have KPIs for both the business parts and the security parts.

  • Originally, security champions were the bridge between the two departments (security and another like development or IT). The two sides used to battle one another, and a security champion helped them through that. Now, though, they serve more as a person who is encouraging employees to learn and to stay committed to security policy. They don’t know as much as someone in the security team, but they can answer questions and relay info.

  • In terms of thinking about the carrot vs. the stick tactic of getting people to think about security and be compliant with requirements, historically security has always used the stick. But what they’ve found is that the stick (do it because you must) only gets minimal compliance, which isn’t enough in today’s world. The carrot comes into play with making training fun and desirable to do. Make it a competition, and change your approach to training your personnel in security.

  • Having security champions is worth finding resources for. They guide the product team, and help the team to start thinking like a hacker. Try to break the product, and then develop something to prevent that from happening.

  • We need more daily security tasks (about 90%) to be completed by the native team with help from a security champion, instead of going to the central security team.

Some interesting quotes from today’s episode:

“Often the case is that the term security champion is perceived as the specific job, or just even yet another buzzword. But there is not actually one specific definition, it evolves over time.” - Roman Zhukov

“Influencers from these divisions who have to really understand that security is not a feature, but a part of daily life.” - Roman Zhukov

“I think this is the era when security first mindsets start to play.” - Roman Zhukov

“The thing is, security is no longer a product feature or a company’s feature. It’s part of normal functionality of our organization.” - Roman Zhukov

“I know that the integration of product development life cycles and security development life cycles has been a trend, right? So I think things like that probably help. We kind of back it up so that you’re not doing a security review at the very end, pre-ship, and discovering a whole bunch of problems you have to address; you’re finding them along the way.” - Camille Morhardt

“Just to realign policy and establish requirements or running your scanning tool is not enough. Why? Because implementing [those] alone, they cannot help to grow security mindsets and to make these cultural shifts.” - Roman Zhukov

“Cybersecurity is widely unfair, right? A hacker needs to succeed only once to get what they want, while a business needs to succeed every day to prevent that from happening.” - Roman Zhukov