A behind-the-scenes look at turning cybersecurity from a compliance topic into something people want to be part of.
Most cybersecurity stories start the same way. A new threat. A new tool. A new policy. A list of things people in the company must do, on top of everything else they already have to do.
This is not that story.
This is the story of how security at Levi9 went from a one-person job with no real job description to a company-wide community where people genuinely want to be involved. This is what the talk of our Headquarter Information Security Officer, Tanya van Witzenburg, at Cybersecurity Week 2026, was about. 009 Agents: How to Empower People with Security, with 009 agent being every levi niner.
If you work in security, talent, marketing or communication in your company or just someone trying to get colleagues to care about something hard to care about, we hope you can get something useful here.
The problem with enforcement
Tanya opened her talk with a question to the audience: what creates a stronger security culture — enforcement or engagement?
“Build me a web dashboard that tracks my local air quality using an API and sends me a summary via Discord.”

One could say it is a provocative question, as you need both. Indeed, you need policies, procedures, controls. These are the basics, the things that make sure people comply when someone is watching.
But the question that decides whether a company is resilient is what people do when no one is watching. Which decisions they make. Which corners they cut or do not cut. Which suspicious thing they report instead of quietly closing the tab.
That part is not built on enforcement. It is built on culture. And culture, in the way we have come to think about it, is built on community. In big organizations with generous security budgets and polished policies, breaches still happen. The gap is rarely a missing tool. The gap is usually that security lives in one corner of the company and everyone else is just trying not to get in trouble. Closing that gap is what can lead you to real resilience.

Step one: trust before anything else
Seven years ago, the role of Information Security Officer was new at Levi9. There was no playbook, no predecessor to ask. Tanya took the role anyway. More often than not, security and the rest of the organization are not on the same side. Security pushes for restrictions; organization pushes for speed, convenience and flexibility.
Both sides have the best intentions, and while everyone is trying to do the right thing, it still somehow leads to stagnation and frustration for both sides.
We made a different choice early on. Rather than positioning the security function against the organization, we positioned it with the organization. We even wrote a small manifesto for ourselves, partly inspired by the Scrum manifesto:
- Enabling a system over restricting and controlling. Restriction matters. Enabling matters more.
- Value-driven solutions over rules and documents. We have rules and documents. They serve the value, not the other way around.
- Partnership with customers over securing ourselves. We can address common risks together with our customers, or we can defend our own perimeter and leave them to defend theirs. We choose together.
- Local ownership over security team governance. The more people who carry a piece of security, the stronger the whole system gets.

In practice, this looks small but constant. When someone comes to the security team asking to use a new tool, the first answer is not “no, it is not allowed”. The first answer is, “what are you trying to achieve?” Sometimes there is a way. Sometimes there is not. Either way, the conversation has happened, and the next time, the person will come back instead of going around.
This is how you earn trust of people. This is how you get them on board when they also start thinking together with you on finding the solution.
Step two: build a team — and then keep extending it
The second realization came quickly. One person cannot do this alone. Tanya went to her manager with a sketch of three teams she thought we needed, and over time, all three came into being: Risk and Compliance Team, technical security team, and an internal red team.
Many companies stop there. But we didn’t. We kept getting more teams on board with the security topic.
A few examples from the last few years.
We could run our annual Capture the Flag hacking competition ourselves. We do not. We run it together with our internal red team. They design the challenges, they bring a different energy, they attract people who would not otherwise show up to a security thing. Both teams own the event, which is a different feeling from one team asking the other for a favor.
We ran a “Lunch with a Hacker” session — a filmed interview with a well-known hacker, face hidden, screened in our offices alongside a special lunch. We could have produced this alone. We produced it with Talent and Marketing, who had more and better ideas than we did about how to make it land.
Our annual security event last year carried the slogan Inhale. Exhale. Secure. Marketing proposed running an in-office meditation retreat as part of the build-up. That is not something a security team would come up with. It is exactly the kind of thing that creates a positive association with the topic before the event even starts.

The pattern across all of these: do not ask other teams to help with your event. Do something together that is genuinely both of yours. This makes your team bigger and stronger.
We also look for different ways to collaborate with other departments. We invite ourselves into other teams’ meetings to learn from them or to share our knowledge. We also invite people to our meeting to brainstorm with us, to share their knowledge with us. Afraid to ask, because people might say “No”? In reality, most people feel honored to share and enjoy being asked.
Step three: make it a tribe people want to join
Once the team is real and trust is in place, the work shifts. You stop pushing the topic out. You start making it attractive enough that people pull themselves toward it.
Three things have to be true.

It must be easy. Security has a reputation for being heavy — long procedures, dense documents. Some of that is unavoidable; a lot of it is not. We use short, cartoon-style refresher videos with a single takeaway at the end, and we have been surprised how often people quote those lines back to us months later. One episode ended with “if you see something, do something,” and a few days later a colleague flagged something suspicious to Tanya with exactly that phrase. Our incident notification process is similarly stripped down. People do not need to memorize seven steps. They need to remember one: tell the security team. We will walk them through the rest.
It must be fun. Even the parts you would not expect. Audits, for instance. In most organizations, the word carries a specific kind of dread. But ours have become something people actually look forward to, because the audit is the place to learn and grow for both sides. And also, because we start the audit with a joke from the Best Auditor Jokes book. External auditors’ compliment us on how relaxed and confident we are during audits. They say they enjoy working with us. That is a strange sentence to write about audits, and it is true.
The fun layer extends across the whole program. We built a persona — Agent 009 — the kind of colleague who knows everything about security, the one everyone secretly wants to be. There are 009 posters in the offices, Teams backgrounds people use on calls, a James Bond-style promotional film we shot in-house, themed events in every location, and a custom Secretini drink with its own recipe. None of this is the substance of security. All of it is the wrapper that makes the substance approachable.

It must be insightful. Fun without content is empty, and people in IT can sense the difference immediately. Our annual Secure9 event runs a full week, and we book it like we mean it — well-known speakers, authors, podcast hosts our colleagues already follow. The Capture the Flag competition is gamified and genuinely educational; people leave knowing something they did not know that morning. We even built a physical Agent 009 escape room where the puzzles teach real security lessons along the way.
When easy, fun, and insightful line up, something happens that is hard to engineer directly. People start asking to be involved. The cast of last year’s promotional film was almost entirely colleagues from outside the security team. They wanted to be in it.
The bonus ingredient
Tanya said in her talk that there are three steps. Then she admitted she had lied a little. There is a fourth, and it does not fit neatly into a framework, but is still crucial.
Add passion.

It is not a word you hear in security circles often, and it is also the thing that decides whether any of the rest works. Trust, team, and tribe are mechanics. Passion is what makes mechanics feel alive. If the people running the program are not visibly invested in it, no manifesto and no Secretini will make up the difference. The good news is that passion is contagious in both directions — if you bring it, people pick it up; if you do not, they pick that up too.
What this gets us

To get everyone on board with the security topic does not happen overnight. It takes patience to keep training the trust muscle even when nothing visible is happening, it take continuous efforts to make this topic attractive. But it worth it.
What we get back is the thing every security organization wants, and most cannot quite name. People report incidents in seconds, not after they have already tried to fix them quietly. People come to us with suggestions and sometimes with criticism — which we take as a gift, because it means the trust is real. Other teams treat security as a partner rather than a duty. New joiners arrive into a culture where caring about this stuff is normal, not nerdy.
And the work, frankly, is more fun. Which matters more than it sounds like it should.
If any of this resonates, or if your organization is doing something similar we could learn from, we would love to hear about it. Connect with Tanya on linkedin.com/in/tanyavanwitzenburg, and the rest of the security team is one introduction away.
We will keep building the tribe. There is always room for more agents.










