The Trust Problem in Cybersecurity — and How to Fix It
Ross McKerchar, CISO at Sophos, joins Alan Shimel on Techstrong TV to talk about why trust has become the most important — and most underdeveloped — currency in cybersecurity. Drawing on 19 years inside Sophos and findings from the brand-new 2026 Sophos Trust Reality Report (more than 5,000 organizations across 17 countries), Ross explains why customers struggle to assess vendor trustworthiness and what should replace today’s broken supply chain questionnaires.
The conversation covers the breadth of the Sophos portfolio — from endpoint and email to firewall and one of the industry’s largest MDR businesses, with more than 30,000 customers — and dives into the radical transparency approach behind Sophos’s Pacific Rim report, the Secure by Design tailwind, and why “verifiable artifacts of maturity” like wide-scope bug bounties, fast and technical incident communication, and a credible CNA/CVE program tell you more about a vendor than any survey ever will.
Ross also shares why SBOMs remain a great idea that most buyers cannot yet use effectively, why 62% of respondents now question their vendors’ trustworthiness, and what data point in this year’s report wasn’t on his bingo card.
Learn more at https://www.sophos.com
Transcript
Hey everyone, welcome back here to another Techstrong TV interview. My next guest is Ross McKerchar, and Ross is the CISO over at Sophos, and he comes to us today. I'm assuming you're coming to us from the UK today, Ross, yeah?
Yeah. Absolutely. Based in rainy Bristol right now.
I'm sorry to hear that. Well, right now I'm in sunny south Florida, Boca Raton, but I'm headed to Orlando and Dallas. It's conference season.
I seem to be in a different city every other week or every other day. Anyway, Ross, CISO at Sophos is a big position, right? I would imagine you've had quite a career leading up to this one.
Why don't you share, if you don't mind, with our audience, a little bit of your kind of journey? Yeah, absolutely. To be honest, I don't have much of a career prior to Sophos because I've been here for 19 years come September.
That's fantastic. Yeah. Fantastic, man.
It's been quite the journey. Unheard of today, right? Yeah, absolutely.
For a CISO to have not had such a big incident in 19 years that they get turfed out is quite a rarity. Well, you're being humble. I'm sure there's more to it than that.
But you know what? Give us your background, how you came to be at Sophos 19 years, and kind of what your internal journey has been. Yeah, absolutely.
Yeah, I started at Sophos because I really wanted to specialize in cybersecurity. " And I thought, well, obviously a cybersecurity company is going to be a priority there. Turns out 19 years ago, I was actually partially wrong.
I got a job at Sophos, and I realized very quickly there was no security team. So it was just, which is actually quite- But you know what? That's not unusual.
It's the old mechanic never takes care of his car kind of thing. That's right. Yep.
Yeah. Yeah. So Sophos was- I started a security company in 2001, or I co-founded one, and it was a similar thing.
We didn't really have an internal security team. We were so busy trying to get product out. That's right, yeah.
And we were a much smaller company back then, obviously, as well. Mm-hmm. So it actually turned out to be a great thing for me because I had the opportunity to position myself to lead the security team of one, which I did within a couple of years of arriving, and essentially I've been kind of in the same role ever since.
But as you can imagine, as the company's grown, we went public on the London Stock Exchange, and we went private again. We've had all sorts. So, the company's changed a huge amount.
We were probably only four or 500 employees back then. We're now about 5,000, 5 and a half thousand. So, yeah, absolutely, very exciting journey and I've essentially been leading the team ever since that day 19 years ago when I joined.
Fantastic. And as I said, almost unheard of today for one person to be right that long, so congratulations to you. You mentioned a little bit about Sophos being on a bit of its own journey, right?
We didn't call it cybersecurity, let's be real. It was InfoSec- Exactly, yeah. when I first got involved in information security almost 30 years ago.
And then Sophos came on. Originally, I think it was more network perimeter kind of security. And then when UTMs burst on the scene, I forgot what company Sophos had acquired, but it was like an open source based kind of- Astaro.
Yeah, that was Astaro. Yeah, I was there for that one. Astaro, yeah.
Yeah. I loved Astaro, and Sophos did great things with it. It was a great product.
And then, of course, Sophos spread out into endpoint security, and- It was actually the other way around. We started with endpoint- Excuse me. Right ...
and then we- You were originally endpoint, then you went to the perimeter. Yeah. That's right.
Yeah. That's right. Yep.
But as you said, there's been a lot of water under that bridge since then. And today, Sophos is really a full-featured security company. Give people a sense of the breadth and depth of the Sophos offering.
Absolutely. Yeah. So our roots really are endpoint security, and then we got into email security first after- Mm-hmm ...
endpoint. That kind of got us into that network security business. We sold some gateway email appliances, web appliances, then we bought Astaro, which got us into the firewall market.
And to this day, endpoint and firewall are a couple of our largest products. But more recently, we've very much expanded. The tip of the spear there is our MDR service.
So we think we're one of the largest MDR businesses in the world, in fact, if not the largest. We have over 30,000 MDR customers. Wow.
And they consume a whole range of services from us. So we have identity-related products. We have risk management, we have vulnerability management, as well as email security, workspace protection.
Basically, the full suite that most companies need. Excellent. You mentioned 30,000 customers on MDR alone.
It gives Sophos kind of a unique seat vantage point into what is the state of security, what are things that are working, what are things that are not working, what people are doing, how they're feeling. You guys recently came out with your annual 2026 Trust Reality report, right? Before we get into the findings of this year's report, if you would, mind, Ross, give people a sense of what is the report about, how many years have you been doing it, that kind of thing.
Yeah. So, we haven't been talking externally about trust for that long. It's actually an initiative that I really kicked off a couple of years ago with some of the product managers and marketing team.
We recognized that trust was an emerging problem within cybersecurity. We were seeing so many cybersecurity companies get breached, or their products get compromised, resulting in customers who, the very thing that they bought to keep them safe was actually the thing that harmed them. And we thought that was a problem for the whole industry.
And Sophos wasn't perfect with this either. We've had some serious vulnerabilities in our products. Who has this?
Yeah. Absolutely. One thing that we did that was maybe a bit different, and this really kind of fired the starting gun on the way that we really focused on trust in our external messaging, and that was our Pacific Rim report.
So, that was a large report where we described five, if you like, six years of back and forth we did with a very well-resourced threat actor based in China who's continually attacking our products. We took a really radical approach with that report where we just went with full transparency. We disclosed a level of detail that I don't think any other vendor has disclosed into the attacks that are going on by very well-resourced nation-state actors against our devices, all the way through to actually working with the FBI and the DOJ to get some indictments, an indictment against a specific company.
Sorry, sanctions against a specific company, an indictment against an individual, a reward with the FBI. So, that was when we realized that not only was it the right thing to do to go to that level of transparency, but it actually really resonated in the market. We were very nervous about going public about those incidents.
But every single time that we shared more with our customers and the market, we got positive feedback. Of course, there were a few people who'd kind of take low shots at us, but the resounding vibe we were getting from our customers was, doesn't matter if you've had an incident, it's how you dealt with it that matters. And that allowed us to just double down on that messaging really heavily.
We also had some tailwinds from things like the Secure by Design initiative that CISA kicked off a couple of years back. Yes. That gave us a nice framework to kind of talk about all the good things that we were doing as well.
And then it culminating in the report that we're talking about today, where we went out to over 5,000 organizations across 17 countries and- Wow ... got their view on how do they assess trust, what's important to them when they're assessing a vendor, and questions like that. Love it.
And, I just want to emphasize and kind of tie a bow on what you said. Any company, I don't care whether they're a security company or not a security company, any company that tells you they haven't been victimized, attacked, A, is either blind to what's going on or lying. Right?
Yeah. That's just the nature of today. And then certain companies, they just have a bigger target on their back.
Right? When you're a security company providing security to other organizations, almost by definition, you have a bigger target on your back. Right?
And when you're one of the leaders in it, like Sophos, well, that's a really big target on your back. So, you know the old saying, it's not whether you get knocked down, it's how you stand back up that counts. Yeah.
That's exactly it. And I absolutely 100% agree with you. If you haven't had a security incident, then that is a sign of immaturity, not maturity, because everybody has- Yeah.
No, it's something to be worried about, right? Yeah. Right.
Yeah, exactly. " And you know- Right ... if you don't write zero on that form, you're in for a whole load of grief, which can only be- Right.
And then it's time- ... punishment and behavior ... it's time for the proctology exam, right?
Yeah. But it happens. But I hear you.
It's the truth. And look, I have a lot of friends who've founded companies that I've been involved in helping. They've come to me sometimes, again, nation state style breaches, and said, "Should we disclose?
" And my attitude is, the truth will set you free. Right? The more transparency, the better.
So kudos to Sophos for that. Ross, let's jump into this year's report, though. Right?
Over 5,000 people or org surveyed. I always like to ask, what are the key findings? Give me three key things that people should take out of this.
Yeah. Absolutely. So I think the top finding is that trust and verifiable artifacts of trust came in as the very top, most important thing for both the IT professionals and the executives at these surveyed companies.
I was super excited when I saw that result because it really verified something that I kind of felt for quite a few years, and to see it actually reflected in the data was really, really interesting. But the challenge is, and 80% of people said this, was that it's really hard to accurately vet a new vendor. Like, understandingwhat makes a vendor trustworthy wasn't there.
So we have everyone recognizing that trust is really important, but they don't know how to assess it. And then over half the leaders said that they were anxious. They were very anxious about their supply chain.
This opacity was breeding concerns, and they didn't know how to handle it. So yeah, it just showed how murky and confusing the situation is, resulting in that pressure and that anxiety. Yeah.
No, and my experience in speaking with execs around that is they know it when they see it. They recognize it when they see it, but it's hard for them to quantify trust. Right?
Yes. What is the threshold before I trust you, right? Yeah.
Yeah, absolutely. It's more of a feeling in your stomach than it is, I think, a feeling in your head sometimes. And I've reflected on this a lot.
I'm a purchaser of cybersecurity technologies. Sure. Obviously, we partner with other companies to fill gaps in our own protection, and it is really hard.
We've all seen these surveys, the questionnaire-based approach, and when it comes to supply chain risk, I put very, very little faith in the results of those surveys. So we've really focused our own trust initiatives around what I call hard-to-fake things- Mm-hmm ... where you can't just say yes to some kind of very high level, very basic question on a survey.
It's verifiable artifacts of your program's maturity. That's what I like to focus in on. Love it.
You mentioned software supply chain. I don't know if you went to this level in asking people and stuff, but has SBOMs made their mark? Are people trusting SBOMs?
Are they even using SBOMs? Are they even on the horizon? Yeah, we covered SBOMs briefly.
Give me your honest answer on that one. Yeah. SBOMs are a great idea, but there's work to be done before they are usable by the majority of people.
We get a lot of value out of our SBOMs internally, but the value that we get from other vendors without context is very, very minimal. There's a big problem in cybersecurity that we're always expected to say everything's perfect. Now, cybersecurity is just fundamentally a very, very hard discipline, and there is no company in the world, including the most resourced ones with 1,000-person, 2,000-person security teams, who doesn't have significant issues.
Yet, the old-school way of dealing with this is to try and pretend and expect that everything is perfect. One reason that we've really struggled to roll out SBOMs as an industry is because nobody's got a perfect SBOM. Unless they're doing a ton of massaging, in which case it loses all its value, nobody can just take from a large SaaS application or a large hardware application, a raw SBOM and stick it on their internet, and for it to be absolutely perfect.
So we have this first-mover disadvantage. " Or, "Look, you're not doing this. " When the reality is what you really want to know is whether those are well-understood issues, and they've had the processes to ensure that, yes, maybe they've got a library that's out of date, but it's well mitigated.
There's no path to compromising the applications through that library. But we haven't built up that kind of nuance or the tools to be able to have that type of conversation, which means that nobody wants to be the first to be super transparent with their SBOMs, because they'll get noise from it with very, very little benefit. Doesn't mean we shouldn't get there, but it requires a mind shift change from the whole industry in terms of what does good security look like.
It's not about absolute values. It's about evidence of the processes that companies are running to keep themselves secure. Excellent.
Great response. Ross, I wanted to dive in a little bit more into the report. One of the things that had jumped out to me was that 62% of the survey respondents- Mm-hmm ...
almost two-thirds, question their vendors' trustworthiness. And I guess that's healthy, right? We should.
But, just between you and me, no one else is watching this, one of the things that, my pet peeve is so what is the response? Oh, well, let's send the vendor a new questionnaire, right? I can tell you, as where I sit, I get these questionnaires and it's like, okay, another third-party questionnaire.
No, no, no, no, yes, no, no, yes. And I don't know how much real value is getting- Very little ... is received out of filling out these questionnaires.
If we have this high a level of people worried about the trustworthiness of their vendors, what could they really do? Yeah. So I think that supply chain risk management and vendor assessment is an area where is ripe for revolution, not evolution.
Agreed Fundamentally doing it wrong. It is incredibly manual, and companies, and I don't think companies aren't outright lying here, not deliberately, but companies will always- No, but they're just filling out the form ... Yeah.
But also the people filling out the form, they'll figure out an organizational structure that allows them to say yes to everything, even if they don't really believe it. They'll have a team in front of a team. It's a game of whispers, essentially.
And then the front-end team is just incentivized to reduce sales friction. They never talk to the security team, and they're saying all sorts. That kind of stuff happens all the time.
So yeah, I think that approach has to go. So the question is, what do we replace it with? That's the hard part.
So this is where I think back to this, the idea of verifiable artifacts of maturity are what we need to be looking for. To give you a few examples, and these are ones that are hard to fake. You can't just do these things.
So it is hard to fake a really good vulnerability disclosure policy. If you've got an advisory page with CVEs on it, your CNE, so you can add a CNA, so you can actually issue CVEs. You're known to work with the community, you've got a bug bounty program, and you've got a good reputation.
One of the simplest ones that I'm really proud of is Sophos, as a cybersecurity vendor, has the largest rewards for our bug bounty. That to me is just a very kind of market-driven way of us standing behind the security of our products, that we're willing to pay a lot of money for vulnerabilities in our own product. And then having that, and that's a very wide scope as well.
It's not a very narrow scope. It's across our entire portfolio and our infrastructure. You can't run a well-funded bug bounty program with a wide scope and high rewards if you haven't got very good organizational maturity to deal with it.
Another one is how you communicate and respond to incidents. So the timeliness of it. Obviously, if you have an incident, then to understand what's happening really quickly, and that requires operational maturity.
If you're phoning around trying to find an IR partner, when you have an incident, you're already too late. That's not going to work for you. You need to know who to call, who to get involved, what your processes are internally, so you can kick them off straight away because information loves a vacuum.
You can't just hold the shields up forever and not say anything. That used to be acceptable. This is all hiding behind a veil of secrecy.
We can't say anything, and then three weeks later, you'd come out with a response. You're expected to respond in hours and days now publicly. Again, companies that can do that, and they can do it effectively, not just kind of hand-wavy, PR-driven response, but true technical data, again, that's a great indicator of maturity.
So I really encourage people, when they're assessing their supply chain, to spend less time asking vendors and more time looking for these verifiable artifacts. Excellent point. We haven't even touched on AI and what effect this is having on this whole piece of it.
But unfortunately, we're over time already. Ross, we didn't even get halfway through some of the stuff I wanted to cover. Let me ask you one last question, and then we unfortunately have to wrap up.
What wasn't on your bingo card in this report? Right. " Anything?
I was pretty surprised about some of the tertiary drivers, so the stuff that got to the bottom of the list. So people actually rated their own experiences and the experience of others, like peers and customers, much lower than I expected them to. I think particularly their own experience, it kind of showed me that because everyone's had a supply chain incident of some kind.
They've had a vendor who, even if it's just a vendor who's emailed them saying, "Whoops- Yeah ... we lost your data," or something. And that to me showed that people don't know what to make of that.
Again, they don't know how to assess that. They don't know what a good response looks like versus a bad response, hence why it's so far down the list. Absolutely.
Ross, I want to mention, of course, the report is available for people to go download, and they could see for themselves and dig in a little bit. I'm going to give a URL here. It's not the easiest to remember, but I would also imagine it's probably available off the front page right now from- Yeah, you'll be able to find it.
Yeah, or you just Google cybersecurity vendor trust Sophos. You'll find it straight away. Yep.
com/en-us/content/cybersecurity-vendor-trust-survey2026. Again, not anything that rolls off the tongue. com.
You could get it off there or Google. Hey, Ross, I want to thank you for coming on and giving us at least a little peek into some of the findings here. There's so much more there.
I encourage people watching this, go check it out, dig in. It's an interesting time. As I said, we didn't really talk a lot about AI today, but this whole mythos and vulnerability finding and glass swing and all of this is shaking the very foundations of our trust in the software we're using.
And it'll be interesting to see if this has an effect on next year's survey results. Yeah, we're watching that very closely. Yep.
Ross, thanks for coming on. Come back soon. Don't be a stranger.
Thanks, Alan. Great to be here. Thank you.
All right. Hey, we're going to have more with you on Techstrong TV. We're going to take a break right now.
We'll be right back.