From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

The Democratic National Committee’s (DNC) journey to building a security-first culture is a fascinating case study in what it takes to prioritize cybersecurity in a complex organization. At the heart of this story are two chief security officers, Bob Lord and Steve Tran, who have shared their experiences and insights on how they cultivated a strong security mindset within the party.

When Bob Lord took over as CSO in 2018, he knew that implementing a robust security culture would require more than just technical solutions. He needed to get his employees engaged and invested in security best practices. To achieve this, Lord employed a range of creative tactics, from plastering “Bobmoji” stickers above urinals and bathroom stalls to creating a “Security Feud” game, a parody of the popular TV show Family Feud, to make security checklists fun and memorable.

These unorthodox approaches may have raised eyebrows, but they were effective in getting people on board with security. Lord’s successor, Steve Tran, who took over as CSO in 2022, has continued this tradition by introducing bobbleheads – yes, you read that right – to reinforce the importance of security protocols.

One common thread running through both men’s experiences is the need for executive support and a willingness to be adaptable. When Tran walked into the role, he expected to find advanced security measures in place, but was surprised to discover that Chromebooks were being used instead of Windows machines. Initially perplexed by this choice, Tran soon came to appreciate how Lord had deliberately opted for Chromebooks as a more secure and cost-effective solution.

This anecdote highlights an important lesson: when it comes to building a strong security culture, there’s often no one-size-fits-all approach. What works in one organization may not work in another, and CSOs need to be willing to adapt and learn from their predecessors. In the case of the DNC, Lord’s willingness to think outside the box and challenge conventional wisdom paid off.

The key takeaway from this story is that building a security-first culture requires more than just technical expertise – it demands creativity, flexibility, and a deep understanding of human behavior. By recognizing that security is not just about technology, but also about people and processes, organizations can create a culture where cybersecurity is truly integrated into every aspect of their operations.

As Bob Lord so aptly put it, “When the Chairman calls, you answer – and when it comes to security, you need to be prepared for anything.” His words serve as a reminder that building a strong security culture requires constant vigilance, creativity, and a willingness to adapt in the face of changing threats.


Source: Dark Reading — 2026-08-06