Building a Champions Network That Works, part 2 of 7
Most champions programmes never get properly funded. They start as a side project run by an enthusiastic awareness lead, survive on goodwill for a year or two, and quietly fade when that person moves on or the sponsor changes. When we ask why, the answer is nearly always the same: nobody ever wrote the business case. The programme was pitched as a good idea rather than as an investment, and good ideas do not get budget lines.
This article sets out how to build a business case that survives contact with a finance director. It draws on the network of 500 champions we built inside a FTSE 250 organisation over 18 months, the work we now do, and research explaining why champions produce value in the first place.
Start with the problem, not the programme
The most common mistake is to open with the champions programme itself: what it is, how it works, and who will be in it. Executives do not buy programmes. They buy solutions to problems they already recognise, so the first job is to describe the problem in terms the board is already worried about.
For most organisations that problem is a gap between security policy and security behaviour. Ross Anderson made the point two decades ago that security failures are usually failures of incentives rather than technology: the people best placed to prevent an incident are rarely the people who bear its cost. Your policies say one thing, the daily reality in the business says another, and the security team is too small and too distant to close the gap on its own. Put numbers on that gap. How many incidents last year had human behaviour as a root cause? How long does the security team spend answering questions that a local colleague could answer? How often do projects reach the security review stage with problems that should have been caught weeks earlier? These are the costs the programme will reduce, and they need to be visible before the programme is introduced.
Explain why champions work, in one paragraph
A business case needs a plausible mechanism, otherwise the benefits look like wishful thinking. The mechanism for champions is well understood, and it is not what most people assume.
Champions are often described as an extension of the training function, people who cascade awareness messages into their teams. That is the weakest version of the argument, and the one most easily challenged, because awareness has a poor track record of changing behaviour. The stronger argument is that champions change norms. Damon Centola's work on complex contagion shows that behaviours which carry a cost or a social risk do not spread through a single exposure the way information does; they spread when people see several trusted peers adopting them. A champion embedded in a team is exactly that trusted peer. Fehr and Gächter's experiments on cooperation add the second half: people contribute to a shared good when they can see that others are contributing too, and stop when they cannot. Security is a shared good. A champion is a visible, credible signal that colleagues are cooperating, and that signal sustains cooperation across the team. When we describe champions to boards, we describe them as cooperation signals first and teachers second, and the conversation changes.
Build a benefits model before a cost model
Traditional business cases lead with costs. A modern investment case leads with a benefits register, and the discipline of writing one forces clarity about what the programme is actually for.
Separate the benefits into two groups. Cash-releasing benefits are the ones finance will accept in a return-on-investment calculation: reduced incident-handling costs, reduced remediation of audit findings, fewer project delays at security review, hours returned to the central security team. In the network we built, the reduction in low-level queries reaching the security team was the first benefit to appear and the easiest to evidence, because the ticketing system already measured it. Non-cash-releasing benefits are real but harder to monetise: faster reporting of suspicious activity, higher reporting rates, improved audit outcomes, better relationships between security and the business. Do not force these into the financial model. Present them alongside it, with their own measures, and let the reader weigh them.
For each benefit, name a baseline, a target, an owner and a measurement method. If you cannot say how a benefit will be measured, it does not belong in the register.
Be conservative on attribution
When incidents fall after a champions programme launches, it is tempting to claim all of the improvement. Do not. Technology changes, policy changes and general awareness activity all contribute, and a finance director will know that. Attribute a defensible share to the programme, explain how you arrived at it, and show the return on investment at that share. A case that claims a 60 per cent contribution and delivers it builds trust for the next funding round. A case that claims 100 per cent and delivers 60 looks like a failure even though the programme worked.
Run a simple sensitivity analysis: what does the return look like if benefits arrive at half the expected level, or six months late? If the case still holds at the pessimistic end, say so. Boards fund resilience, not optimism.
Cost it honestly, including the champions' time
The highest cost in any champions programme is not the programme manager or the training platform. It is the champions' own time, and it is the cost most often left out because it does not appear as a line in the security budget. Leave it out and the business will find it later, usually when a line manager complains that their best analyst is spending a day a month on security. Put it in, at a fully loaded hourly rate, and the case becomes credible. In our experience, a well-run network costs a fraction of a single additional security hire and reaches parts of the organisation that a hire would never see.
Include programme management, onboarding and continuing development, recognition, tooling and a modest budget for events. Then show the payback period. In most organisations, the cash-releasing benefits alone return the cost within the first year.
Show how you will know it is working
The weakest business cases stop at the return-on-investment figure. The strongest describe what the sponsor will see at three, six, and twelve months, because that turns a one-off funding decision into a sustained commitment.
Use leading indicators as well as lagging ones. Lagging indicators, such as incident counts and audit findings, move slowly and are affected by many things. Leading indicators move early and are closer to the mechanism: champion engagement, the share of teams with an active champion, reporting rates, query volumes reaching the central team, and the health of the network itself. Organisational network analysis is particularly valuable here, because it shows whether champions are actually connected to the people they are meant to influence or are simply names on a list. A network with high coverage but weak ties will not shift norms, and the analysis will show that long before the incident data does.
Address the risks the board will raise
Every experienced executive has seen a volunteer programme collapse, so name the risk before they do. The main ones are champion attrition, loss of sponsor, and drift into a communications channel with no behavioural effect. For each, state the mitigation: a recruitment pipeline rather than a one-off call for volunteers, a named executive sponsor with the programme in their objectives, and a measurement model that tracks behaviour rather than message reach. Showing you have thought about failure often secures funding.
What the evidence says
A business case is stronger when it can point beyond the author's own experience, and the external evidence for champions programmes, while thinner than it should be, is now good enough to cite.
The most useful recent source is the Layer 8 Champions Impact Report 2026, a survey of more than a hundred organisations across the UK, Europe and the US. It found that organisations see the most growth in secure behaviour adoption once a programme has been running for three years or more, that nearly three quarters of organisations with a measurement programme in place report higher champion engagement over the long term, and that investing in measurement reduces the need for expensive incentives and extends programme life. It also found that only 7 per cent of organisations attempt to measure champions' direct effect on risk reduction, and that nearly half still run their measurement on spreadsheets. Read together, those findings make a specific argument to a finance director: the programmes that last and pay back are the ones funded to measure themselves.
The clearest public before-and-after comes from Purina's ambassador programme, where teams with an ambassador reported a fifth more phishing attempts, achieved full training compliance, and clicked on simulated phishing at half the rate of teams without one. That comparison between champion and non-champion teams is exactly the evidence structure a scaled programme should build for itself, and it is worth showing a board what it looks like when it exists.
In application security, the BSIMM14 study reported that organisations with active champion programmes scored around a quarter higher on overall software security activities and had 40 to 50 per cent higher training adoption. The mechanism the whole model rests on, that people adopt security behaviour when they see trusted peers doing it, has independent support too: a 2025 cross-national study in the Journal of Cybersecurity found that witnessing colleagues' security behaviour and perceiving peer expectations were among the strongest drivers of phishing reporting in Germany, the UK and the US alike.
Be honest in the case about what this evidence is. Most of it is survey or case data rather than a controlled trial, and the academic literature includes a well-documented example from Sasse and colleagues at a large e-commerce firm: champions appointed without support produced wildly uneven results. That is not a reason to doubt the model. It is why the case should fund sponsorship, support, and measurement rather than a list of names.
The case in one page
If the full document is twenty pages, the summary is one. Problem, mechanism, benefits, cost, return, measurement, risks. A finance director should be able to read that page and understand why this is an investment rather than an expense, and a CISO should be able to defend it in a budget meeting without the author in the room.
A champions programme is one of the few security interventions that gets cheaper and more effective as it scales, because each new champion strengthens the signal for everyone around them. That is a story worth telling properly. Written as an investment case rather than a good idea, it also gets funded.
About this series. Building a Champions Network That Works is a seven-part guide from CyBehave to starting, funding, recruiting, scaling and measuring a security champions programme, and to the shift from awareness to behaviour change that sits underneath all of it. Previous: Part 1, Why now is the right time to start a champions programme. Next: Part 3, Where to start: the first ninety days.