Transforming GRC From a Cost Center to an Automated Revenue Driver
Techstrong Group’s Alan Shimel sits down with the visionary founder behind TrustCloud.ai, Sravish Sridhar, to explore how artificial intelligence is fundamentally redefining governance, risk, and compliance for the modern enterprise. While the cybersecurity industry has long struggled to prove its financial return on investment, emerging platforms are now empowering CISOs to transform manual, “check-the-box” compliance tasks into automated revenue drivers. By continuously monitoring controls and mapping them directly to business outcomes, organizations can finally treat security as a measurable, trust-building asset rather than a necessary liability.
Transcript
Hey, everyone. Welcome back here to Techstrong TV. My next guest, and I'm gonna do my best to say his name right.
I said it well in the green room, but you never know. Uh, Sravish Sridhar. Close, but S-Sravish say it better for me.
Hi, Alan. I'm Sravish Sridhar. I'm the founder and CEO- There you go ...
of TrustCloud. Fantastic. Sravish, first of all, welcome to Techstrong TV.
It's great to have you on. But let's jump into it. Tell people a little bit about yourself.
ai, which is the website. But y- you know, tell us how you got here. Well, Alan, literally, I got to the US as a seventeen-year-old kid and put myself through undergrad at the University of Texas at Austin- Very cool ...
in computer science and math. And the reason I'm starting with that story is after I graduated, I had the opportunity to be co-founder at a startup, which was very successful venture-backed startup. And then after that, I did a second one, which was also venture backed and had a very successful exit.
And the thread through both those startup experiences was people I've worked with, people that have invested in me, and customers I've worked with have followed me across all three companies, including this third one, TrustCloud. And a big part of that was because we all trust each other. And so that created the genesis of this new company, TrustCloud, which is can you build a world where trust is not just felt in business but can actually be measured accurately?
I love it. And you know what? In today's world- Yeah ...
right, that's a mouthful to say the least, right? It, it, it is... Y-you know, you know, I speak to so many of my friends.
They don't know whether it's on social media or, or the mainstream media, newspapers even, anything, for let alone, you know, internet. No one knows what to believe anymore. No one knows what's trustworthy.
No one knows what's real and what's fake, and it's almost... Uh, and there's a lot. We, we could, we could probably sit down and have a couple of bottles of wine over going- ...
through all of the things that are wrong. Yeah. Or bourbon or whiskey, depending on what stopping or something.
Or something, yeah. I mean, because one part of it is, look, when you doubt everything, you sow doubt on everything, right? That's right.
Everything then becomes doubtful. You don't know. But, you know, with everything going on with AIs and, and, it-it's just, it's, it's, it's a, it's a crazy world is what it is.
But- Absolutely ... this is a, you know, so this is a real problem. This is a big problem that TrustCloud is, is tackling.
It absolutely is. It's the vision is to build a system of record for trust for any workflow in the enterprise. But the first use case we focused on is what does a CISO have to do from a trust perspective, both internally with their internal stakeholders.
That could be their board, their leadership, et cetera, as well as their external stakeholders, which is their auditors and their regulators and- Sure ... and customers. And y- I love how you said it earlier, where in this world of social media and AI and images and new videos, trust is, is hard.
From a CISO's perspective, a couple of artifacts that are relevant to them is audit reports and security questionnaires. How do you trust what people are manually putting into security questionnaires, and how do you trust whether an audit report, a SOC 2 report, or an ISO 27001 certificate, et cetera, is accurately, is actually accurate? And the answer is you can't.
And, and the problem we're looking to solve in TrustCloud is how do you change what is traditionally a manual workflow-driven process, which I lovingly call governance risk and check the box, which is what I think GRC really stands for, and transform that into a traded data-driven strategic practice where it's all about business outcomes, accuracy, and automation. Agreed. You know, I, I, I've been in security a long time, twenty-five, probably more than twenty-five years.
Um, it's always been a bit of a check the box, especially- Yeah ... when we talk about, you know, compliance and, and- And risk ... and risk.
Um, but it, th- some of the issue is a-and I, and I don't mean this in a bad way- Sure ... but quite frankly, not as many people are as passionate about security as security people are, including the CISO, right? And the most su-successful CISOs I know are successful 'cause they're very good at translating security and risk talk and compliance talk into business talk.
Yeah. Right? 'Cause they're not the same language, certainly.
Yeah. Um, but the problem, you know, back to even when I started s- a security company back in the early 2000s, 2001, is, you know, the so-called ROI of security. The myth that-- Let me call it the myth of the ROI of security, right?
Sure. And, and so it started there. I, I was-- When I first realized how hard it is to sell security.
How the heck- Yeah ... can you, can you really prove an ROI? Yeah.
Well, in a, in a, in an industry where nothing happened means you did your job- Yeah Theoretically, or maybe you just weren't the zebra that the lion pounced- Yep. -on that day, right? Yep.
Um, how do you... How does anything have an ROI? How does anything- Great question.
Yeah, I mean, there's a- How do, how do we know what's working? Yeah. There's a lot of interesting threads you pulled on, Alan, in the statement that you made, and I wanna, I wanna take them one by one.
Go for it. I think the first one you mentioned is why should somebody care about security? And I find Trustcloud customers asking their CEOs and their board, "Even if you don't care about security, do you care about trust?
Do you want our customers to trust us? Do you want our regulators to trust us? " And every board of directors will obviously say, "Yes, we do.
" And so if you start with that theme, that you're no longer the chief information security officer, you're, you're almost the chief trust officer, and you, you, you use trust as your umbrella objective, the way you translate your security program into ROI is by deriving from trust three vectors, and this is what we see our customers do all the time. The first one is security needs to facilitate business growth. It needs to drive revenue.
And a big part of driving revenue is operating in new verticals, in new geographies, and helping close new customers. Well, guess what? To operate a new vertical, you need to achieve new compliance standards that cater to that vertical.
To operate in a new geography, you have new data governance, security, AI policies that you have to adhere to. And to close a contract, every contract now has a security addendum. It has a data processing agreement.
It has an AI addendum. These are contractual commitments that the company's making, which they can be h- held liable against if they don't meet those commitments. And so the first part of the story is CISOs tying their security controls to their regulatory obligations, their commercial obligations, and their compliance obligations vis-a-vis compliance and contractual commitments, and showing how the security program is directly contributing to contractual commitments via revenue or business growth by closing new deals, right?
So that's ROI number one. ROI number two is every balance sheet has a liability section, and cyber risk is a liability on a balance sheet. And by quantifying the impact of that risk, you're able to say that, "If we did nothing, we're sitting at risk of, let's say, a billion dollars.
That billions of dollars is our yearly revenue. The whole thing could come crashing down. " Right.
Worst case. "And I'm putting in these mitigating controls to reduce the risk, and now I'm reducing it from a billion down to a hundred bill- hundred million dollars. " And so you're...
The CISO's not talking about risk, they're talking about resilience. How are we getting stronger by reducing potential financial impact for the business? So that's number two.
And then number three is cost optimization. By thinking about how to automate things, how to do things faster, better, how to do things at scale, the CISO's able to show that they're doing more without increasing costs all the time. And if they can do those three things, if they can show how they're facilitating growth, how they're reducing risk, and maintaining costs, they're not only showing the ROI, but they're able to justify that the security program is actually a profit center, which makes them really strategic to the board and to the leadership.
Some music to my ears, but I've... Forgive me if I'm a little incredulous. Sure.
Sure. Um, you know, I, I think we've, we've only recently, let's say in the last 10 years, made the board start thinking of IT as a profit center, right? Yeah.
For a long time, they thought of the IT department as a, as a cost, not as a profit generator- Sure. -but as a, as a cost. I never thought I'd see the day where we think of security as a profit center.
Yeah. I have customers, Alan, who are... who convinced their board because of all the reporting they've done by transforming GRC and tying GRC more from a growth and a resilience standpoint, where the customers are essentially convinced their leadership that security is so important that if our controls are being met on an ongoing basis, it's a good thing for the business, and therefore, the executive bonus, part of the bonus is based on ninety to ninety-five percent of controls passing all the time.
It is an important thing for the organization, so let all the exec's bonus, X percent of the bonus, be based on ninety to ninety-five percent of control passing all the time, right? And that's the culture that we're seeing in strategic CISOs, organizations that have strategic CISOs, where they're, they're able to articulate this. They're able to create that kind of change.
It's happening. I love it. I love it.
So let's talk specifically now, 'cause we're gonna run out of time here. Let's talk specifically how Trustcloud facilitates this. Look, at the end of the day, the reason I lovingly said GRC stands for governance is can check the box is, like you said earlier, it is a set of manual workflows driven by spreadsheets and screenshots and so on.
The modern CISO doesn't want their name put against an audit report or a 10-K filing-Where the underlying work is done in a check the box fashion. They just don't wanna do it. It's personal risk and it's business risk.
And so their approach is whether I'm trying to achieve a compliance objective, a governance objective, or a risk objective, the way you typically do it in a security program is you map everything to control mitigations, and you put technical controls in place, process controls in place, and documentation controls in place following a defense in-depth mechanism to ensure that the company is meeting all its commitments, right? And the, the big hard problem was: How do I know if my controls are effective in a continuous fashion? And the industry's talked about continuous control monitoring.
What Trustload has built is, through our security assurance platform, is a best-of-breed continuous control monitoring engine that solves three hard problems. First is can you operate at enterprise scale? You need to aggregate structured and unstructured data from all sorts of places, and you need to analyze it, so that's problem statement number one, which we've solved.
The second is you need to make sense of it, and that's where AI comes in. You analyze the data, and then you map it to your business objectives. You map the data to a risk.
Is the risk going up? You map it to a compliance objective. Are you meeting the compliance objective?
You map it to a security objective. So you map it to many things, and that's what AI is really good at doing all the time. So you analyze the data, you create business impact, and then the final part is you help report this to the rest of the organization, so they can take action.
Um, and that's what we've done in a nutshell. We, we allow CISOs to aggregate data from their security operations, map it to their risk and compliance objectives so that they can continuously measure if they're doing what they need to be doing and reporting the business impact of any gaps. I love it.
All right. ai, right? That's the website.
What do you, what do you recommend is the on-ramp here? How do... People watching this saying, like, "You know what?
" You know, we'd like to check it out. Yeah. So two things.
ai with whatever your use case is, and that could be you want a better way to improve risk, you want a better way to achieve compliance, or you want a better way to respond to security questionnaires to accelerate sales. Any of the use cases we support, just tell us what we need and we'll get back to you. I love it.
Shravah- Shravish- Shravish, thank you very much for coming here on Techstrong TV. I appreciate it. Best of luck with Trustcloud AI.
You know, it, it, it's stories like this and business models like this that keep me hopeful that we are innovating in security and we are, you know, not doing just the same old, same old. Yeah. So that's good stuff.
Alan, I hope we live in a world where our kids and grandkids don't have to answer security questionnaires anymore, and instead- Go- Amen ... there's an API that can evaluate trust. Amen.
God knows I've, God knows I've answered enough. Um, thank you. Thank you, Alan.
Thank you for watching. We'll be back here on Techstrong TV in a moment.