MaximAlert

Thought Leadership

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

Dark Reading

August 7, 2026

Visit Count : 12

Black Hat USA 2026 – Las Vegas – When Bob Lord became the first chief security officer (CSO) for the Democratic National Committee (DNC) in 2018, he plastered "Bobmoji" stickers above urinals, in bathroom stalls, and on the mirrors. As employees washed their hands, avatar renderings of his face served as a security-first reminder.

To implement and maintain a strong security culture, CSOs must be willing to be "absurd," Lord told attendees during a Wednesday briefing session at Black Hat USA 2026. Lord, now consultant at Lord Consulting, and his successor, Steve Tran, detailed how the party organization built its defenses following a 2016 hack by Russian state actors and continued evolving security.

The DNC is a cyclical organization where "the idea is to win elections, not to be more secure," said Tran. But their recommendations and best practices can be applied to organizations across sectors.

Bobmojis weren't the only tactic Lord used to mold a security mindset. He also created a "Family Feud" game dupe, dubbed "Security Feud," to instill the importance of security checklists to employees. As people shouted "update software" and "use multifactor authentication" and Lord high-fived them during the game, he knew the theatrics were well worth it.

Expect the Unexpected

When Tran, now CISO at lyuno, took over the DNC CSO role in 2022, he replaced Bobmojis with bobbleheads. However, some of Lord's work didn't meet his expectations, which is commonplace when one security leader takes over for another, Tran and Lord explained. When CSOs walk into a new role, they conduct an audit to learn the environment, people, and processes. Tran was just trying to understand what Lord was thinking, which is important for any successor to examine.

They disagreed on the importance of email scanning, and Tran was perplexed by Lord's choice to use Chromebook computers. But auditing the cultural mindset to determine which routines changed how people think about security was one critical point where they're on the same page.

DNC employees didn't work with "fancy Windows machines," as he expected. Instead, they worked on Chromebooks. Tran didn't think that adoption was practical or possible, but Lord proved him wrong.

Not only did Chromebooks offer a more secure path, but they were also cheaper than trying to revive the organization's aging Windows infrastructure and Active Directory controller, explained Lord. AD on-premises is an attack magnet, he warned.

"I walked in with a certain set of expectations," said Tran, who was happy to see hardware security keys and strong multifactor authentication in place.

"You did the hardest part: getting a huge user base to enroll in YubiKeys and use it," he said, turning to Lord. "The laptops were locked down, which was amazing. You got people to patch."

On the other hand, Tran was unpleasantly surprised by the lack of email scanning. But Lord had his reasoning, and the pieces Tran thought were missing had been intentional. Lord wasn't trying to stop an attack at the moment of delivery, whether threat actors used email or SMS, but to build resilience against social engineering scams.

"It's much better to stop it at the moment of intrusion, whether they're trying to get you to install software or cough up your username and password," he said.

A CSO's goal is to make systems resilient so threat actors won't simply be able to run malware or steal sensitive credentials.

"As an executive coming into the organization, expect the unexpected," Lord said.

When the Chairman Calls, You Answer

As in many organizations, Lord faced budget constraints while working at the DNC. But he found that the chief financial officer was his "biggest ally," which made a world of difference.

And support extended even further. Tom Perez, who served as DNC chairman from 2017 to 2021, had the security team speak for the first 10 minutes of every staff meeting and committed to improving security standards.

Many of his moves surprised Lord. When he and his team rolled out security keys to everyone, Perez called one day after the deadline to see whether everyone had enrolled. When he found out that some stragglers remained, Perez called their personal cell phones to ensure they enrolled over the next couple of weeks.

However, it didn't take weeks — they enrolled immediately after getting that call from the chair.

"That's not executive buy-in or advocacy. That's co-ownership," Lord said.

When Tran took over as DNC CSO, he felt he inherited a strong security program. His job then became: How does the organization continue to move forward? With a deeply embedded security-first mindset, he focused on a cloud security upgrade, implemented a knowledge management portal, and formed a security risk committee.

"You saved me so many hard parts," Tran told Lord. "I came in to help them work with gray areas a little bit more because not everything is black and white in security."

contact