← All terms

Security Champion

A security champion is an employee inside a business team who acts as its first point of contact for security, reinforcing good behavior and reporting risk back.

A security champion is a member of a business or engineering team — not the security department — who has agreed to be that team's first point of contact for security questions, to reinforce secure behavior among colleagues, and to feed risks and incidents back to the security team. The role originated in software development, where the BSIMM study of real security programs has tracked champion networks since 2008 and counts roughly 6,500 champions across its 111 participating firms. In a human-risk program the same model is applied to every team that social engineering targets: finance, HR, the help desk, executive assistants and anyone with privileged access.

How it works

A champion keeps their day job and takes on a small, recognized time allocation — typically a few hours a month — for security. In practice the role has four parts. They translate generic security guidance into their team's actual workflows ("here is how a fake vendor invoice would look in our inbox"). They reinforce the rules at the moment they matter, such as reminding a colleague of the callback procedure when an urgent payment request lands. They report back the things security cannot see from the outside — the shared spreadsheet of passwords, the process everyone bypasses, the vendor who emails from a free webmail address. And they escalate fast when a colleague clicks something or receives a suspicious call, which shortens the time-to-report that decides most social-engineering incidents. A network of champions is what turns a workforce into a human firewall: the security team broadcasts, but the champion is the trusted peer who is in the room.

How to run a program that lasts

Champions programs fail when they run on unfunded goodwill. The durable ones select people for their standing in the team rather than their technical knowledge, secure a written time budget agreed with each champion's manager, give champions real information (simulation results, sanitized incidents, early notice of policy changes) and a community of their peers, recognize contributions publicly, and plan for turnover from the start. Effectiveness is measured by comparing champion-covered teams with uncovered ones on outcome metrics — phishing simulation report rate and time-to-report, real suspicious-email reports, and the number of process gaps champions surface — and by feeding coverage and trends into a human risk score. Our full guide covers how to build a security champions program, from selection and time budget to measurement.

Full guide
Read the deep dive on this attack →

Related terms

Human FirewallA human firewall is a workforce trained and measured to recognize, resist and report social engineering — the defensive layer technology cannot replace.Security CultureSecurity culture is the shared attitudes, norms and habits that shape how people in an organization actually behave around security when nobody is checking.Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo