This project aims to help organizations tailor their security efforts so developers can consistently build secure software. Version 2 introduces SECUR-E, an open framework based on COM-B and DASP research, to identify whether barriers to secure development stem from capability, opportunity, or motivation. Users can then select targeted interventions. Features include self-assessment, scoring, persona guidance, team visualizations, playbooks, and progress tracking to support better security culture. Personas reflect current conditions, not fixed identities. Results should never be used for hiring, performance, or disciplinary decisions. The framework is under expert review and community testing.
Starting question
“How do I stop guessing which intervention this team needs?”
Take the assessment yourself, dry-run the scoring logic, then facilitate an aggregate-first team workshop that ends with one intervention.
In 30 minutes: Read D3’s persona reference and D6’s quick-reference matrix.
In one week: Self-assess and score 2-3 volunteer dry runs. Record every point of confusion.
In one month: Facilitate one team workshop, run the five insight triggers and launch one intervention.
Keep in mind: Aggregate before individual—always. A standard team-wide motivational session may deepen a Resistant-pattern problem.
Goal: a shared, blame-free picture of current conditions and one agreed intervention with an owner and review date.
0:00–0:10 - Framing and safety contract
0:10–0:25 - Teach COM-B and the six patterns before showing data
0:25–0:45 - Show dimension bands first, then aggregate persona-pattern distribution
0:45–1:00 - Sense-making: what is the environment telling us?
1:00–1:20 - Shortlist three interventions, select one, assign owner and review date
1:20–1:30 - Close, confirm data handling and schedule reassessment
“Today is about our conditions, not our competence. Nobody’s individual results get discussed unless that person raises them, and nothing from today touches a performance conversation.”
(Suggested facilitator framing from the Practitioner Implementation Kit)
Volunteer participation
Written confidentiality model
Sponsor signs non-evaluation commitment
Facilitator practices D3 scoring
D5 triggers checked in advance
Aggregate before individual
Open with Opportunity data
Never announce a person’s pattern
Use “pattern present in the team” language
Pick one feasible action
Limit access to the aggregate grid
Launch the action within the agreed period
Set 3- or 6-month review
Delete or retain data as agreed
Record friction and lessons
Small teams: A team may participate with four people, but persona counts must not be reported for groups of four or fewer. Use band distributions only. Any reported group or subgroup must contain at least five people.