SCW Icons
hero bg no divider
Case Studies

Wie Colgate-Palmolive die Sicherheitskompetenzen der Entwickler verbesserte und eine sichere Programmierkultur schuf

Published Jun 07, 2023
Last updated on Mar 09, 2026

TL;TR

About Colgate-Palmolive

Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.

Situation

Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.

Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:

“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."

But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.

“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”

Action

Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.

“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”

Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.

Results

According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”

Key takeaways

  1. Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
  2. Using an SSO tool such as Okta to gate the code repository incentivizes the team.  Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.  
  3. Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.

Bild eines Monitors mit dem Text der Fallstudie
Bild eines Monitors mit dem Text der Fallstudie
PDF herunterladen
Ressource ansehen
PDF herunterladen
Ressource ansehen

Erfahren Sie, wie der Einzelhandelsriese Colgate-Palmolive während seiner digitalen Transformation seine Anwendungssicherheit neu gestaltet hat. Angesichts der Herausforderungen im Bereich der sicheren Codierung haben sie ihren Ansatz erneuert, indem sie gebündeltes, kontextbezogenes Lernen in den Entwickler-Workflow integriert haben.

Interessiert an mehr?

learn more

Secure Code Warrior ist für Ihr Unternehmen da, um Ihnen zu helfen, Code während des gesamten Softwareentwicklungszyklus zu sichern und eine Kultur zu schaffen, in der Cybersicherheit an erster Stelle steht. Ganz gleich, ob Sie AppSec-Manager, Entwickler, CISO oder jemand anderes sind, der sich mit Sicherheit befasst, wir können Ihrem Unternehmen helfen, die mit unsicherem Code verbundenen Risiken zu reduzieren.

Eine Demo buchen
Teilen auf:
linkedin brandsSocialx logo
Autor
Published Jun 07, 2023

Teilen auf:
linkedin brandsSocialx logo
Bild eines Monitors mit dem Text der Fallstudie
Bild eines Monitors mit dem Text der Fallstudie

TL;TR

About Colgate-Palmolive

Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.

Situation

Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.

Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:

“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."

But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.

“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”

Action

Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.

“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”

Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.

Results

According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”

Key takeaways

  1. Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
  2. Using an SSO tool such as Okta to gate the code repository incentivizes the team.  Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.  
  3. Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.

PDF herunterladen
Ressource ansehen
PDF herunterladen
Ressource ansehen

Füllen Sie das unten stehende Formular aus, um den Bericht herunterzuladen

Wir bitten um Ihre Erlaubnis, Ihnen Informationen zu unseren Produkten und/oder verwandten Themen rund um sichere Codierung zuzusenden. Wir behandeln Ihre persönlichen Daten stets mit größter Sorgfalt und verkaufen sie niemals zu Marketingzwecken an andere Unternehmen.

Einreichen
scw success icon
Danke für den Download.
scw error icon
Um das Formular abzusenden, aktivieren Sie bitte „Analytics“ -Cookies. Wenn Sie fertig sind, können Sie sie jederzeit wieder deaktivieren.
Bild eines Monitors mit dem Text der Fallstudie

TL;TR

About Colgate-Palmolive

Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.

Situation

Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.

Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:

“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."

But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.

“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”

Action

Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.

“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”

Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.

Results

According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”

Key takeaways

  1. Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
  2. Using an SSO tool such as Okta to gate the code repository incentivizes the team.  Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.  
  3. Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.

Webinar ansehen
Fangen Sie an
learn more

Klicken Sie auf den Link unten und laden Sie das PDF dieser Ressource herunter.

Secure Code Warrior ist für Ihr Unternehmen da, um Ihnen zu helfen, Code während des gesamten Softwareentwicklungszyklus zu sichern und eine Kultur zu schaffen, in der Cybersicherheit an erster Stelle steht. Ganz gleich, ob Sie AppSec-Manager, Entwickler, CISO oder jemand anderes sind, der sich mit Sicherheit befasst, wir können Ihrem Unternehmen helfen, die mit unsicherem Code verbundenen Risiken zu reduzieren.

Bericht ansehenEine Demo buchen
PDF herunterladen
Ressource ansehen
Teilen auf:
linkedin brandsSocialx logo
Interessiert an mehr?

Teilen auf:
linkedin brandsSocialx logo
Autor
Published Jun 07, 2023

Teilen auf:
linkedin brandsSocialx logo

TL;TR

About Colgate-Palmolive

Colgate-Palmolive Company is a marquis consumer products brand known and loved across households everywhere. Despite being more than two centuries old, they are an innovative growth company leveraging digital to reimagine a healthier future for people, their pets, and the planet.

Situation

Colgate-Palmolive, just like nearly every other organization, is going through a digital transformation to better serve its customers, and this has led to a shift in how the organization approaches application security.

Alex Schuchman, CISO at Colgate-Palmolive, puts it this way:

“It is very important to us that we are protecting our customer’s data and therefore are able to build trust—not just in our products but in the digital interactions our customers have with us."

But for Alex, the challenge was to secure the root source of potential customer data breaches—the code itself.

“Working on the build side of applications was really helpful when I made the switch over to my role as CISO. I understand the pain of getting tickets back from AppSec or the frustration of missing deadlines because of re-work. As a result, my goal as CISO hasn't just been increasing security in the software development lifecycle, but also streamlining how it is implemented.”

Action

Colgate-Palmolive approached this challenge by breaking up its security training into smaller, bite-sized chunks. This made it more palatable for developers so they could fit it into their workflow, instead of the long, monolithic compliance training they were used to. By leveraging Secure Code Warrior’s agile, in-context approach to secure code learning, developers were able to understand vulnerabilities in the context of their real-life projects – leading to higher engagement and long-term retention of secure coding skills.

“I wanted to roll out these best practices while keeping the developers engaged,” says Alex. “We still have mandated critical parts of the program but keeping the training manageable and listening to developer feedback has helped the program be successful.”

Colgate-Palmolive implemented an Okta workflow that gates the GitHub repository, allowing only developers who've passed specific SCW assessments access for pull requests, as depicted in the diagram below.

Results

According to Alex, “We understood that to optimize for success we needed to have our developers on-board from the start. So we made sure the developers knew they would be a critical part of the success of the program. As a result, we found that there was a much better relationship between our security team and our developers, and it really felt like we were working together as a team on the program. We are continuing to expand and scale the security maturity program, building on the success we have already enjoyed.”

Key takeaways

  1. Clearly define program goals and emphasize developer input and engagement. Developers are more likely to buy-in to a secure code learning program that is built into their workflow and integrated with the dev tools they use every day.
  2. Using an SSO tool such as Okta to gate the code repository incentivizes the team.  Only developers with a passing score on specific SCW courses and assessment are permitted to make pull requests.  
  3. Over time, build a security culture that promotes a strong working relationship between AppSec and Development teams.

Inhaltsverzeichniss

PDF herunterladen
PDF herunterladen
Ressource ansehen
Interessiert an mehr?

learn more

Secure Code Warrior ist für Ihr Unternehmen da, um Ihnen zu helfen, Code während des gesamten Softwareentwicklungszyklus zu sichern und eine Kultur zu schaffen, in der Cybersicherheit an erster Stelle steht. Ganz gleich, ob Sie AppSec-Manager, Entwickler, CISO oder jemand anderes sind, der sich mit Sicherheit befasst, wir können Ihrem Unternehmen helfen, die mit unsicherem Code verbundenen Risiken zu reduzieren.

Eine Demo buchenHerunterladen
Teilen auf:
linkedin brandsSocialx logo
Ressourcen-Hub

Ressourcen für den Einstieg

Mehr Beiträge
Ressourcen-Hub

Ressourcen für den Einstieg

Mehr Beiträge