The Cultural Triad: How to Embed Security into Company Culture with Partnerships, Cooperation and Collaboration
February 10, 2022

Michael Eisenberg
Coalfire

To arrive at a risk-based product development lifecycle, there must be a risk-based culture. While nearly everything can be automated these days, the source code for early-warning risk management starts with people and teams, not machines.

Software development has worked in its own silo for generations, and traditional DevOps has allowed for this vacuum with little to no security involved. Since security is now a process of continuous integration and deployment, it is mission critical for CISOs and the DevSecOps teams to engage in deeper conversations together to start working through the obstacles. The ongoing proliferation of data breaches, bad actor disinformation campaigns, and the endangerment of customer data demands it.

But how does one begin to embed security into company culture? Let's start with the cultural triad — then discuss how to get there.


The Cultural Triad: Partnership, Cooperation, and Collaboration

When the CISO brings the DevSecOps initiative to the C-suite, it should stream into the very fiber of the organization. It must be embraced from above, without indifference, dismissiveness, or passive aggression. By top-level management embracing this framework, the CISO can more effectively set the playing field for seamless integration throughout the organization.

Foster partnerships. Application development and product managers typically don't go to security folks. To begin this pivotal partnership, security folks must go to them. There may be pushback and indifference at first, but to receive cooperation from all parties, it's imperative to overcome communication challenges in pursuit of DevSecOps success. Understand that development may have legitimate grievances with security or executive leadership, so tread carefully and address those grievances in a respectful way.

The best way to start the conversation is from the standpoint of customer priorities. Start talking with designers, developers, and engineers about the customer's threat perspective. The customers need assurance, and if they don't get it from you, they'll go somewhere else that provides and certifies it.

Seek cooperation. Once the security conversation with DevOps is underway, set the table with expectations. If agile methodologies are a part of software development's DNA, now is the time to integrate security into that DNA. In the new development lifecycle, security is everyone's responsibility, so be sure to clarify and delegate ownership and accountability. Leverage the organization's mission and purpose to merge security with quality and infuse it into the company's culture.

Embrace collaboration to drive revenue growth. After addressing the need for DevSecOps from a customer perspective, everyone should focus on management's prime directive: revenue growth. Corporate officers and directors are measured and compensated by how well they deliver benefits to shareholders. A breach, a fine, or lost customer trust will have dramatic and direct impact on this calculation. Security can no longer be viewed solely as a cost center; instead, it is essential to generating revenue.

A collaborative corporate mindset empowers employees with more portable skills that enable career advancement and instills confidence in their technical abilities. It also embraces the principles of diversity, equity, and inclusion to create a mosaic of ideas and backgrounds. With this recognition, everyone is better equipped to understand their role, and how they can contribute unique skills and perspectives to the “security-focused” company culture in a meaningful way.

Security Leaders Can Lead the Transformation

Secure products have become value propositions and trigger points for purchasing decisions. The secure product lifecycle is closer than ever to everyone's core business, and everyone knows it. Customers expect it, and marketing is talking about it. Security has become more cross-functional by necessity, and with that, the surrounding corporate culture that supports it. A risk-based culture focused on threat modeling and the logical prioritization of vulnerabilities makes all this possible.

Security leaders are in the perfect position to help create a risk-based culture. Developers need to exercise risk-based team collaboration through cooperative partnerships. Examples:

■ Partner with someone in security to run tests on what they're building

■ Use procurement and vendor management to validate desired third-party software

■ Work with legal to sort out open-source contract issues

■ Communicate with marketing in putting a public face on the secure app they have created

That's a lot of people, and many teams to work with, compared to the smaller microcosm of stakeholders that developers typically interacted with 10 to 15 years ago.

Ask questions. Ask for help and advice. Role play, humanize and align. Partnership, cooperation, and collaboration are the cultural disciplines that bridge the gaps between development and security operations, and into the new methodology of DevSecOps. The alignment created through a risk-based culture strengthens the development lifecycle and produces better applications that protect the customer, the product, and the company.

Michael Eisenberg is VP, Strategy, Privacy, Risk, at Coalfire
Share this

Industry News

March 27, 2025

webAI and MacStadium(link is external) announced a strategic partnership that will revolutionize the deployment of large-scale artificial intelligence models using Apple's cutting-edge silicon technology.

March 27, 2025

Development work on the Linux kernel — the core software that underpins the open source Linux operating system — has a new infrastructure partner in Akamai. The company's cloud computing service and content delivery network (CDN) will support kernel.org, the main distribution system for Linux kernel source code and the primary coordination vehicle for its global developer network.

March 27, 2025

Komodor announced a new approach to full-cycle drift management for Kubernetes, with new capabilities to automate the detection, investigation, and remediation of configuration drift—the gradual divergence of Kubernetes clusters from their intended state—helping organizations enforce consistency across large-scale, multi-cluster environments.

March 26, 2025

Red Hat announced the latest updates to Red Hat AI, its portfolio of products and services designed to help accelerate the development and deployment of AI solutions across the hybrid cloud.

March 26, 2025

CloudCasa by Catalogic announced the availability of the latest version of its CloudCasa software.

March 26, 2025

BrowserStack announced the launch of Private Devices, expanding its enterprise portfolio to address the specialized testing needs of organizations with stringent security requirements.

March 25, 2025

Chainguard announced Chainguard Libraries, a catalog of guarded language libraries for Java built securely from source on SLSA L2 infrastructure.

March 25, 2025

Cloudelligent attained Amazon Web Services (AWS) DevOps Competency status.

March 25, 2025

Platform9 formally launched the Platform9 Partner Program.

March 24, 2025

Cosmonic announced the launch of Cosmonic Control, a control plane for managing distributed applications across any cloud, any Kubernetes, any edge, or on premise and self-hosted deployment.

March 20, 2025

Oracle announced the general availability of Oracle Exadata Database Service on Exascale Infrastructure on Oracle Database@Azure(link sends e-mail).

March 20, 2025

Perforce Software announced its acquisition of Snowtrack.

March 19, 2025

Mirantis and Gcore announced an agreement to facilitate the deployment of artificial intelligence (AI) workloads.

March 19, 2025

Amplitude announced the rollout of Session Replay Everywhere.

March 18, 2025

Oracle announced the availability of Java 24, the latest version of the programming language and development platform. Java 24 (Oracle JDK 24) delivers thousands of improvements to help developers maximize productivity and drive innovation. In addition, enhancements to the platform's performance, stability, and security help organizations accelerate their business growth ...