Almost every security champions programme starts the same way. Someone sets up a recurring meeting, invites the volunteers, and puts a standing agenda in the calendar. For a while it works. Then attendance drifts, the same three people speak, and the meeting quietly becomes a broadcast channel with an audience that has stopped listening.
A forthcoming industry paper at FSE 2026 offers one of the few longitudinal accounts of an organisation trying to solve that problem deliberately, and documenting what happened.
What the study did
Opdenbusch, Shanthakumar, Sasse and Gutfleisch (Ruhr University Bochum and LMU Munich) partnered with an organisation of more than 5,000 employees, of whom roughly 200 are software developers. They observed and analysed the organisation's security champions programme over 64 weeks - about fifteen months of continuous, in-situ observation, which is unusual in this literature and valuable in its own right.
The central change they tracked was a shift in format. The programme moved away from a bi-weekly all-champions meeting towards project-focused groups the authors call breakout action groups (BAGs), meeting monthly. Alongside this, the organisation ran secure coding workshops, used retrospectives to assess progress, and developed a vision statement for the programme.
The reported outcomes: BAGs improved champion engagement and motivation. The vision workshop and the retrospective strengthened group cohesion, aligned champions around a shared sense of mission, and raised the programme's visibility within the organisation.
The interesting part is the direction of travel
Note what happened to cadence. Contact frequency went down, from fortnightly to monthly, while engagement went up.
That should trouble anyone who has ever defended a champions programme on the basis of meeting attendance. It is a direct challenge to the implicit model that underpins most programme reporting: that engagement is a function of exposure and that more touchpoints produce more commitment. If that model were right, halving the contact rate should have degraded engagement. It did not.
The plausible mechanism is not frequency at all. It is task-boundedness. A plenary meeting asks a champion to be an audience member for an hour. A project-focused group asks them to be a contributor to something specific, with a scope they can hold in their head and an output they can point at. The second role is far easier to sustain, and it converts the champion from a recipient of security information into an owner of a piece of security work.
This lines up with what we already know about volunteer roles more generally. Discretionary effort is sustained by autonomy, competence and relatedness - not by attendance obligations. A BAG delivers all three in a way a standing plenary structurally cannot.
Reading it as a network intervention
There is a second reading available here, and it is the one that interests us most at CyBehave.
Moving from a plenary format to breakout groups is not primarily a change to content or cadence. It is a change to the topology of the champion network. A plenary is hub-and-spoke: the programme lead is the hub, the champions are spokes, and champion-to-champion ties are thin and largely incidental. Breaking champions into small, project-bound groups replaces some of those spokes with dense local clusters; champions now have reasons to talk to each other rather than only to the centre.
In the language we use in our own research, this is an edge-restructuring intervention. Nothing about the individual champions changed. No one was retrained, rescreened or re-recruited. What changed was which people had a standing reason to interact with whom, and engagement followed the structure.
That framing also surfaces the risk the study cannot yet see. Dense clusters generate strong bonding ties, and bonding ties are exactly what you want for cohesion, psychological safety and sustained motivation within a group. But the diffusion of security behaviour across a wider organisation does not travel on bonding ties. It travels on bridging ties - the weaker, longer connections between clusters that carry novel practice from one part of the business to another.
So the open structural question is whether BAG formation trades bridging capital for bonding capital. If four BAGs each become tight, motivated and internally cohesive but stop talking across the boundaries, the programme has bought engagement at the cost of reach. That is not a criticism of the study; it is simply a question the study design was not set up to answer, and it is measurable.
The constraints, stated plainly
This is a single-organisation case study and should be read as such. Several limits matter to anyone considering acting on it.
One organisation, one context. A German technology organisation with ~200 developers inside a 5,000-person workforce has a particular culture, a particular delivery model and a particular set of pre-existing relationships. Nothing here establishes that BAGs transfer to a 60,000-person outsourcing group, a regulated financial institution, or a programme where champions sit in operations, HR and finance rather than in engineering teams.
A developer-centric champion population. The champions here are drawn from a software development context, where project-focused working is already the native mode. Organising champions around projects is a much smaller cultural step in that setting than it would be in a programme spanning non-technical functions. The generalisation risk is real.
The interventions are bundled. BAGs did not arrive alone. They arrived alongside secure coding workshops, retrospectives and a vision-statement exercise. Any of these could plausibly drive engagement, motivation, cohesion and visibility on their own. The study reports the package; it cannot isolate the contribution of the BAG format from the contribution of, say, being asked to co-author a mission the champions actually believed in.
Format and cadence changed together. The move to project groups was simultaneous with the move from fortnightly to monthly. If reduced meeting load is doing part of the work, and it may well be, this design cannot separate it from the format change.
No control condition, and time is a confound. Fifteen months is long enough for programme maturation, leadership change, hiring, external incident pressure and general familiarity effects to move engagement on their own. Observational longitudinal work of this kind cannot rule those out, and the presence of researchers in the room for 64 weeks is itself a plausible influence on the behaviour being observed.
The outcomes are proximal, not distal. Engagement, motivation, cohesion, alignment and visibility are all worth having. But they are inputs. The paper does not, and does not claim to, demonstrate that BAGs improved secure coding behaviour, reduced defect density, shortened remediation times or changed any security outcome the board would recognise. The gap between "champions are more motivated" and "the organisation is measurably more secure" remains the central unsolved problem in this field, and this study sits firmly on the near side of it.
Where further exploration should go
None of that diminishes the contribution. Fifteen months of documented practice inside a real programme is worth considerably more than another cross-sectional survey. What it gives us is a well-specified hypothesis worth testing properly.
Four questions look tractable:
Does the format effect survive isolation? A staggered rollout, BAGs introduced to some champion cohorts before others, with cadence held constant, would separate format from frequency and from the surrounding initiatives. Programmes with enough champions to support cohorts can run this without an academic partner.
What happens to the network graph? Organisational network analysis before and after BAG formation would show directly whether clustering increases at the expense of bridging. It would also identify which champions are holding the cross-cluster ties, usually a small number of people whose loss would fragment the programme, and who rarely appear in any programme dashboard.
Does engagement convert? The measurement question is whether motivated champions produce different behaviour in the teams around them. That requires separating what champions report about themselves from what their peers report about the team environment, which, incidentally, is why we hold those signals apart in our own measurement model rather than folding them into a single index.
Does the vision exercise carry more weight than the format? Our instinct, on the evidence available, is that co-authoring a shared mission may be doing more work than the meeting structure. That is a testable claim and a cheap intervention. It deserves to be tested on its own.
For programme leads
The immediate, low-risk takeaway does not depend on resolving any of the above.
If your champions programme currently runs on a recurring plenary meeting and you are watching attendance decline, the instinct to increase frequency, tighten the agenda or chase non-attenders is probably wrong. This study is a reasonable prompt to try the opposite: meet less often, and give small groups of champions something specific to own between meetings. Keep the cross-group connections deliberate rather than accidental, and make sure someone is looking at whether the clusters are still talking to each other.
Then measure whether anything downstream actually changed. That part, the field still owes itself.
Reference
Opdenbusch, J. C., Shanthakumar, S., Sasse, M. A., & Gutfleisch, M. (2026). Enabling Security Champions With Breakout Action Groups (BAGs) – A Longitudinal Case Study. Industry Papers, ACM International Conference on the Foundations of Software Engineering (FSE 2026), Montreal, Canada, 9 July 2026.