From Security Champion to Engineering Security Culture: MTS Web Services Transforms DevSecOps Approach
MTS Web Services has moved away from the traditional Security Champion model toward an engineering-wide security culture that embeds DevSecOps practices into everyday work. Head of DevSecOps Ilya Sharov and DevSecOps Lead Nikolay Luzgin described the transformation in detail, explaining how the company addressed overload, shallow training, and lack of motivation that plagued the earlier program.
How the original Security Champion program operated
The company first secured internal approval, created a wiki space, and established rules requiring exactly one champion per team. Managers had to approve the additional workload, and champions were selected or appointed based on interest where possible. Entry barriers were kept low with basic DevSecOps training, and a helper system allowed champions to escalate findings to experts for triage of true versus false positives. Motivation came through internal currency redeemable for merchandise and badges, while playbooks clarified responsibilities during vulnerability handling.
Problems that emerged
Over time the single champion became the default contact for every security question, leading to role overload and diluted focus. Basic corporate courses proved inadequate for deeper skill growth, and appointed champions showed little desire to advance beyond minimum requirements. Teams also lacked clarity on exactly which security topics to learn, whether infrastructure controls or secure coding techniques.
Changes introduced
The company replaced the single-champion structure with multiple security heroes who voluntarily deepen expertise within their primary roles. A DevSecOps guild was formed inside the larger engineering community, supported by community managers who organize events. Regular activities now include meetups, workshops, case studies, and feedback sessions; the number of such events grew from a few in 2023 to 18 in 2025.
Security scan results are now visible to entire teams and tied to maturity metrics. A short DevSecOps onboarding course introduces new employees to existing tools and processes. Competency maps define role-specific tracks for developers, DevOps engineers, architects, and managers, with quarterly updates to materials and external courses adapted to internal terminology. Recognition programs highlight both individual heroes and top-performing teams, while basic training completion is linked to key performance indicators.
Results achieved
Engagement has grown organically as specialists pursue security skills for professional value rather than obligation. Product teams increasingly include secure development topics in their own events, and the topic has moved from a localized initiative to a sustained engineering practice across the organization.
Related articles
From Scanner Overload to Manual Insight: A Bug Bounty Hunter's Journey
A young researcher recounts his transition from automated scanning to thoughtful manual analysis in Bug Bounty programs. After completing a broad information security course covering cryptography, networks, Docker, databases, and OWASP Top 10, he initially approached real-world targets with the same scanner-heavy mindset used in labs. Months of fruitless results led to burnout and a six-month break working in construction. Returning with a new focus, he studied hundreds of public HackerOne reports to understand researcher reasoning and anomaly detection. This shift enabled his first valid, unreported finding and fundamentally changed his methodology. Today the 18-year-old university student balances Bug Bounty with reconnaissance, machine learning, and personal projects while emphasizing deep application understanding over tool volume.
Bypassing Paid Export on AI 3D Generation Sites via Browser Network Inspection
A detailed walkthrough shows how users can retrieve AI-generated 3D models in GLB format from services that normally require a paid subscription for export. The method relies on opening the browser developer console, filtering network requests for .glb files after model generation completes, and opening the intercepted asset in a new tab. Examples using Tripo3D and Hi3D demonstrate that the generated model and textures are already present on the client side even when the export button remains disabled. Additional steps address compatibility issues with 3ds Max by recommending conversion through gltf.report with Draco compression before import. The technique also covers post-processing in ZBrush for auto-retopology and format conversion to OBJ. The article notes that such workarounds exist because many AI platforms limit free exports while still rendering full models locally.
National Platform Max Begins Testing Advertising Tools to Monetize User Attention
The Russian national platform Max has started internal testing of new advertising instruments designed to convert user attention into sellable ad inventory. According to the company's press service, the tests are already underway inside the application, although the exact placement, visual format, and eligibility criteria for advertisers remain undisclosed. The move marks a significant shift for the platform, which previously operated without visible commercial advertising. Observers note that Max could become one of the largest domestic digital advertising channels if the tests prove successful. No timeline has been given for a public rollout or for the publication of detailed advertising policies.
Yandex Drops Earbuds Under X-Ray Microtomography: Detailed Internal Analysis of First AI-Powered TWS Headphones
Engineers used non-destructive X-ray microtomography to examine Yandex Drops, the company's first TWS earbuds featuring the Alice AI voice assistant. The scan revealed an eight-layer HDI PCB, three microphones per earbud arranged in a dual feedforward plus feedback ANC configuration, an 11 mm driver, and a QFN-packaged SoC with NPU. No hardware disconnect point was identified in the microphone signal path within visually accessible traces, connectors, and vias. Battery dimensions, coil windings in the case, and internal flex routing were measured directly from calibrated voxel data. The study also confirmed contact-based charging via spring-loaded claw contacts and a Hall-effect sensor in the case lid. The work demonstrates how industrial micro-CT can support hardware security reviews without destroying the sample.