Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Microsoft-We Energies contract retains provision PSC struck down

    August 6, 2026

    The History Behind Ceuta’s Migrant Crisis

    August 6, 2026

    Houthi attacks reportedly kill at least 30 Yemeni government forces

    August 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Microsoft-We Energies contract retains provision PSC struck down
    • The History Behind Ceuta’s Migrant Crisis
    • Houthi attacks reportedly kill at least 30 Yemeni government forces
    • Trump Issues Tariffs on Key Ingredient for Electronics and Solar Panels
    • Your table awaits: Exhibit at TechCrunch Disrupt 2026 to be seen by thousands 
    • Snowflake Hacker Pleads Guilty in US Court
    • Following Primary Loss, Crypto PACs Invest $1.5M in 3 US State Races
    • Nearly half of dementia cases may be linked to risks you can change
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    How the Democratics Built a Security-First Culture

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Black Hat USA 2026 —Las Vegas—When Bob Lord became the first chief security officer (CSO) for the Democratic National Committee (DNC) in 2018, he plastered “Bobmoji” stickers above urinals, in bathroom stalls, and on the mirrors. As employees washed their hands, avatar renderings of his face served as a security-first reminder.

    To implement and maintain a strong security culture, CSOs must be willing to be “absurd,” Lord revealed during Black Hat USA 2026. Lord, now consultant at Lord Consulting, and his successor, Steve Tran, broke down how the party organization built its defenses following a 2016 hack by Russian state actors and continued evolving security.

    The DNC is a cyclical organization where “the idea is to win elections, not to be more secure,” said Tran, but their recommendations and best practices can be applied to organizations across sectors.

    Bobmojis weren’t the only tactic Lord used to mold a security mindset, which can take plenty of work. He also created a “Family Feud” game dupe, dubbed “Security Feud,” to instill the importance of security checklists among employees. As people shouted, “update software” and “use multifactor authentication” and Lord high-fived them during the game, he knew the theatrics were well worth it.

    Related:Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

    When Tran, now CISO at lyuno, took over the DNC CSO role in 2022, he replaced Bobmojis with bobbleheads. The predecessor and successor agreed on tactics to get people to care about security.

    Expect the Unexpected

    However, as Tran took over the role, some of Lord’s work didn’t meet his expectations. This is commonplace when one security leader takes over for another, Tran and Lord explained. When CSOs walk into a new role, they conduct an audit to learn the environment, people, and processes. Tran was just trying to understand what Lord was thinking, which is important for any successor to examine.

    They disagreed on the importance of email scanning, and Tran was perplexed by Lord’s choice to use Chromebook computers. But auditing the cultural mindset to determine which routines changed how people think about security was one critical point where they’re on the same page.

    DNC employees didn’t work with “fancy Windows machines,” as he expected. Instead, they worked on Chromebooks. Tran didn’t think that adoption was practical or possible, but Lord proved him wrong.

    Not only did Chromebooks offer a more secure path, but they were also cheaper than trying to revive the organization’s aging Windows infrastructure and active directory (AD) controller, explained Lord. AD on-premises is an attack magnet, he warned.

    Related:Former Citigroup CISO Blauner on What Makes A Great Security Leader

    “I walked in with a certain set of expectations,” Tran said during the session. He was happy to see hardware security keys in place, and strong multifactor authentication (MFA).

    “You did the hardest part, getting a huge user base to enroll in YubiKeys and use it,” he said, turning to Lord. “The laptops were locked down, which was amazing. You got people to patch.”

    On the other hand, Tran was unpleasantly surprised by the lack of email scanning. But Lord had his reasoning and the pieces Tran thought were missing were intentional on his part. Lord wasn’t trying to stop an attack at the moment of delivery, whether threat actors used email or SMS, but build resilience against social engineering scams.

    “It’s much better to stop it at the moment of intrusion, whether they’re trying to get you to install software or cough up your username and password,” he said. The CSOs’ goal is to make systems resilient so that threat actors won’t simply be able to run malware or steal sensitive credentials.

    “As an executive coming into the organization, expect the unexpected,” Lord said.

    When the Chairman Calls, You Answer

    As in many organizations, Lord faced budget constraints while working at the DNC. But he found that the chief financial officer was his “biggest ally,” which made a world of difference.

    Related:CISOs vs. Boards: Myth or Misunderstanding?

    And support extended even further than that. Tom Perez, who served as DNC chairman from 2017 to 2021, had the security team speak for the first 10 minutes of every staff meeting and committed to improving security standards.

    Many of his moves surprised Lord. When he and his team rolled out security keys to everyone, Perez called one day after the deadline to see if everyone had enrolled. When he found out that some stragglers remained, Perez called their personal cell phones to ensure they enrolled over the next couple of weeks.

    However, it didn’t take weeks — they enrolled immediately after getting that call from the chair.

    “That’s not executive buy-in or advocacy. That’s co-ownership,” Lord said.

    When Tran took over as DNC CSO, he felt he inherited a strong security program thanks to his predecessor. His job then became: How does the organization continue to move forward? With a deeply imbedded security-first mindset, he focused on a cloud security upgrade, and implemented a knowledge management portal, and a security risk committee.

    “You saved me so many hard parts,” Tran told Lord. “I came in to help them work with grey areas a little bit more, because not everything is black and white in security.”

    Built culture Democratics SecurityFirst
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Snowflake Hacker Pleads Guilty in US Court

    How a global investment firm reduced security surprises

    How a software provider closed unknown paths to cloud compromise

    New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

    Meta AI model hacked a company during misconfigured cyber test

    How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Microsoft-We Energies contract retains provision PSC struck down

    August 6, 2026

    The History Behind Ceuta’s Migrant Crisis

    August 6, 2026

    Houthi attacks reportedly kill at least 30 Yemeni government forces

    August 6, 2026

    Trump Issues Tariffs on Key Ingredient for Electronics and Solar Panels

    August 6, 2026
    Latest Posts

    Bitcoin treasury company erases 7.7M shares after selling 177 BTC

    July 24, 2026

    New Dolphin X malware uses AI to rank high-value targets

    July 24, 2026

    An FDA Panel Just Endorsed These Unproven Peptides

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Microsoft-We Energies contract retains provision PSC struck down

    August 6, 2026

    The History Behind Ceuta’s Migrant Crisis

    August 6, 2026

    Houthi attacks reportedly kill at least 30 Yemeni government forces

    August 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.