Mark McMillan - Leading with the Carrot: Building Security Culture, Not Just Compliance
Manage episode 517898755 series 3457700
Mark McMillan has been building and leading Information Security Champions programs for over five years and has spent nearly a decade shaping cybersecurity culture at Rocket. He's passionate about creating programs that empower, not punish, and help people understand their role in keeping data secure.
In this episode of The Security Champions Podcast, Mark shares his journey into the field and what he has learned about fostering engaging and supportive security programs. He contrasts the outdated “stick” approach with a more empowering “carrot” method that fosters trust, ownership, and lasting behavior change. He breaks down how Champions Programs act as powerful networks of internal advocates, strategies for scaling and sustaining them over time, and the importance of continuous improvement and community support.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Podcast sponsored by Security Journey, Secure Coding Training for Developers and Everyone in the SDLC. Learn more at securityjourney.com.
FOLLOW US to stay up-to-date with new content!
- LinkedIn (linkedin.com/company/security-journey)
- Instagram (https://www.instagram.com/securityjourney)
- YouTube (youtube.com/c/securityjourney)
- Twitter (twitter.com/SecurityJourney)
- Online (securityjourney.com)
- CONTACT: [email protected]
Chapters
1. Mark McMillan - Leading with the Carrot: Building Security Culture, Not Just Compliance (00:00:00)
2. Welcome to The Security Champions Podcast (00:00:14)
3. The Carrot vs The Stick (00:06:00)
4. The Carrot in Practice (00:13:05)
5. Scaling a Program to Over 900 (00:21:51)
6. The Power of Guest Presentations (00:26:44)
7. Supporting Large Programs (00:35:14)
8. Final Thoughts (00:40:51)
25 episodes