Enabling Security Champions With Breakout Action Groups (BAGs) – A Longitudinal Case Study
2026Konferenz / Journal
Research Hub
Hub 5: Human-Centered Security and Privacy
Abstract
Many organizations, particularly smaller ones with limited development resources and few security experts, face major difficulties in developing secure software. Security Champion programs are a scalable strategy for strengthening security practices throughout the software development process. However, previous work has shown that establishing and maintaining such programs often entails currently unsolved challenges, including varying levels of engagement and expertise among champions, conflicts with other organizational responsibilities, and a lack of guidance on addressing these issues. In partnership with an organization employing over 5,000 employees, including approximately 200 software developers, we documented its efforts to address the challenges faced by its Security Champions through multiple initiatives and formats. We attended and analyzed the organization's Security Champion program for 64 weeks. Within this study, we investigated transitioning from bi-weekly Security Champion meetings to a project-focused group format, which we called breakout action groups (BAGs), with monthly meetings. Additionally, we documented secure coding workshops, evaluated progress through retrospectives, and observed the development of a vision statement for the program. Our results show that the BAGs enhanced Security Champions' engagement and motivation. In addition, the vision workshop and the retrospective fostered stronger group cohesion, aligned champions toward a shared mission, and increased the program's visibility within the organization. We further discuss the potential and limitations of BAGs as well as the initiatives for Security Champion programs.