From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

The Democratic National Committee’s (DNC) cybersecurity journey is a testament to the power of creating a security-first culture within an organization. Over the past few years, the party has undergone significant transformations in its approach to protecting itself from cyber threats. Two key figures behind this shift are former Chief Security Officers (CSOs), Bob Lord and Steve Tran, who shared their insights during Black Hat USA 2026.

When Lord took over as CSO in 2018, he realized that instilling a strong security mindset within the organization required more than just technical measures. To drive home the importance of security checklists, he created a “Security Feud” game, where employees shouted out best practices like “update software” and “use multifactor authentication.” This lighthearted approach not only engaged employees but also helped to create a culture that prioritized cybersecurity.

Tran, who succeeded Lord in 2022, built upon this foundation by introducing his own unique approach. In place of Bobmojis, he opted for bobbleheads – a nod to the playful yet effective way security was being communicated within the organization. Both CSOs agree that creating a security-first culture requires executive support and a willingness to think outside the box.

One area where Tran differed from Lord was in email scanning. While Lord had intentionally chosen not to implement email scanning, citing the need for resilience against social engineering scams, Tran was initially perplexed by this decision. However, he came to understand that Lord’s approach was focused on building systems that could withstand cyber threats rather than just blocking them at the point of delivery.

The DNC’s journey also highlights the importance of flexibility and adaptability in cybersecurity leadership. As Tran took over from Lord, he conducted an audit to learn more about the environment, people, and processes within the organization. He discovered that employees were working on Chromebooks, which was a departure from his own expectations. However, Lord explained that this choice had been made with security in mind – Chromebooks offered a more secure path at a lower cost than revamping their aging Windows infrastructure.

The takeaways from the DNC’s experience are clear: creating a security-first culture requires a willingness to be creative and flexible, as well as executive support. It also highlights the need for CSOs to audit not just technical systems but also cultural mindsets to determine which routines change how people think about security.

As Lord so aptly put it during his session at Black Hat USA 2026, “When you walk into an organization, expect the unexpected.” By adopting this mindset and embracing a willingness to adapt, organizations can build strong security cultures that prioritize resilience and preparedness in the face of ever-evolving cyber threats.


Source: Dark Reading — 2026-08-06