The Boring AppSec Podcast

S2E2 - Dustin Lehr


Listen Later

In Season 2 Episode 2, we interview Dustin Lehr, Co-Founder, Chief Product & Technology Officer at Katilyst.

We discuss the significance of security champions in application security. We explore the cultural aspects of implementing security champions programs, the challenges of maintaining engagement, and the importance of leadership support. The conversation delves into measuring the success of these programs, the role of behavioral science, and the impact of effective training and gamification in enhancing security awareness within organizations. Dustin discusses the Octalysis framework, which identifies eight core human motivators that can be leveraged in gamification and cybersecurity culture. He emphasizes the importance of building relationships within organizations to change perceptions of security teams and foster a collaborative environment. Dustin also shares insights on the intersection of creativity and cybersecurity, his motivations for starting a company, and the role of AI in enhancing human interactions rather than replacing them.


Key Takeaways

- Security champions programs are crucial for fostering a security culture.

- Engagement and leadership support are key to program success.

- Measuring success can be challenging but is essential.

- Behavioral science plays a significant role in security engagement.

- Gamification can enhance training but must be used wisely.

- Curiosity can drive initial engagement but must be sustained.

- Training should be relevant and tailored to the audience.

- Creating empathy between teams improves security outcomes.

- Deep gamification focuses on understanding human drives.

- Starting a company is about helping others, not just profit.

- AI can augment human interactions but cannot replace them.

- Security teams should focus on providing value and support.

- Human connection is essential in cybersecurity.

- The importance of community and collaboration in security efforts.

Tune in to find out more!
Contacting Dustin
* LinkedIn: https://www.linkedin.com/in/dustinlehr/

* Security Champion Success Guide: https://securitychampionsuccessguide.org/

Contacting Anshuman
* LinkedIn: ⁠⁠⁠⁠https://www.linkedin.com/in/anshumanbhartiya/
* X: ⁠⁠⁠⁠https://x.com/anshuman_bh
* Website: ⁠⁠⁠⁠https://anshumanbhartiya.com/
* ⁠⁠⁠⁠Instagram: ⁠⁠⁠https://www.instagram.com/anshuman.bhartiya
Contacting Sandesh
* LinkedIn: ⁠⁠⁠⁠https://www.linkedin.com/in/anandsandesh/
* X: ⁠⁠⁠⁠https://x.com/JubbaOnJeans
* Website: ⁠⁠⁠⁠https://boringappsec.substack.com/

...more
View all episodesView all episodes
Download on the App Store

The Boring AppSec PodcastBy The Boring AppSec Podcast