DiscoverThe Security Champions PodcastMark McMillan - Leading with the Carrot: Building Security Culture, Not Just Compliance
Mark McMillan - Leading with the Carrot: Building Security Culture, Not Just Compliance

Mark McMillan - Leading with the Carrot: Building Security Culture, Not Just Compliance

Update: 2025-11-05
Share

Description

Mark McMillan has been building and leading Information Security Champions programs for over five years and has spent nearly a decade shaping cybersecurity culture at Rocket. He's passionate about creating programs that empower, not punish, and help people understand their role in keeping data secure.

In this episode of The Security Champions Podcast, Mark shares his journey into the field and what he has learned about fostering engaging and supportive security programs. He contrasts the outdated “stick” approach with a more empowering “carrot” method that fosters trust, ownership, and lasting behavior change. He breaks down how Champions Programs act as powerful networks of internal advocates, strategies for scaling and sustaining them over time, and the importance of continuous improvement and community support.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Podcast sponsored by Security Journey, Secure Coding Training for Developers and Everyone in the SDLC. Learn more at securityjourney.com.

FOLLOW US to stay up-to-date with new content!


Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Mark McMillan - Leading with the Carrot: Building Security Culture, Not Just Compliance

Mark McMillan - Leading with the Carrot: Building Security Culture, Not Just Compliance

Dustin Lehr