In my experience, the most effective security champions aren't necessarily the most technical people. They're the ones who are well-respected in their teams and have a knack for communication. Your job is to equip them with knowledge, support them, and empower them to be your voice when you're not in the room.
Now, here's a controversial opinion: I believe every cybersecurity leader should spend at least 20% of their time on champion development. This might seem like a lot, but the force multiplier effect is enormous. When security becomes part of the culture, driven by peers rather than imposed from above, that's when real change happens.
💡
Key Takeaway: Identify potential security champions in each department. Invest in their development and give them the tools to advocate for security within their teams.
4. Leverage the Power of Reciprocity
Human beings are hardwired to reciprocate. If someone does us a favor, we feel compelled to return it. As cybersecurity leaders, we can use this principle ethically to build influence.
Look for opportunities to help others achieve their goals, even if it's not directly related to security. Can you use your technical skills to automate a tedious process for the marketing team? Can you share insights from your threat intelligence that might help the product team build a better feature?
I once spent a week helping our sales team build a more secure demo environment. It wasn't strictly part of my job, but it solved a real pain point for them. Months later, when I needed their support for a major security initiative, they were eager to help. The goodwill I had built paid off in spades.
💡
Key Takeaway: Be generous with your time and expertise. Look for ways to help others succeed, and they'll be more likely to support your security initiatives when the time comes.
5. Frame Security in Terms of Business Outcomes
Too often, we frame security in terms of risk mitigation or compliance. While these are important, they don't always resonate with business leaders focused on growth and innovation. To truly influence without authority, we need to align our security goals with broader business outcomes.
For example, instead of talking about reducing the risk of a data breach, frame it in terms of protecting customer trust and brand reputation. Instead of focusing on compliance requirements, emphasize how strong security practices can be a competitive differentiator in the market.
I once worked with a company that was hesitant to invest in a comprehensive security program (as most are). Rather than hammering on risks and threats, I helped them see how a robust security posture could open up new market opportunities. We positioned security as an enabler of innovation, allowing the company to handle more sensitive data and take on higher-value clients. This reframing turned security from a cost center to a revenue driver in the eyes of leadership.
💡
Key Takeaway: Always tie your security initiatives back to business goals. Speak the language of growth, efficiency, and competitive advantage.
Putting It All Together
Influencing without authority requires a mix of emotional intelligence, strategic thinking, and persistent effort. By building trust, telling compelling stories, cultivating champions, leveraging reciprocity, and aligning with business outcomes, you can drive significant change even without formal authority.
Influence is not about manipulation or forcing your will on others - never try to do this. It's about creating a shared vision of a more secure future and inspiring others to join you in making it a reality.
I'd love to hear your thoughts and experiences. Have you used any of these strategies in your organization? What other methods have you found effective for influencing without authority in the cybersecurity realm? Share your insights in the comments below!