Former DNC Chief Security Officers Bob Lord and Steve Tran shared at Black Hat USA 2026 how they built a security-first culture at the Democratic National Committee following the 2016 Russian hack. Lord used unconventional tactics like 'Bobmoji' stickers and a 'Security Feud' game show to drive security awareness, while also deploying Chromebooks over Windows to reduce attack surface and rolling out YubiKey hardware MFA organization-wide. Key to success was executive co-ownership — DNC Chairman Tom Perez personally called employees who hadn't enrolled in security keys. When Tran succeeded Lord in 2022, he inherited a strong foundation and focused on cloud security upgrades, a knowledge management portal, and a security risk committee. Their core message: security culture requires absurdity, executive co-ownership, and resilience-focused thinking over point-in-time threat blocking.
Questions this post answers
Why did the DNC choose Chromebooks over Windows machines for security?
Chromebooks offered a more secure and cheaper alternative to reviving aging Windows infrastructure and on-premises Active Directory. On-premises AD is a significant attack target, and replacing it with Chromebooks reduced that attack surface while also cutting hardware costs compared to upgrading the existing Windows fleet. Security teams weighing endpoint strategy decisions like this track real-world CISO reasoning on daily.dev.
What does real executive buy-in for security look like beyond just attending meetings?
True executive co-ownership means leaders take direct personal action to enforce security standards. At the DNC, Chairman Tom Perez personally called employees on their cell phones who had not enrolled in hardware security keys after the deadline — and they enrolled immediately. Lord distinguished this from mere advocacy: executives must share ownership of outcomes, not just endorse the program. CISOs making the case for leadership involvement in security programs find concrete examples like this on daily.dev.