This project aims to help organizations tailor their security efforts so developers can consistently build secure software. Version 2 introduces SECUR-E, an open framework based on COM-B and DASP research, to identify whether barriers to secure development stem from capability, opportunity, or motivation. Users can then select targeted interventions. Features include self-assessment, scoring, persona guidance, team visualizations, playbooks, and progress tracking to support better security culture. Personas reflect current conditions, not fixed identities. Results should never be used for hiring, performance, or disciplinary decisions. The framework is under expert review and community testing.
Starting question
“Is the problem skills, motivation or the environment I control?”
Review the team grid and interpretive limits, agree the confidentiality model, then sponsor rather than dominate the workshop.
In 30 minutes: Review D4’s worked team example and focus first on the Opportunity dimension.
In one week: Identify a facilitator, secure volunteer participation and sign the non-evaluation commitment.
In one month: Sponsor a workshop and own one concrete environmental change with an owner and review date.
Keep in mind: Do not request individual profiles. Low Opportunity is management information flowing upward.
Goal: a shared, blame-free picture of current conditions and one agreed intervention with an owner and review date.
0:00–0:10 - Framing and safety contract
0:10–0:25 - Teach COM-B and the six patterns before showing data
0:25–0:45 - Show dimension bands first, then aggregate persona-pattern distribution
0:45–1:00 - Sense-making: what is the environment telling us?
1:00–1:20 - Shortlist three interventions, select one, assign owner and review date
1:20–1:30 - Close, confirm data handling and schedule reassessment
“Today is about our conditions, not our competence. Nobody’s individual results get discussed unless that person raises them, and nothing from today touches a performance conversation.”
(Suggested facilitator framing from the Practitioner Implementation Kit)
Volunteer participation
Written confidentiality model
Sponsor signs non-evaluation commitment
Facilitator practices D3 scoring
D5 triggers checked in advance
Aggregate before individual
Open with Opportunity data
Never announce a person’s pattern
Use “pattern present in the team” language
Pick one feasible action
Limit access to the aggregate grid
Launch the action within the agreed period
Set 3- or 6-month review
Delete or retain data as agreed
Record friction and lessons
Small teams: A team may participate with four people, but persona counts must not be reported for groups of four or fewer. Use band distributions only. Any reported group or subgroup must contain at least five people.