Trust Is the New System of Record
Trust used to be a feeling. Now it has to be a metric. Sravish Sridhar, Founder and CEO of TrustCloud, joins Alan Shimel on Techstrong TV to make the case that trust between businesses needs a system of record — measurable, transparent, and continuously improving — the same way revenue and customers do. Sravish walks Alan through TrustCloud’s three-step framework for codifying trust (document mutual expectations, report transparently, show continuous improvement), and challenges CISOs to stop proving a negative and start proving how security makes the company stronger, grows the business, and accelerates recovery. He and Alan dig into how TrustCloud connects telemetry from existing security tools to real business objectives, why CISOs should be measured on questionnaire turnaround time and contract velocity, and how vulnerability — admitted honestly — is what actually builds trust at the board level.
Transcript
Hey everyone. Welcome back here to Techstrong TV. I am happy to have returning to us, Shravage Sridhar.
Shravage is the founder and CEO for Trustcloud. Let's welcome him back. Shravage, it's great to see you again.
How's everything? Hi Alan. Thank you for having me.
I really appreciate it. My pleasure. I hope all is well.
Shravage, I'm sure everyone watched the previous times you've been on Techstrong TV, but just in case there's a few people out there who didn't, give our audience a little bit of a refresher on your journey on how you came to found and become CEO over here at Trustcloud. Alan, I started Trustcloud with a very simple idea after having built and successfully sold two previous startups. And the idea was, trust is foundational for every relationship and especially foundational for every business relationship.
We use the word trust a lot, but we've never built a system of record where you can codify trust and you can continuously measure if we, as human beings and us as an organization, are meeting all our trust obligations or not. So can you build an API for trust and can you measure it, was the thesis. And we then focused on the CISO and what does trust mean to the CISO?
How can you build data to show that you can trust the CISO, and how can you build data to show that the CISO's work is delivering strategic impact to their business? And that's what we're doing at Trustcloud. I love it.
You're right. Trust is something you really couldn't put your finger on in the past. Yeah.
It reminded me of, so I went to law school 100 years ago, and when I went to law school, there was a Supreme Court case on pornography. And I forgot what judge it was. He's not alive anymore, I'm sure.
But the judge said, and I'll probably mess up the quote, but, "I'll recognize it when I see it, but I can't tell you beforehand. " Yeah. " And trust was like that.
" Yeah. And that is something now that we... On the other hand, I came up after I realized I never wanted to do law or I'd got into the tech.
" Right? And we measure everything, and so we have to be able to measure what goes into- Yeah ... a trusting a trust.
Yeah. Alan, I actually think it's a lot simpler when it comes to the world of the CISO. I think the step one is you cannot build trust if you don't have well-documented mutual expectations.
Yeah. So I think first things first is what do you expect from me? What do I expect from you?
Let's document it and let's have clarity around it. That's step number one. Step number two is- Let me stop you right there.
Yeah. Repeat it again for people in the back row. You must have, say what you said.
Write down first- You must have well-documented expectations of what do you expect from me and what do I expect from you, and it needs to be clear and measurable. Absolutely. Okay, that's step one.
That's step number one. I love it. Step number two is transparent reporting against those expectations.
And the word transparent is as equally important as reporting. You can't be- Love it ... cagey about it.
You might fail from time to time, but that's okay. Mm-hmm. Own up to it.
Absolutely. That's step number two. Step number three is show me that you're improving.
I'm not expecting you to be perfect. I expect to know when you're not perfect, but I also want to see how you're getting better. And if you can do that in a cycle where the expectations are always monitored, they're transparently reported, and you're showing me that you're improving, I'll continue to trust you.
Excellent. You know what, Shravage, excuse me, you're making it sound too simple. It is.
It can't be that simple. It is. And so when I talk to CISOs, I ask the very simple question.
" The conversation I have with my CISO is, "I'm looking for three things from you. " Mm-hmm. "Not how you're securing us, because security is proving a negative, that we were not breached.
I want you to show me how you're making us stronger. What are our areas of risk? What are our areas of vulnerabilities?
" That's objective number one. Objective number two is, how are you helping us grow our business? That should be a universal requirement of any executive on the leadership team.
How is your function, your business function, how is it helping me grow the business? That's number two. And number three, how are you ensuring that the business is going to recover if there's going to be some sort of disaster or something?
What is your risk management process for your function if catastrophe happens? Just like if I'm talking to a salesperson, a head of sales What happens if three deals fall out? How are we going to compensate for it, right?
Every executive needs to be thinking about the risk related to their business and have a view of how do I recover from it, and how do I remediate it. So those are the three things. Are we making it stronger?
Are we helping grow the business? And how are you going to recover, and how are you planning to recover if something bad happens? I love it.
Shrivaj, look, if this thing doesn't work out for you, I think you've got a future as a lecturer, a teacher, because you make it easy for people to understand. When you could boil things down to three easy steps, three principles, I think that's the kind of stuff people get their head around. Trust stops becoming this abstract idea and- Yeah ...
it becomes real. Something you can touch, you can smell it, you can squeeze it. Yeah.
Let's talk about now how Trustcloud, I'm assuming Trustcloud helps us with this, but how does Trustcloud help us? What we did was we looked at what is the hierarchy of work that happens inside a CISO's organization. The base level hierarchy of their organization is all the security tools that they've put in place, the processes that they've put in place to detect and protect the organization, right?
And that's a baseline that's a must-have, and that continuously expands as there's more threats and vulnerabilities to the organization, or if the organization's attack surface is increasing. So that's our baseline. But in order to do that well, what CISOs need to do is they need to think about it from the top down.
They need to figure out what are the objectives of the business. What does my leadership care about? What does the board care about?
Going back to my earlier point of documenting expectations, document what the business objectives are. I have certain growth goals. I have certain resiliency goals.
I have certain expansion goals. Whatever the business objectives are. From that point onwards, in the platform, document what are the risks that are going to impede those objectives.
And for those risks, what are measures, which in technical parlance is called controls, what are controls are you putting in place to mitigate those risks? And then connect to all the data in your environment to test if those controls are operating effectively. Trustcloud helps you do all those four steps.
Create your objectives, map risks to them, map controls to them, and then continuously test those controls to validate that those risks are being reduced, and therefore you're in a position to hit your objectives. I love it. Again- Yeah ...
boiling it down to easy steps people can grasp. You've got a gift there, my friend. I wanted, though, now take the next step.
So we're meeting objectives. In the case of CISOs at this level, at the exec level, those objectives, they could be tied to very key metrics in security. But increasingly, those objectives and key metrics have to be tied to outcomes that sometimes are out of the control of a CISO, right?
Faster deals, more closed deals. We see this all the time. Salespeople blame marketing.
" Yeah. " Sure. Right?
It's always marketing. "Crappy leads I get from them. " It's the same thing sometimes with security, right?
"Hey, don't blame us the deal didn't close. We gave you everything you needed to prove that we would be a trusted partner, that we could deliver this securely. You didn't close the deal.
" Yep. Yeah. How do CISOs get...
No one wants to play the blame game. How do we use the Trustcloud metrics? Let's make a positive, not a negative, right?
Yep. Yeah. I think this is where it goes back to how we started the conversation, Alan.
The conversation was, let's sit down and document clear expectations on what do you expect from me and what do I expect from you. I think it's a bidirectional conversation, right? If the board expects, let's say, 50% growth, we document that, and every individual in the leadership team contributes their part to that 50% growth.
For example, what the CISO has to say is, to facilitate 50% growth, we are going to achieve GDPR compliance and DORA compliance because we have to expand into Europe. And I'm going to deliver that for us in four months. To facilitate growth, I need to complete security questionnaires that I've been getting from my customers in one day and not 12 days, which is what it's taking us right now.
That's objective number two. Objective number three, in order to facilitate growth, I need to make sure that if a customer is coming to us with brand-new contractual commitments in the security addendum and the DPA, we're in a position to meet those, so contract negotiations don't take a long time. Those are my three objectives as a CISO on how I'm contributing to growth.
But the VP of sales has their objectives, the VP of marketing has their objectives, and so on and so forth. But these are mine. And now I'm using telemetry to show you data that I'm meeting those three objectives to meet the overall growth objective of the business.
And you got to break it down that way. Agreed. Agreed.
I love it. Shrivaj, we're only 15 minutes. It goes quick here.
But man, you should be teaching courses in university. Forget this stuff. The world needs you.
Seriously, though, for people who want to get more information on Trustcloud and maybe dig into this and learn how to be trustworthy, how to emit trust, especially for our CISOs out there who deal with this every day. What's the on-ramp with Trustcloud? Yeah.
There's three very simple places for you to go to learn more and more about Trustcloud. ai. We've got a plethora of information there about what the product does, but it's a very company-focused piece of content.
com. It is a very open community that we built with a lot of practitioners and CISOs. We built a lot of open content on things like this, like what are best practices to implement risk programs, objective-based programs, trust programs in the organization.
And the third one is we have Trustcloud AI, which is our YouTube channel, where we invite a lot of practitioners to come and talk about their best practices and what they're doing to make themselves more strategic to their organization. So you could connect with us in all three places. We'd love to sit down and talk to you.
I love it. Shrivaj, thanks for coming here today on Techstrong TV. Appreciate it.
Keep up the great work. Come back and visit us soon with more. Thank you, Alan.
You're one of my favorite people to talk to because you totally get it. I try. Well, sometimes it's the way you explain it, but I'll leave it at that.
Shrivaj Sridhar, founder, CEO, Trustcloud, here on Techstrong TV. We're going to take a break. We'll be back with more Techstrong in a moment.