The Four Tribes of Security Champions

Marisa Fagan

BSidesSF 2025 — Here Be Dragons · Day 2 · Main

Overview

Security Champions programs are not a monolith — there are four distinct program archetypes, and applying the wrong one to a given organizational culture is a primary reason programs fail. Marisa Fagan presents a research-backed framework that maps security culture to program design, arguing that honest self-assessment matters far more than copying best practices from a conference slide. ---

Watch on YouTube

Visual summary for The Four Tribes of Security Champions by Marisa Fagan
Visual summary for The Four Tribes of Security Champions by Marisa Fagan

Key moments

  1. 5:30 Four CISO Tribes paper: security approach shapes program choices
  2. 7:30 Hayden's competing cultures: compliance vs. autonomy vs. trust vs. process
  3. 9:59 Key insight: wrong culture-program match causes champion program failure
  4. 12:59 Sentinel tribe: champions with mandatory security responsibilities defined
  5. 16:00 Four tribe matrix revealed: matching culture type to program design
  6. 19:59 Research finding: 10 years of data on which program types actually succeed
  7. 23:59 Diagnosis exercise: how to identify your company's actual security culture
  8. 26:59 Practical prescription: select champion program archetype by culture type

The Four Tribes of Security Champions

Speaker: Marisa Fagan

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: Watch the full talk

Reading time: ~7 minutes

TL;DR

Security Champions programs are not a monolith — there are four distinct program archetypes, and applying the wrong one to a given organizational culture is a primary reason programs fail. Marisa Fagan presents a research-backed framework that maps security culture to program design, arguing that honest self-assessment matters far more than copying best practices from a conference slide.

Introduction

The phrase "Security Champions" has gone mainstream enough that nearly everyone in the industry has heard it. That familiarity is creating a new problem. As more organizations launch champions programs and find them failing to deliver, the tendency is to question the concept rather than the execution. Marisa Fagan, head of product at Catalyst and a contributor to the OWASP Security Champions Guide, has spent approximately a decade researching why these programs work or don't — and she arrived at BSidesSF 2025 with a framework that reframes the question entirely.

The issue, Fagan argues, is not that Security Champions programs are difficult or fragile by nature. It is that organizations are selecting program designs without first understanding what kind of security culture they actually have. They then apply a model built for a different culture, watch it fail, and conclude the whole approach is flawed. Fagan's talk draws on two prior bodies of research to show that the right program design is not universal — it depends on where you start.

▶ Watch: Why the term "security champions" is losing the thread (04:00)

The Intellectual Foundations: Two Bodies of Prior Work

Fagan grounds her framework in two sources. The first is People-Centric Security, a 2016 book by Dr. Lance Hayden, which introduces a Competing Cultures Framework. Hayden identifies four types of security culture on two axes — process vs. results orientation on one axis, and individual vs. group emphasis on the other — producing quadrants he labels process culture, compliance culture, autonomy culture, and community culture. Each quadrant implies different prescriptions for what kinds of security initiatives will actually work.

A process culture benefits from clear policies as guides. A compliance culture needs those policies to be enforced and audited. An autonomy (or "cowboy") culture resists friction by design — the challenge there is capturing existing momentum and redirecting it toward security without becoming the team that says no to everything. A community culture can be mobilized through shared mission and social recognition.

The second source is a 2017 paper from Cigital called "The Four CISO Tribes," which demonstrated through research that CISOs tend to approach their programs through one of four consistent lenses: security as an enabler, security as a technology solution, security as compliance, or security as a cost center. These approaches visibly skew the practices and priorities of entire security organizations.

▶ Watch: Hayden's Competing Cultures Framework explained (06:00)

Fagan's contribution is synthesizing these two frameworks to produce a four-quadrant model specifically for Security Champions program design.

The Four Tribes

Fagan's quadrant maps onto two axes: one ranging from AppSec/developer focus to company-wide awareness focus, and one ranging from high structure/high expectations to volunteer/minimal requirements. Each quadrant produces a different type of program.

▶ Watch: The four tribes diagram explained (12:01)

Sentinels (AppSec + high structure). These programs assign explicit security responsibilities to developers or engineers. Teams are expected — not just invited — to participate, and engineering managers may be required to nominate someone. This is where threat modeling lives, along with shift-left activities, security practice ownership, and risk management data. AWS is cited as an example operating in this quadrant. The key characteristic is that individuals may still be volunteers, but there is a team-level expectation to participate, which enables coverage heat maps across an organization.

Learners (AppSec + volunteer/minimal structure). Still developer- and engineer-focused, but driven by personal growth rather than organizational mandate. These programs run CTFs, knowledge-sharing sessions, brown bags, and Slack communities. Champions are a point of contact for the security team when needed, but there are no mandatory deliverables. Fagan is emphatic: this is a perfectly valid program model, capable of longevity and meaningful impact. It does not need to evolve into the Sentinels model to be considered a success.

Sentinels (Corporate + high structure). This quadrant covers company-wide security practices — mandatory MFA rollouts, password manager adoption, zero-trust beta testing — run through an organized group of non-developer champions drawn from across the organization. Fagan uses Atlassian's incident response manager training as a concrete example: roughly 30 people across engineering and infrastructure, certified and "kept warm" through a dedicated Slack channel, prepared to serve as incident managers even though it is not their primary role.

Fan Club (Corporate + volunteer/minimal structure). Fagan preemptively defends the name. The fan club is an opt-in awareness program open to anyone in the organization who is curious about security — not just developers. It promotes a shared sense of responsibility, sources content from Security Awareness Month, features guest speakers, and cultivates broad organizational buy-in. RX is cited as a public example. Fagan notes that logos on her diagram were hard to find because few organizations publish about their programs — she encourages practitioners to share more, including through the OWASP Security Champions Guide's call for artifacts.

How to Find Your Tribe

The diagnostic process starts with Hayden's framework. Fagan is direct: get out of the ivory tower, interview people, and find out what kind of culture actually exists — not what you want it to be. "Every company has a culture. It's comprised of the beliefs and the actions of the people, especially when they're not being forced to do something."

▶ Watch: How to diagnose your organization's culture (24:03)

Once the cultural baseline is established, the next step is benchmarking — not against industry best practices in the abstract, but against the specific problems that the security organization's leadership actually needs to solve. Fagan advises asking what is on the security org leader's radar, taking a baseline measurement, and tracking whether the champions program moves those numbers.

Metrics, she acknowledges, are frequently underspecified in champions programs. Practitioners often measure the wrong things, or nothing at all, and the program becomes invisible to stakeholders. She advocates for right-fitting metrics — ones that connect program activity to outcomes that security leadership actually cares about.

Notable Quotes

"A single program will not have more than one area that it lands in. This is the enormous diagram, but each program lands somewhere specific." — ▶ 12:01

"The real framework is the friends you've made along the way... You need an honest look at yourself. You need an honest look at the organization, asking hard questions." — ▶ 26:03

"It works if you work it. There is no magical key to success and no perfect framework. Just keep working at this, evolve over time, start small." — ▶ 28:04

Key Takeaways

  • There are four distinct Security Champions program archetypes, each suited to a different cultural context. Copying a program from a conference without assessing your own culture is a common source of failure.
  • Organizational culture already exists — the diagnostic task is to assess it honestly, not to wish it were different. Hayden's Competing Cultures Framework is a practical starting tool.
  • Volunteer-light programs are fully valid. A Learners or Fan Club program with no mandatory deliverables can have genuine, lasting impact. The goal is right-fit, not maximum ambition.
  • Right-fit your metrics. Connect program activity to outcomes that security leadership is actively tracking. If an impact happens and no one knows about it, it does not count as an impact for organizational purposes.
  • Publish your work. The field lacks publicly documented examples. The OWASP Security Champions Guide accepts anonymized contributions and is actively building a shared evidence base for practitioners.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Fagan synthesizes Hayden's competing cultures framework and the Cigital CISO tribes research into a four-quadrant program design model that is more intellectually rigorous than most champions program talks. The diagnostic-first approach is the right answer to why champions programs fail. Execution at BSidesSF is competent but the content plays better in a workshop format.

Heather Calloway (CISO) — SOLID

Fagan's four-tribe framework solves a real problem — organizations selecting champions program designs without first understanding what kind of security culture they actually have. The diagnostic methodology is the most valuable part. The broader security implications of program failure are largely out of scope.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons