From Security Champion to Engineering Security Culture: MTS Web Services Transforms DevSecOps Approach
MTS Web Services has moved away from the traditional Security Champion model toward an engineering-wide security culture that embeds DevSecOps practices into everyday work. Head of DevSecOps Ilya Sharov and DevSecOps Lead Nikolay Luzgin described the transformation in detail, explaining how the company addressed overload, shallow training, and lack of motivation that plagued the earlier program.
How the original Security Champion program operated
The company first secured internal approval, created a wiki space, and established rules requiring exactly one champion per team. Managers had to approve the additional workload, and champions were selected or appointed based on interest where possible. Entry barriers were kept low with basic DevSecOps training, and a helper system allowed champions to escalate findings to experts for triage of true versus false positives. Motivation came through internal currency redeemable for merchandise and badges, while playbooks clarified responsibilities during vulnerability handling.
Problems that emerged
Over time the single champion became the default contact for every security question, leading to role overload and diluted focus. Basic corporate courses proved inadequate for deeper skill growth, and appointed champions showed little desire to advance beyond minimum requirements. Teams also lacked clarity on exactly which security topics to learn, whether infrastructure controls or secure coding techniques.
Changes introduced
The company replaced the single-champion structure with multiple security heroes who voluntarily deepen expertise within their primary roles. A DevSecOps guild was formed inside the larger engineering community, supported by community managers who organize events. Regular activities now include meetups, workshops, case studies, and feedback sessions; the number of such events grew from a few in 2023 to 18 in 2025.
Security scan results are now visible to entire teams and tied to maturity metrics. A short DevSecOps onboarding course introduces new employees to existing tools and processes. Competency maps define role-specific tracks for developers, DevOps engineers, architects, and managers, with quarterly updates to materials and external courses adapted to internal terminology. Recognition programs highlight both individual heroes and top-performing teams, while basic training completion is linked to key performance indicators.
Results achieved
Engagement has grown organically as specialists pursue security skills for professional value rather than obligation. Product teams increasingly include secure development topics in their own events, and the topic has moved from a localized initiative to a sustained engineering practice across the organization.
Related articles
Yandex Maps Adds Upcoming Speed Limits and Camera Direction Details to Navigation
Yandex Maps has updated its navigation mode to display speed restrictions on upcoming road segments along the entire route. Drivers can now see a sequence of limits in advance, such as 80 km/h followed by 60 km/h after an interchange and then 40 km/h. The application also provides more detailed information about the two nearest traffic cameras, including the specific lane they target and whether they monitor oncoming or same-direction traffic. Voice alerts now warn users when a camera measures speed after the vehicle has already passed it. Pilot testing showed positive effects on speed limit compliance. The changes aim to make urban and highway driving more predictable by removing the need to guess restrictions or camera focus ahead.
Kaspersky Releases Corporate Version of Kaspersky Password Manager for Mid-Size and Large Organizations
Kaspersky has introduced a business edition of Kaspersky Password Manager designed for centralized credential management across medium and large enterprises. The solution generates complex passwords, stores them in encrypted vaults, and audits existing credentials for strength and exposure in data leaks. Employees only need to remember a single master password while the platform also supports storage of TOTP tokens, passkeys, corporate documents, and payment card details. Administrators gain tools to enforce password policies centrally and apply role-based access controls. Supporting statistics from Kaspersky Digital Footprint Intelligence show widespread password reuse and simplicity, with 37 percent of users merely changing letter case when recycling passwords. The company links these habits to real risk, noting that credential compromise initiated one quarter of attacks against organizations in 2025.
GitHub Experiences Major Global Outage Affecting API, Actions, Copilot and Multiple Core Services
On August 17, GitHub suffered a widespread outage that impacted nearly all major platform functions including the web interface, API, Issues, Pull Requests, Actions, Webhooks, Pages, Git Operations, and Copilot. Approximately 20% of requests to the site and API failed during peak impact, with archive and raw repository content loads reaching around 50% error rates. Corporate authentication mechanisms such as SAML and OIDC, along with SCIM and Team Sync services, were also disrupted while Codespaces remained operational. The incident began around 13:40 UTC with progressive degradation across components, prompting GitHub to identify and mitigate the root cause. Services are gradually recovering but error rates remain slightly elevated, and the incident has not yet been fully closed. Parallel issues were reported in other Microsoft services including Teams and Copilot, with unconfirmed speculation linking the event to Amazon Web Services network problems.
SASTAV and ARX ASPM PLATFORM Integrate Static Code Analysis with Application Security Risk Management
Russian developers ShiftLeft Security and ARX Security have ensured compatibility between the SASTAV SAST solution and the ARX ASPM PLATFORM. The integration allows static analysis of source code to be launched and configured directly from the ASPM platform interface. For each project, specialists can select repositories and branches, form rule sets, set scanning parameters, and establish quality gates that determine whether a product can be released with detected defects. Risk acceptance procedures are also configured within the same interface. SASTAV handles static code analysis, enabling creation and editing of rules, assignment of different check sets to individual repositories, and management of scanning parameters. ARX ASPM PLATFORM serves as a unified center for managing AppSec tools, collecting results from various analyzers, correlating related findings, assessing risks, and displaying the overall security posture of digital products. Both solutions leverage artificial intelligence at different stages: SASTAV uses it for defect verification, automatic triage, prioritization, and code change recommendations, while the ARX AI assistant determines defect statuses. The combined system reduces manual operations, accelerates DevSecOps project onboarding, and lowers the burden on AppSec teams.