Threat Brief

Building a Security-First Culture: Methodologies From the Democratic National Committee

When Bob Lord became the first chief security officer (CSO) for the Democratic National Committee (DNC) in 2018, he placed "Bobmoji" stickers above urinals, in bathroom stalls, and on mirrors. As employees washed their hands, avatar renderings of his face served as a security-first reminder.

To implement and maintain a strong security culture, CSOs must be willing to be unconventional, Lord explained during a Wednesday briefing session at Black Hat USA 2026. Lord, now a consultant at Lord Consulting, and his successor, Steve Tran, detailed how the party organization built its defenses following a 2016 security incident involving Russian state actors and how they continued evolving their security posture.

The DNC operates as a cyclical organization where the primary goal is winning elections rather than security, Tran noted. However, their recommendations and methodologies can be applied to organizations across sectors.

Bobmojis were not the only method Lord used to shape a security mindset. He also created a game modeled after "Family Feud," called "Security Feud," to reinforce the importance of security checklists for employees. As staff members shouted answers like "update software" and "use multifactor authentication," Lord high-fived them, noting that the interactive approach successfully engaged the team.

Auditing a new security environment

When Tran, now CISO at Iyuno, took over the DNC CSO role in 2022, he replaced the Bobmojis with bobbleheads. When transitioning into a new role, security leaders conduct an audit to learn the environment, people, and processes. Tran and Lord explained that it is common for incoming leaders to have different expectations than their predecessors, and Tran focused on understanding Lord's strategic decisions.

The two disagreed on the necessity of email scanning, and Tran initially questioned Lord's choice to deploy Chromebook computers. However, they agreed that auditing the cultural mindset to determine which routines changed how people think about security was a critical priority.

DNC employees did not work with traditional Windows machines, as Tran expected. Instead, they worked on Chromebooks. Tran initially doubted that adoption was practical, but Lord's implementation proved successful.

Chromebooks offered a more secure path and were more cost-effective than attempting to modernize the organization's aging Windows infrastructure and Active Directory controller, Lord explained. He cautioned that on-premises Active Directory environments often present an elevated risk surface for unauthorized access.

"I walked in with a certain set of expectations," said Tran, who noted he was pleased to see hardware security keys and strong multifactor authentication already in place.

"You did the hardest part: getting a huge user base to enroll in YubiKeys and use it," Tran said to Lord. "The laptops were locked down, which was amazing. You got people to patch."

Tran was initially surprised by the lack of email scanning. Lord explained that this omission was intentional. Rather than attempting to intercept every unauthorized message at the moment of delivery—whether malicious actors used email or SMS—Lord focused on building resilience against social engineering attempts.

"It's much better to stop it at the moment of intrusion, whether they're trying to get you to install software or cough up your username and password," Lord said.

A CSO's goal is to make systems resilient so unauthorized parties cannot easily execute malware or acquire sensitive credentials.

"As an executive coming into the organization, expect the unexpected," Lord advised.

Establishing executive co-ownership

Like many organizations, the DNC operated under budget constraints. Lord found that the chief financial officer was his primary ally, which significantly aided their security initiatives.

This executive support extended further. Tom Perez, who served as DNC chairman from 2017 to 2021, required the security team to speak for the first 10 minutes of every staff meeting and committed to improving security standards.

Many of Perez's actions surprised Lord. When the security team rolled out hardware keys to the staff, Perez checked in the day after the deadline to verify enrollment. Upon learning that some individuals had not yet completed the process, Perez called their personal cell phones to ensure they enrolled over the following weeks.

The staff did not take weeks; they enrolled immediately after receiving a call from the chairman.

"That's not executive buy-in or advocacy. That's co-ownership," Lord said.

When Tran assumed the CSO role, he inherited a functional security program. His objective shifted to advancing the organization's capabilities. Building on the established security-first mindset, Tran focused on a cloud security upgrade, implemented a knowledge management portal, and formed a security risk committee.

"You saved me so many hard parts," Tran told Lord. "I came in to help them work with gray areas a little bit more because not everything is black and white in security."

Sources

  1. Managing the Security Culture Half-Life Black Hat USA 2026, blackhat.com

Improve team velocity with
better security and privacy.