Wednesday
Room 1
11:40 - 12:40
(UTC+01)
Talk (60 min)
An AppSec Tale: From Zero to 250+ Champions
Every big program starts small. Four years ago, Equinor’s AppSec team set out to strengthen developer security skills by creating a Security Champion network. What began as an experiment is now a 250+ member community that shapes how software is built across the company.
This talk is the story of that journey, told from the perspective of two champions who became AppSec engineers themselves. We’ll share how the network evolved, the rituals that keep it alive, and the real-world struggles we’ve faced: distributed offices, high consultant turnover, and sustaining engagement over time.
You’ll also see how gamification and small touches like community merch helped us create belonging and visibility.
Attendees will leave with:
- A model for building an inclusive, developer-friendly champion network.
- Ideas for motivating participation without forcing compliance.
- Lessons learned from both failures and successes.
If you’ve ever wondered how to turn developers into security advocates, this session will give you both inspiration and a playbook.

