CyberWiseCon Europe 2025

Panel Discussion: Cultivating a Security-First Culture in Tech Organizations

45:55 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

This panel discussion explores the importance of cultivating a Security First culture within tech organizations. The panelists, who come from diverse backgrounds including engineering, marketing, and cybersecurity, share their insights on how security has evolved into a central focus for businesses, especially following high-profile cyberattacks. They agree that merely having security tools is inadequate if the organization does not foster a culture of security awareness among all employees. Key strategies include embedding security champions within development teams and gamifying security training to engage employees effectively. The conversation also highlights the necessity of executive support and budget allocation for implementing robust security measures to mitigate potential risks.

Full transcript

[Music] hello uh welcome uh to the next uh next stage the next stage is a panel uh right now in the um uh in the track um and the name of the panel uh is quite interesting cultivating a Security First culture in Tech organizations so we will try to U talk about that Security First culture uh I I believe we all have uh our opinion and a

lot to a lot to say about that uh before starting the discussions uh so uh I I'm joined today uh by several folks uh I will leave uh introduce yourself uh let's TR let's start with Hon yeah thank you thank you very much Manel um yeah I'm Anton I I've been an engineer for over 10 over 20 years sorry out of which 12 years I've LED different

um engineering organizations um shipping various products from SAS to bitc and so on and so forth actually always with security concerns that's why this topic interests me so much currently I work as an engineering director at canonical the publisher ofun um where I'm responsible for um the team that works on the back end of things like Snap Store and charm Hub where security is also very important

that's me Okay who wants to go then R okay perfect so my name is Ranjit I I live in Germany I started my career off as a Microsoft fullstack developer and at some point got onto the scrum bandwagon and moved into scrum mastering and um agile coaching and U something I've been working with different clients with different levels of security needs so security is something which I

find very interesting because you know helping clients with internet applications with next to no security and then helping very um you know sensitive client information and how do you make sure that everything is you know where where security is such a big investment you know from zero to very high investment on security so I find security a very interesting you know feature of products that you sell

in consulting or you get into a product in the right manner so that's what attracted me to this discussion okay all right so yeah I'm anugra Benjamin and uh I think uh of all the panelists maybe I bring a slightly different approach in the sense that I come from a marketing background and but uh I've I've spent a little over eight years now marketing uh talking about

devops products Dev SE off seop's products to be exact right I mean I started with infrastructure monitoring products and then eventually to configuration management and security and compliance automation with Chef that we do do today and what I've realized in all of my uh conversations like I mean a little bit uh you know touching upon what Ranjit just said about you know as complexity increase uh with

with increasingly complex environments I mean what I've also noticed and what everybody really overlooks is is the severity of of a lack of a security policy right the the repercussions are are huge right the the financial the reputational implications are huge so I try to you know talk to engineering and figure out what the technical development progress looks like and speak to customers what the their pain

points are speak to analysts and see where the market is growing and then then try to you know condense all of those thoughts into some meaningful sense that helps everybody so yeah that that that that's what I do okay okay thank you uh to all of you I just realized that I did not introduce myself at the very beginning uh so I'm Manuel uh I so ranit

when you when you were talking about the beginning of your career I I don't I believe I don't remember uh the beginning of my career hopefully uh I've been uh so more seriously I've been working for Dev and Ops and Dev Ops and then Dev secops uh vendors uh some of them you will know Serena software cast software microfocus Cloud bees more recently I've been also working

for uh GSI for wepro uh as um as I would say a what what is usually referred to as a uh recently so uh the security is something just like probably AI today uh is is coming into the the fact and coming into the discussions uh security some time ago was not a main topic and did become a um is there according to you because I also

have an opinion on that but is there uh has there been a trigger or or something that made security that today if I may uh start on this one I think uh I think that's a very interesting uh Topic in the sense like whether that was there was a trigger or there was a gradual process I think there's been multiple triggers if we want to talk about

triggers uh like know massive uh um kind of big security big cyber attacks uh big uh Cyber attack successes and uh all of this U becoming a very interesting story uh reaching media and so on and so forth and becoming well known to the public and then suddenly becoming a mif for you know for financial uh indicators and so on and so forth so I think this

maybe one of the one of the ways that influenced things uh but I would say maybe another comp another big component is how uh dependent everyone now is on someone else's software on open source software where uh where basically one vulnerability one vulnerability of underlying Library can expose lots and lots of systems uh at once and uh it's it's hard to um it's hard to protect yourself

from this uh apart from you know like not using open source which is hardly possible today so yeah so then suddenly everyone needs to be aware of like uh vulnerabilities and well-known libraries well-known pieces of code um that are also you know because they are well known they're well known to the to the Cyber attackers uh who will use these V vulnerabilities if they remain open so

yeah I think that that's another big component to that you know if I might just add on to what um you mentioned about the vulnerabilities it's interesting because you know as a developer I still do some development and um the tooling around vulnerabilities is also improved previously you had to go around finding your vulnerabilities now GitHub has its own service reporting vulnerabilities Visual Studio One of the

IDS for Microsoft development you just click on a tab just gives you all the vulnerable libraries so I think the sensibility sensitivity around vulnerabilities itself has just gone up but at the same time like you mentioned right you're not you can't even do business without so deployment has become much more uh complicated with so many dependencies and so many V vulnerabilities the planning for deployment timelines itself

changing so yeah yeah absolutely the the the thing I just wanted to add because uh I I think we all agree on what what you said both of you um probably I I saw something uh with the um the digital transformation the uh the the path to the cloud uh um companies were were operating their own Data Center and they were responsible for the security but they

were owning the security um uh Ju Just In in their own PR privately I would say uh and it's related to the the the the public stuff you were you were talking about Anon now it goes to the news when there are some vulnerabilities uh and but now with the cloud it's more exposed it's more public and then there is uh more attention to the security as

a piece of the software delivery supply chain okay and here we are okay hello Shamir hello hello how are you doing guys we are we are good we are good thanks uh we were sorry I'm late yeah sorry I'm late I was waiting in the lobby I was hearing the amazing discussions going on okay here I just thought you know um I would input my two cents

as well so just a quick introduction uh from you yeah uh sure my name is sham ra and uh I I am a a passionate cyber security researcher um that's basically that's not my day job my day job is that I serve as a CEO of uh uh one company and two startups and uh I have uh written a few books on cyber security as well okay

okay thank you thank you very much so uh we were the uh the first round of discussion was about uh um some kind of of definition and and why security was uh so looked after and looked at topic today while it was not necessarily some some time ago so uh I by the way I like the the title of of our panel um cultivating a Security because

I believe uh let me know if you agree but I believe the that the technical aspect how to technically handle security it's important uh it's uh sometimes tricky but we have roughly uh the ideas the solutions the uh the vendors the open source that that do the stuff I think that the important thing is the culture because you can have I mean it's completely obvious I believe

but you can have the best tools and the best processes in the world if you don't have the the security in our case instilled in the the culture it's quite difficult to uh to move forward so do you have uh so what what contributions do you have on that we have some examples organizations where the culture is there but maybe some other organizations where it's more difficult

to make the culture enter in the daytoday Life yes uh go on it always uh security um it always comes down to the culture you know we uh we are we've been hearing this for a very long time uh that there is no patch to the human stupidity you can have a $100,000 firewall in place but if the person operating that firewall or the person that is

behind uh the computer keyboard if that person clicks the link opens a file that they're they're not supposed to then that then the then the whole concept of that equipment is lost examples uh the the the biggest oil pipeline hack uh that I you know mention in my presentations the colonial pipeline that was because of a a a password leak of a legacy VPN software then we

have the Uber uh hack that happened that was because uh the the attacker was continuously pinging the system system administrator uh to accept the MFA login request and once they did Uber got hacked we have countless examples um of of things like these happening so and and it's not uh it's not hard per se okay it's not it's it's it's a process if you um train your

people if you gamify the security process a security awareness process um and if the employee is is is a loyal person and they want the organization to succeed uh the the the only bridging Gap is the learning part right and the education is very easy to impart so uh my input in that would be you know from what I said earlier is that uh security as a

culture is a process it is you can't shove it down people's throats you have to let them digest it uh gradually and organically and once you do that um it's it's just a matter of time before people uh you know learn it if I may add um yeah actually it's it's interesting how uh how the topic of our discussion mens uh Security First culture and how it

kind of hints on this you know the shift left principle so think about security early in the process and not later and so on whereas I find that much much more uh valuable to actually have security awareness that sort of makes it organic like natural for the security question to come up earlier in the process so if there's security awareness and security awareness of the particular bits

uh of security that are important at the at the particular company then it kind of things start almost working on their own of course there needs to be uh need to be processes defined there needs potentially uh to be um some security training uh or like a lot of different types of security training done but the first and foremost uh the thing that I do first and

foremost would be um kind of learning about the uh threats learning about what what sort of you know what sort of attacks are we trying to protect ourselves from and so on and so forth and that happens perhaps not even on a full Team level that that can happen like with a small group of Security Experts uh and then with this knowledge then we can go to

the teams and say okay look what we know um how about we uh we Now understand what to do to kind of continuously protect ourselves from that yeah and that's where the shiftlet happens go please yeah if I can just quickly you know I mean I I can relate to uh you know everything that was just said quite closely because I see this happening every day within

my own Aug right so one of the thing is you know and and we call it and and I'm not sure if it's quite popular but we call it democratizing devops right or democratizing Dev secops right where every stakeholder is aware of what's Happening you know so they don't have to you know seek individual experts to you know for that knowledge transfer to happen if things are

transparent every stakeholder is informed aware and decisions are taken you know based on that fundamental you know source of truth right and and having said that even when you look at individual teams right and this is something that we practice you know what we preach even within our own augs in the sense that we identify and nurture internal Champions right these security Champions or compliance Champions right

so we Nur these internal Champions who then you know seek other teams and you know you know this information is then trickled down over in meaningful parts to all you know members who might be involved in these projects in the future so it is you know a subconscious way of embedding you know this sort of culture where we make it known that security you know compliance these

are not responsibilities of isolated teams right security is a shared responsibility everybody is an equal participant everybody is an equal stakeholder and not to belab the point but if I can quickly share an anecdote right so when gdpr uh came to be right so I remember it was a huge turmoil within my own product team because I was tasked with you know the the the application of

you know making sure that we comply on all fronts with these regulations right and that is how do we collect data where do we process this data how do we save this data all of that details right and that is when you know it was a startling Revelation that the amount of accountability we assigned to security is perhaps incomparable to any other role right or any other

aspect of software development I would say right a security flaw right the the repercussions of a security a major security flaw is not the same as the repercussions of a broken feature right so so even internally the accountability is massive right and that sort of accountability that sort of responsibility is is what man in the form of these tidbits of information that we consume in in a

holistic Security based environment right hey I like that point you made about that internal Champions and uh you know to just give a metaphor right a lot of companies have for every floor they have someone who's gone to the First Aid course right and they are the go-to person if there is a first aid problem learning CPR right yeah we have a security person for every floor

and you go to that person for security because you know for a lot of my clients I noticed this once a year there's a security awareness training and everybody pushes it away till the end and then they say I'm going to stop your access if you don't do that training and then everybody runs to do that training but that's it never again are they thinking about security

but if we have these kind of internal Champions who are like on every flooor maybe it becomes more relevant I mean yeah and I mean I I strongly agree uh with that uh I would say uh the the decouple of we're talking about Shi left so shift left means doing more uh things more more test more stand uh on on the left hand side at the beginning

of the development but in the meantime what is done by the development teams in that shi left uh spirit should be defined by the the security champions security and uh I mean it can apply to any kind of of test or or scans or I verifications that we want to do on the uh on on the left hand side um and this is something I mean in

my experience the the last projects I I was part of we've been working like this promoting uh left uh but in the meantime make sure that the uh the defin one of the risk of Shifting left is that Developers are loaded by more activities okay I have I also have to care about security I also have to care and in that case security is is a pain

uh and in that case if it's a pain it's more difficult to put it in the culture because it's a pain on the another hand if we tell the the development teams okay will shift left but all the uh facilities all the uh um tools that you need all the processes the pipelines whatever you need uh to ensure security at your level we will provide you you

don't have to care because security Champions security people will Define the the level of security you need they will Define the way uh the corporate way to achieve that security level and we provide you with everything that you need uh to uh to achieve that if you want to contribute you're very welcome because you have to we have to involve you if you want to participate of

course we we always accept incoming skills but if not you can just consume what I have what I provide and in that case from my point of VI this is something that uh does work because it's oriented on uh I mean our topic today culture how to instill in the culture that uh that security stuff we've been talking about uh Champions uh are there some uh specific

roles in uh because we want people I mean listening to that panel bringing home some uh best practices some ideas keywords uh and some of the key wordss I believe in security are what are the typical roles of uh of the people I think um one important thing that one thing that I I uh always uh found important um in sort of engineering organization design so to

say uh was not to confine the security champions in one team sitting somewhere uh that will solve everyone's problems because very quickly this team becomes overwhelmed we can we can say okay no this team now needs to review every design this team now needs to do this needs to do that then this team becomes like I don't know 100 people in size for 300 uh people uh

large tech department and still cannot cope and so on so forth I'm exaggerating but still so what what was helpful um to kind of mitigate all that was actually placing the security Champions on the development team level so in each and every development team there would be a person or two kind of care about security it's not their day-to-day job it's not their 100 100% of their

day-to-day agenda but they are the ones who are in close touch with the dedicated security team who defines just as you uh mentioned Manuel who defines the policies defines how much we care about this or that but who facilitates uh the implementation of all these uh requirements this is these security Champions and then you can expect every design document to be reviewed by someone who cared about

security you can expect uh someone to actually da daily look at how people handle different security relevant things and say oh whoa whoa whoa whoa whoa let's please not share passwords openly on a on a public chat on slack or something like this so these sort of things I mean just to add add on that right I mean it's interesting you know adding those security Champions one

thing I've noticed in you know there's one company policy which I found interesting is anywhere in the the company if software goes to production one of the steps is that um security gate you need to pass and the security gate is normally you know defined by the security team but I'm wondering how would you bring in the the the local security Champion which means the local the

security Champion would be someone who has been trained by the security team to be able to approve that particular security gate before something goes on production right pretty much yes I have to ask you guys can you hear me we can hear you but your video is a um because of my my uh okay the uh the feedback of my video is is completely black so I

have a black screen and I cannot see myself but if he can hear me good okay your video is Frozen for some reason okay uh well my cam was frozen too but anyways let's keep going anyway okay um so yeah um there is there is something that I believe you said ranid is uh the the security awareness okay and uh I like the notion also of security

awareness uh attending that that it should not be as you described uh for the trainings uh everybody's waiting for deadline and he's doing the training very um very quickly uh what are your experiences uh in terms of that kind of training uh security a awareness uh is it useful how useful so I mean to give you the example on that training right so this is a client

of mine who's a strategy consulting company and they're very careful they're very high on security but their trainings are actually difficult to pass because they they put you through multiple I think they possibly got their ideas from strategically Consulting business cases or something they run you through a situation where you're sitting with clients it's a project that is very long and then you go off for an

evening to E with them are you then supposed to say something is that right or wrong and then they put you through multiple cases and I think some of them are not just technical security it's also social engineering and uh when very often we normally rarely talk about it and I thought these kind of uh security awareness training was very interesting to understand and also do it

even though we're doing it just once a year um I'm not sure if you can do it more than once a year because how many people really take the time to sit down and pass a test I think unless I don't know the a better way to do it maybe you can gamify it um yeah know gamifying could be uh probably uh a good uh a good

idea I I don't know I just had a question but but any experience guys for in in from the other guys from gamifying uh such uh such awareness so that yeah yeah I think um I would have something to say about that and we practice it in in our own uh you know offices and companies not just you know the security awareness not just clients so the

biggest motivation for uh people uh is either uh in a company is either a day off paid time off or and or money so that's the biggest motivation for people to learn anything and you can channelize that into gamifying that process uh for example um what we do here is we are we we randomly throw out fishing emails from um from different writers and we reward people

with an hour or two hours off based on you know what what the result of that exercise is similarly you know the they have they what they earn is something called points and you know on specific points you can either redeem uh you know one of your leaves into an C scenario or you can U or you can use it uh at the at the end of

the quarter we announce the best uh the top most engaging employees and we send them on a trip or with their families this is the best way to instill security you cannot give them a YouTube video and expect them to digest and learn it out it has to be a motivational Factor people look at it as as an expenditure but you know um you shouldn't you should

look at it as what if this person clicks on a bogus or a malicious link what is the amount of money that I'm going to lose against uh the the the $200 or $400 dinner that I'm going to provide them against them not clicking it so that's a way to gy it actually I love this uh this system that that uh you described um so it's it's

it's really uh it's really something that I think can move people to pay attention and uh most importantly uh practice the skills and in a safe environment of the fishing emails generated by you so it's it's a bogus thing some some people will click it uh but yeah uh with with no effect and then they'll learn and and uh they'll be motivated to you know look at

it it's it's great I wanted to add on um to uh the lens we're looking at security problems uh through uh that uh I think it's very important to real to to to kind of recognize that security topics for very very few companies security topics are actually something that brings profit uh for most of the something that mitigates risks and mitigating risks is always um is always

something where we temp to say okay so like this is our estimation of the likelihood this risk kicks in yeah the losses may be catastrophic but you know the risk is really low right so we can continue ignoring it for uh a while more um so yeah so there there needs to be a really uh good uh system to model the cumulative uh effect of all the

security risks we are putting ourselves as a company under uh and then if if if the CEO says oh okay no no no no no the probabilities that you're suggesting are too high then you kind of reduce them a notch and say okay so we we're at a potential risk of losing not two billion dollars but just one billion dollar that makes it a lot better of

course so just to to to show the magnitude but I'm I'm very curious how how marketing people look at it what would you say underr yeah so I was just about to come in but glad that you brought me in on it is that when all of these conversations with the c s Executives right so one of the fundamental uh tenets that I believe in establishing a

Security First culture is that it should more often than not come from the executive right there should be executive Buy in that supports the implementation of you know strong security procedures and policies and things like that right I mean we might have a 100 uh security champions our you know individual application development teams right but unless you know there is executive buyin that sees the vision that

understands you know the repercussions of non-compliance and then supports the building of that holistic technology and and of course to establish a comprehensive security or compliance framework it does cost money but then again like shami alluded to earlier right you know where are the right incentives right you incentivize people to do the right thing in terms of but it's also about the tradeoff that you are going

to make do I invest you know 200,000 to support you know a fleet of say 5,000 nodes by implementing some tools that can automate stuff for me right or let's say do I have to spend on training people in these fronts right is that 200,000 against a 2 million you know non-compliance fine or a penalty you know the tradeoffs are just I mean it's a no-brainer that

the tradeoffs are massive right so to have executive buying is perhaps you know I I see today that in my own experience when I talk to customers the fast growing the high-tech organizations they are never reluctant to to implement or try a new tool or a new technology right no wonder they are at the for Forefront of any technological Revolution or you know pioneering some change because

they are not reluctant to try these things right it is usually you know organizations that you know that I mean I I wouldn't use it in the sense that they aren't you know as Innovative in that sense but you know innovating at certain Pace requires you know breaking certain things trying new things and adopting new things to support these evaluating I mean I mean evolving uh scenarios

right so yeah that that is my opinion on these things that that again it should come from the top as opposed to going from the bottom and convincing the management to see the value in it hey hey one one thing I've noticed with the entire you know the security discussions right if it was a finance client or if it was a medical client somehow security is not

even discussed it just becomes part of the sold you know it's budgeted in but if it is anything other than that where there is no person who can get uh medically affected or no person whose bank account can be withdrawn completely everything else even if you can lose a lot of money security is not very often sold as a part of the budget and then it's just

some somebody hiding that security audit into another budget so how does this become you know how do you how do you sell this or how do you budget it in from the beginning with the proper uh selling point you know there has to be I'd be interested to know how how you guys see it um I mean if I can just add a comment uh you know

as a response there is that I mean this uh this panel discussion that we are having is a great Testament to the fact of you know how how important security has become today how mainstream it has become today right so in some ways you know that decision making or is is not that uphill a climb as it used to be right I mean I would argue that

maybe it is still you know security is perhaps still an afterthought you know maybe in some growing organizations but but I but I think in my observation I've seen the large organization at least I think perhaps because there is more to lose the risk factor is enormous when you operate at a very massive scale that the the the management is usually supportive of these Endeavors right I

mean again in macroeconomic sense of things you know profits outweigh everything right so when you do the plus and minus of everything I think you know sound you know leaders actually see that you know the value is in investing in Security today to avoid that you know million dollar perhaps billion dollar damage let alone the reputational damage that comes along with it yeah I I feel that

uh with the size of the company uh the company becomes like with a grow growth of the size of the company the company becomes more and more likely the subject a subject of a Cyber attack right so people want to Target bigger targets because there's there's more to try out and so on and so forth um plus uh this is about the kind of the security the

company specific security awareness to know to your threats to model them to understand what is it that we are kind of trying to protect ourselves with there's a certain amount of time that needs to be spent and it doesn't it doesn't uh kind of scale scale linearly uh with the growth of the company SC it scales a little bit slower than that in my opinion so a

small company would need to spend a significant amount of uh their engineering capacity to model that a bigger company would say ah yeah okay it's like a 0 one% of our engineering capacity for this quarter let's spend it and then learn and once they learn this is the moment of Revelation and they're like oh how how much have you said we can lose there all right maybe

we should budget something for this the the smaller companies usually say like oh no no no like if we start spending time on security we we will you know um close down and become bankrupt uh probably uh we we need to we need to build features and this this tradeoff uh kind of becomes uh more beneficial for the kind of security topics with a little bit more

size in my opinion yeah hey because we have an obuntu person here can I ask a nerdy question sure go ahead so the nerdy question would be you know especially because a lot of projects are container based and on the cloud and assuming let's say I take an Ubuntu container how how does Ubuntu go about you know helping clients with this kind of um you know Security

First thinking you know do you provide you know vulnerability tracking out of the box so that people who are using Ubuntu containers just have a easy way to keep their containers and solutions which are on the cloud secure um typically thank you for this question typically um so clouds meaning public clouds would have uh vulnerability tracking already built in and they would like you know uh notify

you about this however in auntu uh um so first of all uh there's security support of all the components uh that are being shipped with a B right it's for six years for typical long-term support releases and if uh one opts for pro uh which costs a little bit of money but still that that gives you just security update security patches uh for the entire Ubuntu uh

Universe of all the packages for 12 years so that's that's already helpful and the pro tool that's kind of uh that is built in can kind of show uh how many vulnerabilities you would be able to uh you know to uh just get protection from if you opted for pro and not for an upgrade to another LTS which is sometimes with a fleet of many machines a

big undertaking um apart from that uh yeah I I think there there there isn't much uh that that's that's required because basically you you already have this protection as as as long as you you keep updating your reun to container uh one way or another um yeah but then there's there's a ton of tools uh that I think are outside universe but like very you know very

well welln vulnerability scanners container based security is not just specific to Ubuntu right I think all flavors of yeah reux also offer them and okay okay that was a good moment for me to you know you know do a subtle plug of the products that I promote and Market but then again I let Manuel take over yeah also because we have uh less than than one minute

to go so uh I wanted to thank you very much uh guys thank you uh Anon for that uh uh curve into uh into buntu uh thank you very much San thank you an thank you Shamir uh very interesting talk uh on the on the security today uh I just add we have uh 20 20 seconds I strongly believe there is a lot of things that we

could have been talking about I strongly believe that security is also very related to software bill of material that is also uh a topic that is coming back I don't know maybe there are some tracks on that uh but it was something that that I believe is very important thank you very much guys uh and uh have a good uh rest of the the conference uh a

lot of tracks a lot of good stuff uh don't don't hesitate to be curious thank you very much everyone thanks everyone a fun discussion