AWS and Cloudanix team co-authored this blog: Real-Time Threat and Anomaly Detection for Workloads on AWS

Application Security, Threat Modeling, and Building Security Champion Programs with Dustin Lehr

Learn how to build security champion programs, create security-first culture, implement controls starting from production, and why security should not be a startup's day-one priority.

Security people sometimes get discouraged because nobody cares about security like they do. But that is not true. There are people across every organization who care about security. The challenge is finding them, building relationships with them, and turning them into advocates. Dustin Lehr, Senior Director of Platform Security at Fivetran and Co-founder of Catalyst Security, spent 13 years as a software engineer before moving into cybersecurity leadership. He shares how to build security champion programs that actually change culture, why you should start security from the right side (production) rather than the left (source code), and why security should not be a startup’s top priority on day one.

You can read the complete transcript of the episode here >

When should organizations start prioritizing security?

Dustin takes a contrarian position for a security person: security should not be a startup’s day-one priority.

  • Pre-product-market fit: Focus on building the business. You have little risk because you have little to protect. Best practices are fine, but security should not be the top priority.
  • Post-product-market fit: Now you have customers, data, and reputation to protect. This is when security investment should begin.
  • The common mistake: Companies find product-market fit and then keep chasing the next feature, next customer, never turning around to build a resilient product. That delay creates compounding risk.

The driver for initial security investment is often customers themselves. As organizations pursue larger customers, those customers demand compliance certifications, security questionnaires, and evidence of controls. Achieving SOC 2 compliance is often the first milestone. This market pressure naturally initiates the security journey.

Why should you start security from the right, not the left?

This challenges the popular “shift left” narrative. Dustin argues that starting from production (the right side) makes more practical sense:

  • Understand your current reality first: Pen testing, monitoring, and incident detection in production show you what is actually happening, not what might be happening.
  • Measure before you optimize: If you implement code scanning and training without production baselines, how do you know you are making a difference?
  • Justify further investment: Production findings provide concrete evidence for leadership conversations. “We found active intruders in our environment” gets attention. “We found 500 SAST findings” does not.
  • Then shift left progressively: Once you understand your production reality, implement shift left controls (code scanning, training, secure SDLC) and measure whether they reduce production defect density.

Root cause analysis of production incidents further justifies process changes. When an incident occurs, tracing it back to a missing code review or inadequate testing builds the case for preventive controls at earlier stages.

What is a security champion program and how does it work?

Security champion programs find allies across the organization who advocate for security on behalf of their teams. This approach to scaling security champions has proven effective across organizations of all sizes, and it complements broader application security initiatives:

  • Start by finding allies: People who already care about security exist in every organization. Find them and invest time in them.
  • Diffusion of innovation: Champions create a tipping point. One person per team who advocates for security reaches more people than the security team ever could alone.
  • Peer influence: People are more likely to listen to their peers than to the security team. When a trusted teammate delivers the same message as a security person, it lands differently.

The process for building a champion program:

  1. Define goals: What specific metrics are you trying to influence? Make them SMART (specific, measurable).
  2. Identify your audience: Who will you invite? Senior engineers? Cross-functional roles? Beyond engineering?
  3. Understand motivations: What makes these people tick? What would motivate participation?
  4. Define desired behaviors: What specific actions do you want champions to take? Report phishing? Raise security concerns in design reviews? Advocate for secure defaults?
  5. Create engagement channels: Monthly brown bags, dedicated Slack channels, direct relationships between security team members and business lines.
  6. Measure and demonstrate ROI: Track attendance, participation, reported issues, and cultural metrics over time.

How do you get leadership buy-in for security programs?

Dustin’s approach focuses on speaking the language of the business:

  • Quantify risk in business terms: Reputation damage, customer acquisition impact, regulatory fines. Not “500 vulnerabilities.” A mature approach to threat modeling helps frame these conversations.
  • Show customer demand: Implementing security controls to win a specific customer is an easy win that demonstrates direct ROI.
  • Position as differentiator: In competitive markets, strong security posture can be the deciding factor for customers choosing between providers.
  • Invite leadership into the conversation: Show your findings and ask “What do you think? Is this a problem?” rather than dictating solutions.

The key insight: if you show leadership everything you consider a problem and they say “that is fine,” you must adjust your approach. The conversation should be collaborative, not adversarial. Open the books, invite feedback, and let the data drive decisions together.

How do you build security-first culture?

Culture change requires relationship building, not mandates from an ivory tower. Building a security culture takes deliberate effort:

  • Earn your seat at the table: Being hired as the security person does not automatically give you influence. You earn it by providing value and speaking in terms others understand.
  • Overcome the “office of no” perception: Security has a negative reputation. Counteract it by being solution-oriented, connecting with people, and showing you are on their side.
  • Train engineers in their language: Developers who care about code quality already care about security implicitly. Frame security as quality. Ask what prevents them from following guidelines rather than lecturing them.
  • Use root cause analysis to drive change: When incidents occur, trace them back to process gaps. This creates evidence-based justification for controls rather than opinion-based mandates.

The fundamental principle: you cannot influence without a relationship. Building relationships takes time, transparency, and consistent demonstration of value. The security teams that succeed are the ones that stop throwing rocks from ivory towers and start building partnerships with the teams they are trying to help.

Related Resources

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo