Uploaded December 2025 | Updated September 2026, 2 weeks ago
Security Champions programs are a proven way to scale security knowledge and embed secure practices across organizations. But why do so many organizations struggle to successfully implement a security champions program? What makes some programs truly effective, while others are barely surviving?
In this talk, we will introduce the Security Champions Maturity Model, a new framework developed to help organizations assess and evolve their security champions initiatives using the ten pillars of the Security Champions Manifesto.
We’ll walk through the model’s structure, share real-world lessons learned from its application in various organizations, and demonstrate how it provides tailored, actionable guidance (including artifacts) to help organizations grow from ad hoc efforts to deeply embedded, resilient programs.
Whether an organization is just starting out (and wants to take things to the next level) or looking to revitalise a stale initiative, this session will equip the audience with a practical tool and insights to take their Security Champions program to the next level.
Cheyenne Seur
iDEAL
CISO
As the Chief Information Security Officer (CISO) at iDEAL and the founder of the OWASP Security Champions Guide, I blend technical expertise and leadership. My mission is to make technology and security not just understandable, but exciting for everyone—from developers to executive business leaders.
With an extensive background in Security Engineering and Security Risk Assessment I know how to translate complex security concepts into clear, actionable insights for non-technical stakeholders. I thrive on collaborating with engineers and exploring new (security) technologies.
I spearheaded the creation of a vibrant Security Champions Community, uniting over 150 engineers with a shared passion for security. This lead to founding the OWASP Security Champions Guide to share best practises and helping other organizations achieve this!
I love sharing the fascinating world of security and demonstrating why it's such an engaging and vital field.
Managed by the OWASP® Foundation
owasp.org
Security Champions programs are a proven way to scale security knowledge and embed secure practices across organizations. But why do so many organizations struggle to successfully implement a security champions program? What makes some programs truly effective, while others are barely surviving?
In this talk, we will introduce the Security Champions Maturity Model, a new framework developed to help organizations assess and evolve their security champions initiatives using the ten pillars of the Security Champions Manifesto.
We’ll walk through the model’s structure, share real-world lessons learned from its application in various organizations, and demonstrate how it provides tailored, actionable guidance (including artifacts) to help organizations grow from ad hoc efforts to deeply embedded, resilient programs.
Whether an organization is just starting out (and wants to take things to the next level) or looking to revitalise a stale initiative, this session will equip the audience with a practical tool and insights to take their Security Champions program to the next level.
Cheyenne Seur
iDEAL
CISO
As the Chief Information Security Officer (CISO) at iDEAL and the founder of the OWASP Security Champions Guide, I blend technical expertise and leadership. My mission is to make technology and security not just understandable, but exciting for everyone—from developers to executive business leaders.
With an extensive background in Security Engineering and Security Risk Assessment I know how to translate complex security concepts into clear, actionable insights for non-technical stakeholders. I thrive on collaborating with engineers and exploring new (security) technologies.
I spearheaded the creation of a vibrant Security Champions Community, uniting over 150 engineers with a shared passion for security. This lead to founding the OWASP Security Champions Guide to share best practises and helping other organizations achieve this!
I love sharing the fascinating world of security and demonstrating why it's such an engaging and vital field.
Managed by the OWASP® Foundation
owasp.org










