Building a Champions Network That Works, part 3 of 7
The hardest part of a champions programme is not running it. It is the first three months, when the idea is agreed in principle, but nothing exists yet, and every decision in that window shapes what follows. Most of the programmes we have seen fail were lost here, before anyone noticed, through a handful of early choices that felt sensible at the time. This article walks through how to make those choices well.
Decide what champions are for before you recruit any
The first decision is the one most programmes skip. Ask ten security leaders what their champions are for, and you will hear ten answers: cascade awareness messages, be a local point of contact, report incidents, review projects, run phishing simulations, promote training. These are all things champions can do. None of them is the reason champions work.
Champions work because they change what is normal in a team. The research on complex contagion is detailed: behaviours with a cost or a social risk attached, which describes almost every security behaviour, spread when people see trusted peers doing them, not when they receive a message about them. A champion is that trusted peer, and their value lies in being visibly careful in front of colleagues who take their cue. Write that down as the programme's purpose, in one sentence, before anything else. Test every later decision about recruitment, activity, and measurement against it. Programmes that skip this step drift, usually within a year, into a communications channel with a newsletter and no behavioural effect.
Secure a sponsor who will still be there in two years
Champion programmes die when their sponsor leaves. We have watched a well-run network in a manufacturing business collapse within six months of its executive sponsor moving on, not because anyone decided to end it but because nobody with authority was left to protect the champions' time. The programme was rebuilt later at considerable cost.
The sponsor should be an executive outside the security function, ideally someone with a stake in the business units where champions will sit. The sponsorship should be written into their objectives rather than agreed over coffee, and it should come with two specific commitments: that champion time is a recognised part of the role, and that line managers will be told so by someone senior enough that they listen. Without the second commitment, the first is worthless. A champion whose manager quietly resents the hour a week will stop attending within a quarter.
Map the organisation before choosing where to begin
Do not launch everywhere at once. A programme that opens with a company-wide call for volunteers will attract people already interested in security, cluster them in departments where security was already strong, and leave the areas of real risk untouched. The early network will look healthy on paper and be almost useless in practice.
Instead, spend a few weeks understanding where the behaviour gap actually is. Which teams generate incidents? Which reach security review late? Where does the security function have no relationships at all? Then look at how those teams are connected. Organisational network analysis, even in a light form using existing collaboration data or a short survey, will show which individuals sit at the centre of a team's working relationships. Those people are the ones whose behaviour others copy. A champion who is central to a team of thirty is worth more than five champions at the edge of it. When we built our first large network, we learned this the hard way: the first cohort was enthusiastic and well trained and had almost no influence, because they were the people with time to volunteer rather than the people others listened to.
Recruit deliberately, not by broadcast
With a map in hand, recruitment becomes targeted. Approach the central people directly, through their manager and with the sponsor's backing, and ask them to take the role. Some will decline, and that is fine; the aim is a first cohort of perhaps fifteen to twenty champions positioned where they matter, not the largest possible number.
A long-running debate is whether champions should be volunteers or appointed. The honest answer is that both models work and both fail, depending on execution. Volunteers bring motivation and lose coverage. Appointed champions bring coverage and risk resentment. The blend that works in most organisations is targeted invitation: ask the person specifically, tell them why they were chosen, and give them a real choice. Being chosen for influence is itself motivating in a way that answering a broadcast never is.
Give the first cohort something real to do in the first month
Onboarding is where enthusiasm either becomes habit or fades. A day of training followed by silence is the commonest pattern and the most damaging. Within four weeks, the first cohort should have a specific behaviour to model, a specific thing to report on, and a direct line to a named person on the security team who responds within a day.
Keep the first behaviour small and visible. Verifying unusual payment requests out loud, reporting every suspicious message rather than deleting it, checking AI-generated content before it goes into a customer-facing document: any of these will do, as long as colleagues can see the champion doing it. The point of the first behaviour is not its direct security value, but demonstrating that the champion is different from the rest of the team in a way the team notices.
Measure from the first day, not the first anniversary
Programmes that begin measuring in year two have no baseline and no story. Before you onboard the first champion, record what you will later want to show has changed: reporting rates by team, low-level query volumes reaching the security team, time to security review on projects, and a short baseline of the network itself. Then track the leading indicators monthly. Champion activity, coverage of priority teams, and whether champions remain central in their teams' networks are the measures that move early. Incident data will follow slowly, and only if these move first.
What ninety days should look like
By the end of the first quarter, a well-started programme has a written purpose, a named sponsor with the programme in their objectives, a map of where the behaviour gap sits, a first cohort of fifteen to twenty champions chosen for influence rather than availability, a single visible behaviour that each of them is modelling, and a baseline against which the next year will be judged. It doesn't have a logo, a newsletter, a large event, or a hundred names on a list. Those things can come later. The first ninety days are about getting the shape right, because the shape is what scales.
About this series. Building a Champions Network That Works is a seven-part guide from CyBehave to starting, funding, recruiting, scaling and measuring a security champions programme, and to the shift from awareness to behaviour change that sits underneath all of it. Previous: Part 2, Making the business case for security champions. Next: Part 4, Volunteer, voluntold or chosen: how to recruit champions who change behaviour.