How Colgate-Palmolive boosted developer security skills and created a secure coding culture
TL;TR
About Colgate-Palmolive
Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.
Situation
Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.
Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:
“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."
But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.
“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”
Action
Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.
“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”
Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.
Results
According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”
Key takeaways
- Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
- Using an SSO tool such as Okta to gate the code repository incentivizes the team. Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.
- Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.
Discover how retail giant Colgate-Palmolive reshaped its application security during its digital transformation journey. Facing challenges in secure coding, they innovated their approach by integrating bite-sized, in-context learning into the developer workflow.
Secure Code Warrior is here for your organization to help you secure code across the entire software development lifecycle and create a culture in which cybersecurity is top of mind. Whether you’re an AppSec Manager, Developer, CISO, or anyone involved in security, we can help your organization reduce risks associated with insecure code.
Book a demoTL;TR
About Colgate-Palmolive
Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.
Situation
Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.
Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:
“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."
But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.
“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”
Action
Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.
“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”
Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.
Results
According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”
Key takeaways
- Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
- Using an SSO tool such as Okta to gate the code repository incentivizes the team. Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.
- Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.
TL;TR
About Colgate-Palmolive
Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.
Situation
Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.
Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:
“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."
But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.
“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”
Action
Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.
“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”
Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.
Results
According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”
Key takeaways
- Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
- Using an SSO tool such as Okta to gate the code repository incentivizes the team. Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.
- Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.
Click on the link below and download the PDF of this resource.
Secure Code Warrior is here for your organization to help you secure code across the entire software development lifecycle and create a culture in which cybersecurity is top of mind. Whether you’re an AppSec Manager, Developer, CISO, or anyone involved in security, we can help your organization reduce risks associated with insecure code.
View reportBook a demoTL;TR
About Colgate-Palmolive
Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.
Situation
Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.
Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:
“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."
But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.
“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”
Action
Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.
“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”
Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.
Results
According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”
Key takeaways
- Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
- Using an SSO tool such as Okta to gate the code repository incentivizes the team. Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.
- Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.
Table of contents
Secure Code Warrior is here for your organization to help you secure code across the entire software development lifecycle and create a culture in which cybersecurity is top of mind. Whether you’re an AppSec Manager, Developer, CISO, or anyone involved in security, we can help your organization reduce risks associated with insecure code.
Book a demoDownloadResources to get you started
Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise
The Secure-by-Design movement is the future of secure software development. Learn about the key elements companies need to keep in mind when they think about a Secure-by-Design initiative.
DigitalOcean Decreases Security Debt with Secure Code Warrior
DigitalOcean's use of Secure Code Warrior training has significantly reduced security debt, allowing teams to focus more on innovation and productivity. The improved security has strengthened their product quality and competitive edge. Looking ahead, the SCW Trust Score will help them further enhance security practices and continue driving innovation.
Resources to get you started
Trust Score Reveals the Value of Secure-by-Design Upskilling Initiatives
Our research has shown that secure code training works. Trust Score, using an algorithm drawing on more than 20 million learning data points from work by more than 250,000 learners at over 600 organizations, reveals its effectiveness in driving down vulnerabilities and how to make the initiative even more effective.
Reactive Versus Preventive Security: Prevention Is a Better Cure
The idea of bringing preventive security to legacy code and systems at the same time as newer applications can seem daunting, but a Secure-by-Design approach, enforced by upskilling developers, can apply security best practices to those systems. It’s the best chance many organizations have of improving their security postures.
The Benefits of Benchmarking Security Skills for Developers
The growing focus on secure code and Secure-by-Design principles requires developers to be trained in cybersecurity from the start of the SDLC, with tools like Secure Code Warrior’s Trust Score helping measure and improve their progress.
Driving Meaningful Success for Enterprise Secure-by-Design Initiatives
Our latest research paper, Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise is the result of deep analysis of real Secure-by-Design initiatives at the enterprise level, and deriving best practice approaches based on data-driven findings.