HabrJuly 29, 2026🇷🇺Translated from Russian

From Security Champion to Engineering Security Culture: MTS Web Services Transforms DevSecOps Approach

MTS Web Services has moved away from the traditional Security Champion model toward an engineering-wide security culture that embeds DevSecOps practices into everyday work. Head of DevSecOps Ilya Sharov and DevSecOps Lead Nikolay Luzgin described the transformation in detail, explaining how the company addressed overload, shallow training, and lack of motivation that plagued the earlier program.

How the original Security Champion program operated

The company first secured internal approval, created a wiki space, and established rules requiring exactly one champion per team. Managers had to approve the additional workload, and champions were selected or appointed based on interest where possible. Entry barriers were kept low with basic DevSecOps training, and a helper system allowed champions to escalate findings to experts for triage of true versus false positives. Motivation came through internal currency redeemable for merchandise and badges, while playbooks clarified responsibilities during vulnerability handling.

Problems that emerged

Over time the single champion became the default contact for every security question, leading to role overload and diluted focus. Basic corporate courses proved inadequate for deeper skill growth, and appointed champions showed little desire to advance beyond minimum requirements. Teams also lacked clarity on exactly which security topics to learn, whether infrastructure controls or secure coding techniques.

Changes introduced

The company replaced the single-champion structure with multiple security heroes who voluntarily deepen expertise within their primary roles. A DevSecOps guild was formed inside the larger engineering community, supported by community managers who organize events. Regular activities now include meetups, workshops, case studies, and feedback sessions; the number of such events grew from a few in 2023 to 18 in 2025.

Security scan results are now visible to entire teams and tied to maturity metrics. A short DevSecOps onboarding course introduces new employees to existing tools and processes. Competency maps define role-specific tracks for developers, DevOps engineers, architects, and managers, with quarterly updates to materials and external courses adapted to internal terminology. Recognition programs highlight both individual heroes and top-performing teams, while basic training completion is linked to key performance indicators.

Results achieved

Engagement has grown organically as specialists pursue security skills for professional value rather than obligation. Product teams increasingly include secure development topics in their own events, and the topic has moved from a localized initiative to a sustained engineering practice across the organization.

Related articles

AntiMalwareOther

Google Play Store to Add Pause and Resume Option for App Downloads

Google is preparing a long-awaited feature for the Play Store that will let Android users pause app downloads and resume them later without losing progress. The capability was discovered by Android Authority researchers while examining the code of Play Store version 53.0. Currently the store only allows users to cancel a download entirely, but the new update will introduce a dedicated Pause button next to each active download. Once paused, the item remains visible in the built-in download manager, allowing users to resume directly from the list without searching for the app again. The function is intended to help users manage bandwidth, conserve mobile data, or delay large game downloads until a Wi-Fi connection is available. Although Google has not yet made an official announcement, the feature is already functional in testing, suggesting a release may arrive sooner than the previously indicated 2026 timeframe.

AntiMalwareOther

Microsoft Pledges Performance Improvements for Windows 11 on 8GB RAM Devices

Microsoft has announced plans to optimize Windows 11 specifically for computers equipped with 8GB of RAM, addressing long-standing complaints about system resource consumption on budget hardware. Corporate Vice President Mark Linton revealed the initiative during an Acer presentation at IFA 2026, highlighting ongoing work to improve core system components without providing specific metrics or timelines. The effort falls under the internal Windows 11 K2 project, which targets faster File Explorer and search functionality, fewer update-related crashes, better overall responsiveness, and expanded interface customization options including the return of movable taskbar positioning. These changes come at a time when AI-powered features are increasingly integrated into Windows, raising concerns about performance on entry-level laptops that often ship with soldered 8GB memory configurations. Microsoft intends to roll out the improvements gradually through standard Windows updates, focusing on both home users and broader device compatibility.

SecuritylabOther

Prioritizing Account Protection: Moving From Job Titles to Real Business Risks

When budgets are limited, companies must decide whether to protect C-level executives first or focus on employees handling critical data such as accountants, database administrators, and developers. The article outlines four practical scenarios that determine protection priorities instead of relying on corporate hierarchy. These include perimeter defense through VPN access, safeguarding email and documents against phishing, addressing unique user cases like offline executive work, and managing contractor accounts with mandatory multi-factor authentication. A protection matrix maps assets such as commercial information, infrastructure access, and privileged accounts to specific threats and controls including 2FA, DLP systems, and PAM solutions. The piece also highlights three common mistakes, such as treating tool deployment as the finish line, underestimating pilot preparation, and attempting to secure everything simultaneously. It concludes with actionable first steps: inventory accounts, disable unused ones, enable two-factor authentication for high-risk users, and expand coverage gradually.

AntiMalwareOther

Russian Voice Traffic Surges 25-30% as Mobile Internet Usage Falls for First Time

In the first half of 2026, voice traffic in Russian mobile networks grew by 25-30 percent while mobile internet consumption declined 10-12 percent for the first time. Home broadband traffic rose 18-20 percent as users shifted conversations to traditional voice calls and moved video, AI services, and other data-heavy applications to fixed Wi-Fi connections. Experts attribute the changes primarily to mobile internet restrictions and difficulties accessing foreign messengers, prompting a return to basic phone functionality. Additional load on wired networks comes from IoT devices including surveillance cameras, sensors, and smart watches. In May, traffic generated by AI bots exceeded the volume of data created by human users for the first time. Analysts forecast that by the end of 2026 mobile internet traffic will drop another 5-10 percent, while fixed broadband will grow 15-20 percent and voice call volumes will increase 10-15 percent.