Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage

    September 23, 2026

    Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption

    September 23, 2026

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage
    • Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption
    • Discord’s age verification era is upon us, despite community backlash
    • Only 13% of OT Network Segments Are Fully Isolated: Analysis
    • Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says
    • Reptiles, gold and money: How Australia is cracking down on wildlife trafficking
    • Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott
    • Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    How the Democratics Built a Security-First Culture

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Black Hat USA 2026 —Las Vegas—When Bob Lord became the first chief security officer (CSO) for the Democratic National Committee (DNC) in 2018, he plastered “Bobmoji” stickers above urinals, in bathroom stalls, and on the mirrors. As employees washed their hands, avatar renderings of his face served as a security-first reminder.

    To implement and maintain a strong security culture, CSOs must be willing to be “absurd,” Lord revealed during Black Hat USA 2026. Lord, now consultant at Lord Consulting, and his successor, Steve Tran, broke down how the party organization built its defenses following a 2016 hack by Russian state actors and continued evolving security.

    The DNC is a cyclical organization where “the idea is to win elections, not to be more secure,” said Tran, but their recommendations and best practices can be applied to organizations across sectors.

    Bobmojis weren’t the only tactic Lord used to mold a security mindset, which can take plenty of work. He also created a “Family Feud” game dupe, dubbed “Security Feud,” to instill the importance of security checklists among employees. As people shouted, “update software” and “use multifactor authentication” and Lord high-fived them during the game, he knew the theatrics were well worth it.

    Related:Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

    When Tran, now CISO at lyuno, took over the DNC CSO role in 2022, he replaced Bobmojis with bobbleheads. The predecessor and successor agreed on tactics to get people to care about security.

    Expect the Unexpected

    However, as Tran took over the role, some of Lord’s work didn’t meet his expectations. This is commonplace when one security leader takes over for another, Tran and Lord explained. When CSOs walk into a new role, they conduct an audit to learn the environment, people, and processes. Tran was just trying to understand what Lord was thinking, which is important for any successor to examine.

    They disagreed on the importance of email scanning, and Tran was perplexed by Lord’s choice to use Chromebook computers. But auditing the cultural mindset to determine which routines changed how people think about security was one critical point where they’re on the same page.

    DNC employees didn’t work with “fancy Windows machines,” as he expected. Instead, they worked on Chromebooks. Tran didn’t think that adoption was practical or possible, but Lord proved him wrong.

    Not only did Chromebooks offer a more secure path, but they were also cheaper than trying to revive the organization’s aging Windows infrastructure and active directory (AD) controller, explained Lord. AD on-premises is an attack magnet, he warned.

    Related:Former Citigroup CISO Blauner on What Makes A Great Security Leader

    “I walked in with a certain set of expectations,” Tran said during the session. He was happy to see hardware security keys in place, and strong multifactor authentication (MFA).

    “You did the hardest part, getting a huge user base to enroll in YubiKeys and use it,” he said, turning to Lord. “The laptops were locked down, which was amazing. You got people to patch.”

    On the other hand, Tran was unpleasantly surprised by the lack of email scanning. But Lord had his reasoning and the pieces Tran thought were missing were intentional on his part. Lord wasn’t trying to stop an attack at the moment of delivery, whether threat actors used email or SMS, but build resilience against social engineering scams.

    “It’s much better to stop it at the moment of intrusion, whether they’re trying to get you to install software or cough up your username and password,” he said. The CSOs’ goal is to make systems resilient so that threat actors won’t simply be able to run malware or steal sensitive credentials.

    “As an executive coming into the organization, expect the unexpected,” Lord said.

    When the Chairman Calls, You Answer

    As in many organizations, Lord faced budget constraints while working at the DNC. But he found that the chief financial officer was his “biggest ally,” which made a world of difference.

    Related:CISOs vs. Boards: Myth or Misunderstanding?

    And support extended even further than that. Tom Perez, who served as DNC chairman from 2017 to 2021, had the security team speak for the first 10 minutes of every staff meeting and committed to improving security standards.

    Many of his moves surprised Lord. When he and his team rolled out security keys to everyone, Perez called one day after the deadline to see if everyone had enrolled. When he found out that some stragglers remained, Perez called their personal cell phones to ensure they enrolled over the next couple of weeks.

    However, it didn’t take weeks — they enrolled immediately after getting that call from the chair.

    “That’s not executive buy-in or advocacy. That’s co-ownership,” Lord said.

    When Tran took over as DNC CSO, he felt he inherited a strong security program thanks to his predecessor. His job then became: How does the organization continue to move forward? With a deeply imbedded security-first mindset, he focused on a cloud security upgrade, and implemented a knowledge management portal, and a security risk committee.

    “You saved me so many hard parts,” Tran told Lord. “I came in to help them work with grey areas a little bit more, because not everything is black and white in security.”

    Built culture Democratics SecurityFirst
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Rogue external MFA providers can steal passwords during logins

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage

    September 23, 2026

    Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption

    September 23, 2026

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage

    September 23, 2026

    Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption

    September 23, 2026

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.