Build a Security Champions Network (2026 Guide)

Build a security champions network in 2026: 90-day steps, Ideal Actions, manager cover, and metrics that prove the programme works.

A security champions network turns a thin central security team into a distributed coaching layer — people already trusted on their squads who can translate policy into the work. Building one well is a 90-day design problem, not a poster campaign.

TL;DR

Why this matters

Most organisations will never hire enough security engineers to sit in every product squad, contact centre, or branch. Champions are the practical alternative: non-security volunteers who get extra training and a formal link both ways — security into the team, and the team’s friction back to security.

Done well, the model scales awareness, shortens the path from policy to behaviour, and surfaces risks earlier. Done poorly, it creates unpaid auditors with no manager cover who quit after the first phishing fail they are asked to police. Industry practice — including the open Security Champion Success Guide — stresses vision, participants, and design before delivery. That order is the difference between a network and a name list.

Champions do not replace security awareness training or phishing simulations. They amplify them: they answer "why did we get this module?" in stand-up language and flag when a simulation felt unfair or a process is broken.

Who this is for

This guide is for security leaders, GRC owners, and people partners who want a champions network across engineering, operations, finance, or customer teams. If you have more than ~80 staff and a security team smaller than the number of product or business units, the steps below apply.

What you will need

The steps

1. Write the vision before you recruit anyone

Answer in plain language: what does success look like in 12 months? Examples: fewer repeat phishing fails in two high-risk teams; security questions answered inside the squad before tickets hit the SOC; a named champion in every product train. Publish the vision where managers can see it.

Expected outcome: a one-page vision signed by the sponsor.

Common mistake: launching a Slack channel called #security-champions with no goal.

2. Define participants and Ideal Actions

Decide which teams need a champion first (usually highest data sensitivity or highest phishing fail rate). List Ideal Actions — concrete behaviours such as "runs a five-minute threat share once a month," "escalates suspected BEC within the hour," "reviews access requests for their squad," "coaches one teammate after a failed simulation." Keep the list short.

Expected outcome: a participant map and three to seven Ideal Actions.

Common mistake: copying another company’s champion job description wholesale.

3. Secure manager cover and time

Champions need protected hours — often two to four per month at the start. Get written agreement from their managers before nomination. Without cover, champions become night-and-weekend volunteers and attrition follows.

Expected outcome: manager sign-off template and a named time budget.

Common mistake: recruiting enthusiastic juniors whose managers never agreed.

4. Recruit volunteers, do not appoint police

Open a call with the vision, Ideal Actions, time ask, and what champions get (training, access to security leadership, recognition, career signal). Prefer volunteers with peer respect over people security already likes. Allow teams to nominate.

Expected outcome: a pilot cohort of 8–20 champions, not a full-company mandate on day one.

Common mistake: forcing the person who failed the last phish to "be the champion."

5. Train for the role, not only for generic awareness

Give champions a short onboarding path: how to escalate, how to read simulation metrics, how to run a five-minute share, and where policy actually lives. Layer deeper modules by domain (secure coding for eng champions, payment verification for finance champions). Keep sessions under an hour and story-led.

Expected outcome: 100% of the pilot completes champion onboarding in two weeks.

Common mistake: dumping the entire security wiki and calling it enablement.

6. Design motivation and a monthly cadence

Mix recognition (public wins, certificate paths, skip-level time with the CISO), usefulness (early access to tool changes, input on policy drafts), and community (monthly 30-minute forum). Publish a simple scoreboard: Ideal Actions completed, simulation report-rate trend in their area, open questions closed.

Expected outcome: a recurring calendar invite and a living scoreboard.

Common mistake: swag-only motivation with no operating rhythm.

7. Deliver, measure, and tune every quarter

Kick off with the sponsor present. After 30 and 90 days, survey champions and their managers: time used, friction, what to drop. Adjust Ideal Actions. Expand to the next wave only when the pilot’s managers would recommend joining.

Expected outcome: a 90-day tune-up note and a go/no-go for wave two.

Common mistake: scaling to every team before the pilot has a working cadence.

Troubleshooting

Champions go silent after month two. Re-check time cover and Ideal Action load. Cut the list before you add incentives.

Managers treat champions as free audit labour. Restate the vision: coaching and two-way signal, not local compliance police. Escalate to the sponsor if needed.

Security team bypasses champions and still dumps all-staff mail. Route at least one initiative per quarter through champions first so the channel stays valuable.

Engineering wants deep AppSec; contact centre wants social engineering. That is correct — split domain tracks under one network brand rather than one generic curriculum.

No baseline metrics. Start with simulation report rate and training completion by team; add Ideal Action counts in month two. Do not wait for a perfect data warehouse.

Tools and resources

What to do next

Once the pilot holds a cadence, connect champions to adjacent playbooks — for example reducing BEC risk with staff training for finance champions, or privacy escalation for customer teams. The network should feed real process fixes, not only cheerleading.

FAQ

What is a security champions network?

A structured group of non-security volunteers who receive extra training and act as two-way liaisons between the security team and their own squads, spreading better habits without hiring a security engineer for every team.

How do you build a security champions network in 90 days?

Write a vision, define Ideal Actions, secure manager time, recruit volunteers, train for the role, run a monthly cadence, and tune with a 30- and 90-day review before scaling.

Should champions be volunteers or appointed?

Volunteers with peer respect outperform appointees. Appointment without manager cover is the fastest path to burnout and quiet quitting from the role.

How much time should a champion spend?

Plan two to four hours per month at pilot stage, written into the manager agreement. Heavier AppSec champion roles may need more — say so up front.

What metrics prove the network is working?

Ideal Actions completed, simulation report-rate trend by champion area, time-to-answer for security questions, and manager willingness to support wave-two recruits.

Do champions replace company-wide awareness training?

No. They reinforce and localise it. You still need a baseline curriculum and phishing programme for everyone.

How big should the first cohort be?

Eight to twenty champions is enough to learn. Full-company rollout before a working cadence usually dilutes support and kills the brand.

One last thing

A champions network is a behaviour-design programme wearing a community badge. If you cannot name the Ideal Actions and the time budget, you do not have a network yet — you have a mailing list. Fix those two, then buy the stickers.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.