Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 282. We're in a whole new year, Alex.
We are in a whole new year. Happy 2026. Happy 2026. I think we're saying this is, this is the January 5th podcast. We have an unbelievably warm winter going right now, don't we?
I don't think it's actually considered winter, Robb. It's early spring, late fall. Yeah, I played outdoor beach volleyball at a park on Friday, the day after Christmas, and it was perfect. Like, the weather couldn't have been better. I think the day that this podcast is dated, the 5th, I think it's supposed to be 70 degrees.
Well, okay then. Yeah. Yeah, that's weird. It is very, very weird. Probably not so good for our friends at the ski mountains, huh?
No, I haven't been skiing yet. I really want to go, but the snow has just been so horrible that I haven't gone yet. So not good. One of my kids is skiing today as we record this. So hopefully I hear that it's better than I think it is and I'll actually go.
Is it like man-made snow then? I think a good bit of it is, yes. Yeah. You got to keep those things open somehow. And speaking of keeping them open, we have a Slack channel that people can join at any time, 24 hours a day.
Is open for conversation. Yes, you should keep that open all the time and come, come participate. Come join our Slack channel and sign up for our mailing list at colorado-security.com. There's a little form in there. Get signed up, you'll get into the Slack, get on the mailing list, hear all the good news.
If you're listening to this, it means you know how to listen to a podcast. And if you do, we'd love for you to subscribe so you get this every month and rate us so that people know how great it is. And go take as a task, go find one person who doesn't know how to listen to a podcast and teach them how to listen to your favorite podcast or us, whichever one you want. While you're at it, go tell another friend, let them know about us, and hopefully we can get more people into the Colorado Equal Security community. We would love that.
Also, we have some annual sponsors. We are coming up on the end of that, that year of annual sponsorship, but we still want to thank them. CrowdStrike, Red Canary, and Zscaler. Thank you all very much for supporting Colorado Equal Security. We appreciate you.
And you know who else we appreciate? This audience that is listening to us, that supported us for the last— coming up on ending our 9th year of doing this podcast. Next month will be the end of 9 years, starting our 10th. That, that is pretty crazy, Robb. I, you know, we didn't know what we're— we were doing when we started this, and we still don't know what we're doing, but, uh, it's, it's been amazing that it's lasted this long.
Yeah, we're, uh, we're, we're giving some news. There's going to be a significant format change to Colorado Equal Security coming after next month. So next month is the end of the current format of this podcast. Yeah, and you might say, oh, what does that mean? And we're not gonna tell you.
Well, we are gonna tell you. At least not right now. Yeah, next month we're gonna tell you. Tune in, listen in, hear what's coming for the future of this podcast. It's not going away, but it is changing, and we're excited for those changes.
Yeah, it's gonna be great. All right, speaking of things we're excited about, what do we got for news here this month, Alex? So Colorado has its first treehouse hotel, which is now open. And as the article says, it's gorgeous. It is gorgeous.
I, of course, was looking at the beautiful picture. I have a beautiful picture of it up right now. And it looks like this lovely cabin up in, literally up in the trees. I feel like it's a little misleading when it calls it a treehouse. Yeah, it is among the trees.
But it's not, it's not built on a tree. No. And I think, you know, I'm sure some people have seen the Treehouse Masters show where they actually, they build actual treehouses. This looks more like a tiny house they put on stilts, which is nothing wrong with that. Oh, it's gorgeous.
And it looks very well appointed and beautiful. And I'd love to go stay there. But yes, doesn't quite seem exactly like you might think of a treehouse. I think this story made the podcast because the headline was great. Once you get in there, you're like, well, it's not exactly a treehouse.
But Very beautiful. If anyone does go and stay at this new treehouse resort, we'd love to hear about it and whether we should go stay there ourselves. All right. Next up, we've got some news about a couple of local travel companies and an acquisition. Yeah, we've, we've talked quite a bit about this over the last several months.
Right. Holy smokes. I'm totally blanking on the name. Inspirato. Inspirato.
Yeah. Thank you. Inspirato has been the talk of acquisition Man, for most of 2025, right? The— they are a public company that, that lost so much value. They were almost delisted off of Nasdaq.
They got a new CEO. They've been working to fix things. They had had one of their rivals had placed an offer to buy them. Inspirato said, no, we think we're— we think we're more valuable than that. But what happened after that?
Yeah. And the rivals, I think that the people that started the rival company were the people that originally started Inspirato and then left and started a new company. The current CEO was going to combine the company with another of his companies to try and make things work. Work. And anyway, eventually this other company gave a good enough offer and Inspirato accepted it.
So Exclusive Resorts is a competitor who looks like they, they have now made an accepted offer to buy Inspirato for— was it $59 million? I think, I think that was right. $59 million, which is interesting, like a relatively low purchase price for a subscription SaaS type of a company. They had, I think, 400-ish employees, pretty big organization for a pretty low purchase price. I'm interested to see how this goes, you know, if the combined company is able to reinvigorate and accelerate growth.
It does— Inspirato does say that they're intending that 2026 was going to be their first profitable year anyway, so maybe the future is looking brighter than it was. Yeah, I'm excited for them and hopefully things go well for the new combined company. It sounds like the shareholders still need to technically vote, but it seems like it will get approved. So I know they had to vote. I'm not sure if they have by now.
I don't know what to do. I guess it depends on when this story was. Well, in the category of all news is local, there is some federal news that has a Colorado angle to it. President Trump has signed an executive order to bid states putting in place AI regulations. And of course, you know, we have talked multiple times about Colorado and our upcoming AI law that goes into effect June of '26 here.
Well, what is this? What does this new executive order do to Colorado's law? Yeah, I think the intent that the federal government was trying to make with signing this executive order was to prevent state AI regulations from going in place. However, the executive branch doesn't actually have that power. So this more or less instructs various other pieces of the executive branch, the attorney general and some other things like that, to, to essentially take action against states in areas where they feel like the state AI laws are overreaching or burdensome or things like that.
Yeah. So to be really clear, this executive order doesn't directly stop, slow down, impact Colorado's AI law. But it could change the calculus as Governor Polis had already asked a commission to look at, should we amend this law, should we change it, what should we do before it goes into effect in June? It could certainly change the calculus of what they choose to do there, and, you know, maybe they weaken it, maybe they strengthen it, maybe they delay it again, maybe they nix it. A lot of kind of open, up-in-the-air questions about this right now.
I think on the sort of positive side of this, The one of the stated intents is that, you know, we want to make sure that the US is positioned to be a leader in AI. And, you know, if you have 50 different states with 50 different regulations, it makes that hard. I think as security professionals, we know that from various security and privacy legislation. I think obviously, the easiest way to do this is pass a federal law that, that has preemption for these state laws. But I don't know how likely that is, considering we haven't seen that for any of the other things that are related to this, whether it's privacy or security.
So and maybe this is the place it could happen, because there's more money on the line here. There's, there's more.
I think, you know, we talked about lobbyists as a, as a bad thing. But it could be a positive thing here if we can get some lobbyists to, to get momentum on a solidified approach. To AI federally. That'd be much better. It's possible.
All right. Staying on the government angle, our next article is talking about the evidence sharing system that we have in Colorado for the courts and maybe some problems that there are with this system and how maybe to fix it. Yeah. Really interesting. You know, I say one of the cool things about doing this podcast is we come across stories I never would have known about this.
Without this story. This was by the Denver Post telling us about this evidence sharing system that the state stood up about a decade ago, 2016. Yeah. And the intention of it was that defense attorneys can make requests, you know, to DAs to get access to all of the evidence related to a case that they are defending against. And of course, in terms of being able to have a just legal system, you have to be able to share this information.
This discovery both ways. So this system was stood up to make it so across the state there are ways to share that evidence. What they've learned throughout this process is, you know, in 2016, the volume of data, the types of data, was just so much smaller than it is here a decade later, and the system is overwhelmed by the complexity of interacting with, you know, external third-party systems like Axos, the body cam system, and They gave a couple other examples of third parties that have to be interfaced with here. And the system is burdened down and it's led to some negative results where either, either the defense was not provided with information on time or some of the files were left out and leading to some prosecutions being dropped because judges said, hey, you didn't, you didn't follow the discovery rules. So the, the state had to let some things go.
Yeah. And this article talks about a task force that was put in place and really the output from that task force is what we're talking about here. And so that there are a number of recommendations from that task force. But so far, you know, there's nothing that is happening or has happened to change this. But I think that there is a path forward to help make some improvements or a better system.
But we'll have to see what happens based on these task force recommendations to see if it actually happens. You know, usually I think about the government as not having enough resources to do things well. But in this case, it seems like maybe that might not be the problem, at least from my naive read of it. They have $750,000 a year earmarked for maintaining the existing system. Yeah.
And, and the, they get about $3.5 million for, for supporting both that and kind of developing the system and improving it per year, $3.5 million a year. So there's, there's money there as they identify the right way to do this. It feels like a problem that they, if they get the right direction, if they have a good leader in place, they should be able to execute on it with the resources they have. I hope. Let's hope.
Yeah. Interesting stuff. I always appreciate getting a little more insight to our federal government. Speaking of insight, at the end of the year, Optiv released their 2025 Industry Threat Profile. This is an annual report they put out that shows based on different industries, What are the— what are the— what does their threat profile look like?
How likely are they to be targeted? What type of attackers are going after them? What are the reasons they're going after them? Some interesting stuff to take a look at based on industry. Yeah.
I think you may not be surprised that this report has some of the same themes and tropes that we have seen over the years. Ransomware is obviously popular and has become probably the biggest disruptive threat that's out there. I think we've heard about this a lot, but social engineering has been a big way that ransomware is being affected on organizations, you know, as an initial access vector. And, you know, I think the rest of these are sort of similar to what we might have thought in the past. Last one, and this is not going to be a shock to people either, that AI is a force multiplier for these threats that are coming at us.
Yeah, AI is both the best and the worst of it these days, isn't it? Yep. Anyway, good stuff from Optiv. If you're, if you are interested in seeing how your industry stacked up, go into the show notes. There's a link to, to their, their, their report.
You can download it for free and, and learn everything you want to know. All right, uh, next up we have a blog post from Laris talking about, uh, audits, audit success versus operational resilience and understanding the gap. So yeah, Andrew Heller here wrote this, and it feels a little bit more like a LinkedIn post than it does a blog post, right? Like, or like a, like a blog where he had 10 minutes. It is succinct.
It's succinct. Yeah. And it's again another theme that I think we've heard before. Just because you can pass an audit doesn't mean that your operational security is good and that you are in a good position to maintain security. Yeah.
I think he does a decent job framing it though. The reason CISOs and other security leaders are often starting with compliance is from an outsider perspective, That's how you prove you have a program, right? You prove that you've got the basics in place by having a third party come in and see you've got your policies, you got your standards, you got your evidence. Yep, yep, yep. You exist.
Okay. You're really here. And then he goes on to say, great, you needed to do that, but now you need to prove that your program is effective. And this is where adversarial engagements are key, is going through and actually looking for, do your controls work? Can I get past them?
And I think it's an interesting perspective. Yeah. And I think it's definitely important. You want to make sure that your controls are working as effectively as they can be in the actual real world, not what the paper says. Yeah.
Awesome. Well, so we have a blog post here from Ping Identity, and I don't know, maybe I've been kind of sleeping. I haven't thought of it quite this way before. The way that Ping talks about maybe the best way to implement AI in your security program, they specifically talk about it in your identity program. I'm just going to broaden it a little bit.
And they're specifically talking about human human-in-the-loop AI and thinking through where are the places where, as you implement AI to go help make better decisions and risk engines, that you can identify, here is the place where a human can just sanity check this thing, can apply that bit of judgment to say this is right or wrong. I think I'm just kind of flipping on its head this where we came from, which is we have analysts who you're using AI to automate some of their processes. And, and okay, where can I automate some of the analyst processes? This is going the other way and saying, hey, AI can do it all. Where do you want a human, right, to be the, to be the check on it to say, hey, is this, is it going the right direction?
Is this the result you really want? And kind of reversing your thinking about it. That, that's how I walked out of this article. I was actually pretty interested in what it had to say. It gave some examples that maybe I didn't think were as good as they could have been, but, but the concept I think is really strong.
What do you think? No, I agree with you, Robb, and You know, there, there is enough, uh, enough work out there that it, it would be very easy to just try and automate it as much as possible. Um, and, but people always have reservations for that because they don't want to, um, have things happen that they didn't expect, that they, um, that, that are out of bounds, that are, you know, high risk, you know, whatever it might be. And so this is a way to, uh, to help work through that. Um, In my mind, I was thinking also about the practicality of actually implementing this, right?
Like, how, how is it that I'm defining all of these things? It's going to take some work to figure out all sort of the edge cases that I would want to make sure that there is a human in the loop. Not to say that you couldn't do it, but I think that there are some hurdles there too. Yeah. And I mean, I think that defining those edge cases and understanding your processes better is probably the highest value work we can do in this, in today's world.
The understanding of what you do and why you do it and why humans exist and getting as, as discrete as we can on those things is probably the highest value human work today. Maybe relationship building. But, you know, you call those things, it's like, what do we want to be doing? And, and any of us who are actually busy spinning the hamster wheel and not doing that kind of meta thinking are, are maybe not in the highest value place that we could be in our companies and our day-to-day life. I think the other part of that too is that We often don't do that work because we are buried in doing the mundane volume of things.
But if you take all of that away and you can really focus on that high-quality work, I think it is valuable. Yeah, and I appreciate Ping Identity coming up with a good blog post to walk us through that. And I think we have one more blog post. We do. So this is a Red Canary blog.
Title is Beyond the Bomb: When Adversaries Bring Their Own Virtual Machine for Persistence. Yeah, so this is, uh, I, they actually are walking through a case study here, a real-life, uh, incident in one of their, I assume one of their customers. I'm not positive about that. Um, where someone, they went through one of those, what do they call them? Email bombs, spam bombing, spam bombing, which we actually saw this at my daytime, my regular employers, uh, recently where we got overwhelmed with lots and lots of emails, uh, you know, spam emails that looked Customized to our environment.
And then immediately following that, we— there are the people who got the email started getting phone calls saying, hey, we're IT and we want to help fix this problem. Hey, you're, you're under an attack, let us help you fix it. Fortunate— I'm knocking on wood here— fortunately nobody in my organization fell for that support trick. But man, like, it'd be so easy to happen, right? Well, in this case, the, the incident that Red Canary is walking us through, it— someone did.
They let, they let one of the attackers access their computer under the guise of being an IT person, and they walked them through how to connect. But what the attackers did once they got on there, which is ingenious and different, was rather than directly owning the laptop of that user, they installed a new VM. And this VM allowed the attackers to get persistence on that system while they got off the phone. Yeah, not a completely novel thing, but it's not something that has been seen Um, as a, uh, a big method for attackers in this way. And so, uh, this walks through what happened once they got that, uh, that VM on the machine, the steps that they took after initial access to pivot and, um, how it was detected.
So yeah, I read this article. I love how Red Canary, they share, they don't just share what happened. They share all of the, the tools that Red Canary used during their forensics. They showed all of the actual indicators of compromise they came up with. They show the open source intel they use.
Just all this information shared throughout that, uh, not only makes me better understand the attack but makes it make me able to do my job better because now I have all these tools. So I appreciate Red Canary's great sharing on this blog. On this stuff. Uh, so that is the news for this month. Uh, we can jump over to events.
As a reminder, we have an event calendar on the website, uh, colorado-security.com. You can see all of the upcoming events and, uh, all of the ones that are further out too. All right. Start with January. First week people are taking off.
But starting on the 13th, ISSA Colorado Springs is kicking off their year with their January meeting in the evening. On the 14th, ISSA Denver is doing an event. CTI Revolution Starts Now: Building a Business-Centric Intelligence Program. I think they're doing that both in the DTC and downtown. So I think there's 2 different places one could go.
On the 23rd, ISACA Denver is hosting She leads, she leads tech, the 2026 Climb and Carry event. This is a 7-hour event, full-day event down at the Tech Center. I'm actually going to be there. They're doing a bit of a hiring fair, and I'm going to talk about some of the jobs that we have at PAX 8. So if you're going to be there, come say hi.
The 23rd in the Tech Center. On the 24th, ISSA Colorado Springs is doing their January workshop. And last event for the month. On the 28th, ISC2 Pikes Peak has their monthly meeting. So get out there in the evening.
Good stuff. All right. Well, that is it for our events. We do have an interview and we actually have a pretty interesting new, new interview this month. Yeah.
So Frank Victory is interviewing more than one person in this month's interview. So it's a little bit of a different format. We've got 3 folks from the company Xactly. Matt Sharp, who's the CISO over there, Ian O'Neill, who runs legal, and Jason Godley, who is the CFO. And they're talking a little bit about how they built the program over there, how they've interacted between the different organizations to make sure security is working properly and growing and helping the business and all those kind of things.
So the way that— way Matt put it was helping security go from a cost center to helping drive the business strategically. Interested to hear how they did it. Yeah, should be good. All right. Well, that's it.
We'll look forward to talking to you guys next February. Thanks. Or in February. In February. Well, I mean, the next February.
You're correct. The next one is coming. All right. Have a good one.
Hi, this is Michelle Wilson, CISO at Movement Mortgage. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Good morning. Good afternoon. Good afternoon and good evening. This is the Colorado Equal Security Podcast. My name is Frank.
I am your host here, and today we have something completely different. We normally have a one-on-one where we talk to everybody, or we talk to a single person about their history and how they get to the rest of how they got to that position as a leader, as a security leader. But today we've got something completely different. We're going to talk to 3 different people about strategy and why some of these decisions are being made. So today I have Jason Godley, right, who is our CFO, our CFO of Exactly.
We've got Ian O'Neill, who is our general counsel, and we got Matthew Sharp, who is the CISO for, again, Exactly. Matt and I go back a little bit from my work with the OWASP chapter as well as Colorado EcoSecurity. But this is the first time that I've met Ian and Jason. So, gents, how are you today? Good.
Good morning. Good to be here. Good to be here. All right. For those of you that are regular listeners of the podcast, I always start with an icebreaker question.
These gentlemen have not heard this before. Here we go. Here we go. Here we go. All right.
We're going to go ahead and start here. If the 3 of you are stuck in an elevator for, say, 3 hours, Who is the one that's cracking jokes to keep the morale up? Who is immediately trying to find the technical escape hatch? And who is checking their watch and calculating the lost productivity cost? Oh shoot, I think Jason's driving the morale conversation for sure.
I mean, like, thank you, Matt. Thank you, Matt. I'll take that. I'll take that. Jason has done some fantastic research actually on positive psychology and the impact on leadership.
And so there's absolutely like no question in my mind that that's what Jason Jason, uh, the escape hatch. And what was the other one? The escape hatch. Tracking the timeline when we get out of here. Yeah.
Oh dang, I don't know, that's kind of tough. I mean, Jason might also be calculating that productivity, but okay. So would we call that a split personality with him? I don't know, it's possible. I think Matt would probably jump to try to solve the problem with Ian kind of behind the scenes like, well, maybe we should look over there.
That's probably right. That sounds about right. Okay. Cool. All right.
So let's get into this. Let's talk here. First subject I have is security as a business catalyst. And, you know, we're all here about security. We all have a long history about security here or been involved with security.
So we're about to talk about something here called shift left. It's been a concept within cybersecurity for years now. And of course, what it really means is instead of being a roadblock at the end, we want to be a blueprint at the beginning. But how do we get there? We've been struggling with this for, again, years, right?
I mean, traditionally security happens on the right. You build the whole thing, and right before the launch, security steps in, finds a problem, and stops the train. That's why people say security is where speed goes to die. However, of course, moving the process to the left should mean having value creation and transformation.
And here's a question for you. Kind of, we'll focus a little bit on Matt here, but everyone, of course, jump in. But we often hear that security is where speed goes to die, right? Now, at Xactly, you've gone through some changes and these transformation things, and we've heard this so many different times. We've heard transformations, shift left, But what does that actually mean?
What is that, and can you put that in a tangible side, tangible piece of information? I mean, I guess for us, as we describe the arc of the business, I believe that we have been pursuing probably 3 meaningful transformations since this crew joined Xactly. So Xactly is a long-standing you know, a SaaS provider, but this group has been at the helm of leading the risk and security story for the last probably 3 years. And in those, in that time period, we've seen just like broader context, we've seen AI come to center stage. And at the same time, I think Exactly has continued to demonstrate our ability to win our unfair share of business at the enterprise.
And then similarly, we've been through a financial transformation which has brought on a handful of things. So the combination of those 3 things would be the way that I would couch it, and I think, Jason, in your words, maybe it's a go-to-market transformation, a financial transformation, or product transformation, right? I think those are the— yeah, so I think those are the things that we probably have been the major storylines in the arc of the business. Jason, I don't know, maybe you wanna add some context there. Yep.
I think you're right, 'cause I think this will come back to when we double-click on some things. So zooming way out, right? We are a private equity-backed software business, which has its own DNA, whereas if you, right, if financial sponsor, private equity firm acquires the company for a variety of reasons, there's really, that's on the clock, 'cause you're now what we call executing the value creation plan, which is identifying all the opportunities in the business, top line, bottom line, to drive, right, improve financial performance of the business. That could be across— yeah, go ahead. Yes.
For years, cybersecurity has been a word that makes a company's finance department see red. It's often viewed as a single lens, a necessary expensive cost center, a big black box where money goes in but profit never comes out. We invest in firewalls, training, compliance issues because we have to, not because we want to. But what if the narrative is fundamentally flawed? In the next section, we're going to talk about this and how security can be more than just a cost center.
It can be more of an investment.
So here's a question then for you. Or along those lines, what we've always said, that security is a cost center. How do you look at it? I mean, I say this from a security perspective, but from a CFO's perspective, can you honestly say that we are not a cost center, or are we a cost center? How do you see that?
So I think me personally may be different than others. Of course, what he's talking about here in the CRO is the Chief Resource Officer. Not usually a standard title. Someone that manages people, budget, tooling, data, and time.
What could be some of those responsibilities? Well, strategic resource allocation. How do you control that balance spend across Secure coding, IAM, also part of those preventative controls. Those detective controls: logging, SIEM, DNS visibility. And even those responsive controls: IR, focus, and recovery.
I think generally, unless it is a revenue, directly revenue-generating cost, right? Marketing, sales reps, etc. One could make the case that everything is effectively a cost center, right? And I would agree with you that the CISO organization can get bucketed into the less interesting spending because it is perceived to not be directly associated with, in this case, revenue growth. I think where Matt has done a good job and where companies can find success in getting out of that paradigm of being perceived as a cost center is aligning the activities that are being done with business objectives.
So for instance, in our case, we have continued to gain traction in large enterprises because our product suite, as Matt mentioned, part of the transformation was having a product set that is well situated for the large enterprise. Well, with that, we also needed to upgrade and uplevel our overall legal and InfoSec posture, right? So to some degree, like, my CRO is like, hey, unless we have best-in-class InfoSec, I can't put, you know, your InfoSec org in front of a prospective very sophisticated buyer. We need to make sure that you are not slowing deals down. So therefore, by aligning investments against InfoSec with a real quote-unquote sexy business outcome, in this case generating enterprise sales, it completely changes the conversation from a cost center to, oh, this is— it may be a cost, but there's real tangible strategic value to the function because you're going to increase the win rates of large customers.
In that case, everybody wins. But how do we show that? I mean, everything that you're saying is making sense, and we've talked about this, but what would be meaningful metrics to you? My standpoint, I'm currently serving as a principal security engineer. What would I do to make sure and get that message up to Matt and then eventually you to prove that I need this money, I need this half million dollars?
I think that's 2 questions. Yes, perhaps. I think the first one maybe, and I'll let Matt jump in, is again, let's go customer acquisition with large enterprises. How do you make the end-to-end buyer journey a positive experience where they're learning, getting what they need? So the way Xactly historically interfaced with customers was clunky, not obvious, not very interesting.
I think Matt did some very good job using AI and a bunch of other tooling to make the experience of the customer when engaging with InfoSec completely different to drive time to close of our transaction versus us getting in our own way. You know, go ahead, Matt, on some of the stuff. Is that— yeah, I mean, like, the things that come to mind for me would be when Sam gives, at the end of, at the end of the period, he talks about like, how did we do, and he gets to highlight some of the exciting wins that we've had. I think We have 70% logo attach rate, and because our revenue skews to the larger enterprise, like there's a few logos that dominate the revenue every quarter, we have an 80+% attach rate. So those deals don't get closed without InfoSec participating.
That's full stop, right? So 70% of revenue, or 70% of logos and 80% of revenue doesn't onboard into Xactly without the InfoSec team participating. And that's just That's full stop. But I think Jason's highlighting some of the other things that we've done to sort of streamline the experience. So behind the scenes, we've done interesting things which are really sales enablement if you think about it.
Like, yes, we got to get a SOC 2 and sort of have the basic credentials to participate in the conversation, but then we've also taken the forecasting app and done some AI pipeline-driven analysis with proactive outreach to our sales team members to talk about like, hey, we see these few deals are in the late stage. You're targeting closing these at the end of quarter, but they haven't started cyber diligence. And this is going to create friction and potentially cause delays in revenue onboarding. So that's one thing. I think we've obviously created these fairly robust packages, which, you know, 6 or 7 years ago wasn't actually as common as it is today.
And that includes, you know, the traditional artifacts that you're gonna have for closing deals within the enterprise. And we, we've positioned that proactively. And then we also talk about utilizing AI to ramp our team and to make sure that we've equipped the group. So we have trained some large language models on a handful of our artifacts, our policies, our control framework, some of the maturity that we have, and that allows a variety of folks to answer diligence questionnaires and engage with customers in a more efficient way. And so I think the combination of those things holistically help us drive revenue.
Um, and, but when you say a metric specifically, I think the logo attachment or the revenue attachment are probably the ones that come to mind like immediately. And if we're doing our jobs right, I'll give a specific example. Clearly there's going to be investment that Right, you need to underwrite. But there's also, if we're doing the job right, the investment case is actually getting pulled into the business. And I'll give you an example.
So end of quarter, right, a lot of— there's a lot of deal volume. So you need to staff, you need sufficient staffing, right, to enable quick response time for the sales organization to close deals. So We've had conversations like, look, is Matt's team along with our CRO, does he have sufficient individuals at the end of quarter to accommodate those requests? In that case, the cost of not closing a very large deal is very high. So CFO is more willing to invest in people and process to ensure that business outcome occurs.
Okay. So far we've talked a lot about closing the deals and the sales cycle, but focus more on the actual security and the services and not so much what exactly does, but in general, how do we use that to protect? Like, for example, right? I want Splunk. We'll just throw a name out there or a SIEM in general.
We're not associated with Splunk in any way, but I want some more money for Splunk and then I need some extra tools. I need extra servers. I need to go to Matt as a principal engineer and I say, Matt, you know, we need this to solve this. And Matt's going to go and try his best to, you know, Matt, how are you going to pitch that? And at the same time, you know, to bring Ian into this conversation a little bit here, at the same time, what about that legal aspect of it?
You know, if we get breached, what role do I have as a principal security engineer to make sure that I bring that to you? Should I bring it to you? So, but yeah, there's a couple of questions there, right? There's 2 separate questions there. One around, you know, the role of security and kind of a request in terms of justifying the purchase of Splunk in the first place.
And then there's a question of if there's a breach, should it come to me? And answering those 2 separately. In this next section, we're going to be talking about cybersecurity through the lens of a legal counsel. You know, the counsel views on cybersecurity are at the intersection of things like duty and care, regulatory compliance, litigation exposure, contractual obligations, and even corporate governance.
I look at what, from my perspective, from the legal, the contracting, the you're kind of making sure that we get signatures on the dotted line and revenue in the door and do so in a way that doesn't expose the company to risk. I look at it as security, just like compliance, is part of a product, right? And so at the end of the day, it goes to everything Jason was talking about with respect to speed to contract and everything Matt was talking about with respect to attaching logos through confidence to contract. But from my perspective, It is a fundamental part of the product profile that security compliance are effectively as much a part of what is being purchased by a customer in any SaaS platform in which data is involved. And obviously, there's a spectrum on which that is more or less essential based upon the nature and type of the data that they're responsible for and stewarding.
If they're a bank or a financial institution or a healthcare organization, it's higher. If it's less PI, more kind of PII-focused, maybe it's a little lower, but it doesn't really matter fundamentally in the analysis. Compliance and security are part of the product that is being purchased and part of the contracting process. So from Matt's perspective, when he comes and asks for that purchase, At the end of the day, it's going to be part of a sales cycle, sales process, contracting process, right? And it can be very onerous, very skepticism-driven on the part of the purchaser if they don't think we have security buttoned up, if we don't have data privacy buttoned up, if we don't have compliance buttoned up, then that's going to add a lot of extra friction, a lot of extra delay, a lot of extra doubt on whether contracts will close, how fast they'll close, how much diligence needs to be done on their part.
So it's a fundamental part of a product. I like it to be easy button from the old Office Depot ads, where when I buy a product as a purchaser that is buying a product in which some type of data or information is going to pass through, and I'm going to trust you as a steward of my data under whatever legal regime that is, be it HIPAA, GLBA, GDPR, whatever the regime is, I am purchasing not just the function of whatever that SaaS platform is. In our case, incentive performance incentive management. I'm also purchasing an easy button that my procurement and my legal team have hit to say, hey, any security issues, any compliance issues, any privacy issues that have to be worked through, wrangled, put together, you guys have already taken care of. So I'm hitting the easy button on that.
I'm just buying off-the-shelf compliant, secure, usable product that, yeah, there's technical configurations and implementations that need to be done, and there is with any SaaS platform. But at the end of the day, it's off the shelf, and I can use it tomorrow in terms of security compliance and know that it's safe. That's that. With respect to a breach, breaches are inevitable. But what about liability?
Is liability inevitable?
It's not if we get breached, it's how exposed are we when it happens. And a couple of primary post-incident questions are things like, did we know about the risk? Did we act on the known vulnerabilities? And did we follow our own policies?
Absolutely. That's an entire podcast in and of itself. We can talk about how it gets escalated. But yes, if Matt— if I'm not the first person on Matt's speed dial, then we have an issue going on between legal and security that needs resolving because we should be walking cheek by jowl in all of us. And I should be Matt's first call, both as the privacy officer and as the general counsel for any data breach, data security breach.
We can get into much more details about why and where and what sort of data breach security kind of instant response management, and we take that very seriously. But yes, absolutely. And I think that is also a part of our easy button, right? That when you are a purchaser and you are going through a contracting process and I'm on the other side of the table negotiating from you, that should be, do you have this all in place? Great.
Give me your agreements. I'll make one or two little tweaks here and there, but I can sign off on it. And that includes if there is a breach, do you have your processes down? Do you know exactly what's going to happen? Do you know how to respond?
Is that all part of the easy button I'm buying as well that's securing the taken care of. And I would just add on that, like Frank, you said as a principal engineer, you're looking to secure funding. I frame— I often, like, my pattern for framing an investment for Jason, or, uh, and oftentimes recruiting Ian to sort of co-collaborate with me as we take a business case to Jason, includes other stakeholders. So if I can have my CRO or my CTO saying these are necessary for core business outcomes that are separate and independent from InfoSec, then it's great. Like, this is going to accelerate our code deployment velocity, or this is going to improve the number of deals that we can get done, or this is going to improve our adherence to laws that we have to follow, or something like that.
Like, that— then it becomes much easier. But sometimes— so the other stakeholders that are involved, right, we have Obviously, I think cost, risk, and value is a nice framing. So you can think about how much are we going to spend relative to the others? And if I can bring in efficiency in other departments, that often helps me frame the storyline outside of just the limited staff that we have, right? Like no security team is as big as the rest of the broader org, and technology teams are always an order of magnitude bigger usually.
And then I think the other stakeholders that are involved are, of course, our regulators, And our investors. And sometimes investors play a more significant role than others. Like we're backed by Vista. Vista has 100 SaaS portfolio companies. They're all software companies.
So they have opinions on how this is done right and wrong because they get to learn at scale, right? Like they have $100 billion plus in capital deployed and they're seeing the sort of same patterns of, you know, a CTO with a bunch of people is developing software and releasing this and the faster they can release it. The more they can integrate the AI value drivers into their business, like the greater financial outcomes they get. So sometimes my framing is we have to satisfy our customers. Sometimes we have to satisfy the law and sometimes we have to satisfy our investors.
But at the end of the day, like I'm allowing those obligations in a variety of different ways to help dictate what we need to do. And then in addition to that, I'll complement with things like, this is going to reduce our tech debt and accelerate our deployment velocity, or this is going to— which allows us to deliver more features faster to our customers, or this is going to reduce the potential impact to discounts on our enterprise value because, you know, you need to have, you need to have something in place. And if you don't have that something in place, then it can erode the enterprise value at the point of exit or something along those lines. So I think there's lots of ways that I think about framing and each investment is unique. So when you say Splunk in particular, right, like the first thing that comes to mind is visibility, but many of these data visibility platforms have opportunities for cost sharing and collaboration across the technology org.
Many of these provide visibility that can accelerate other functions, and so probably my first stop on that would be how can I involve my CTO's org or my CIO's org in order to provide or deliver more meaningful value or accelerate or enhance some, some other things? So if I can, with Splunk, understand adoption of AI tools, or I can use Splunk to accelerate a consolidation of different tools because I can detect what tools are deployed in the environment and encourage a more rationalized tech stack that's optimizing the financial profile of the business. Like, those are all things that I'd like to bring to the table and have a partner at the table with me. So it's not just me asking for, you know, additional money to support a security outcome, but instead we're tied to some kind of key financial metric or some kind of productivity outcome or some kind of a value driver for the business. Well, okay, so, and I want to throw a challenge out there.
I know You know, I'm currently serving as a principal. I've served as a director before. But from those statements, right, I still haven't really heard from a tech head standpoint, are we going to get Splunk? What are you going to do for me, Matt, as a tech head that is protecting— that is a hands-on keyboard person protecting your enterprise, whether it's at your company or a client, etc.?
Are we going to get Splunk, or what do I have to do to get you to buy Splunk? And what would your expectations of me be as the art— as the technical— as a technical stakeholder in our business, or as the CISO? I'm— what role am I— what, in this hypothetical, what role are you having me play? Well, the role that you're currently in, the role that I know you of being in a CISO Right. And I'm trying to give some feedback for, I guess, the more technical people in the audience here.
Yeah. That are like, what we still haven't heard is, are we going to get Splunk? And what are you going to do? Are you going to give me all the money? What is the ROI, internal ROI, that I have to give you in order to get you to say yes?
Because I can't just— I mean, I think, Jason, maybe you can talk about Like you do this all day, every day, right? You have 50 people asking for money and you have to decide where to spend the money. So like, what's your thought process on getting to that? So in this podcast, we've talked a lot about CISOs. We've talked a lot to security leaders, to big, huge figures within this industry.
Now we're going to take a little bit of a shift and talk to a CFO. That's Chief Financial Officer. And this is where cybersecurity actually pays dividends, not in more alerts, but in developer decisions that force attackers to change tactics. I think first is— and I try to articulate this and I've said it out loud to a lot of my stakeholders— I think first is under the person who is asking for the money to really understand the mind of a CFO. So thing one, I am running a business.
I am not running a budget, right? So a budget is one of many guardrails, but I'm in my mind solving for a variety of conflicting priorities across the business, right? But ultimately I got to figure out where to— like, the default of the CFO can feel like it's no, but that's actually not the case. They're just trying to thread a variety of things. I think thing 2, if I'm an individual and I do this with my own CFO CEO in terms of presenting ideas or investments is, and I think Matt does this quite well, is having all of the arithmetic and all the ROI, however you want to describe it, but presenting it in shades of gray.
Right? It is not, Jason, you know, there are certain cases where thou shalt do this, right? And you got to know when to throw the flag on the field, right? But most of the time it is a trade-off decision between status quo and something else. So I think it's being very honest with oneself and when presenting to me, talking about it in terms of if we do this, we will get this and that.
If we don't do this, we'll get this and that. That signals to the CFO that in this case it's the CISO has really thought through. They aren't just blindly saying we need this. It is, I am, I really understand the trade-off decision that has to be made here and I'm sufficiently comfortable having that conversation. And then that opens, I think, through that ability to present the pros and cons, it's almost like you're playing the CFO against yourself.
You, build trust, in this case with the CFO, to have a real conversation around what it is we're trying to solve for. And I think you get much easier get to yes, because I think the default mode, at least of most CFOs, is skeptical of anything, not just information security, right? That's— I think that coming to the table with some open-mindedness and curiosity drops the guard of the decision maker to then enable a more rich discussion about what it is we're trying to solve for. Because again, the arithmetic is a bunch of assumptions, right? So while it may say ROI is X, we all know that can be a bit of an illusion.
So through that conversation, can really understand what it is underlying the arithmetic to justify spending more money or not. Okay. I think so. This is— if I can just throw something out there real quick, Frank. So I think as Jason was describing some of the things that I probably do, In the book, in, in the CISO Evolution, we talked about some decision frameworks.
We lean on Decisive. It's a book by the Heath brothers. And what's cool now that we have large language models is like, if you're framing your prompts, you can say, hey, use the WARP framework from the Decisive book that the Heath brothers wrote in order to help me frame this decision. And they highlight in their framework, and I forget off the top of my head the way the language they use, but they highlight like looking for why would this not be the right answer and sort of counterplaying this narrative. So by the time I get to Jason, I've already asked myself in a fairly meaningful and robust way, like, what are the good reasons to object to this?
And then allowed the answer with my team to be, our best answer might be we don't spend this money. The best answer could be Splunk is a waste of money. And in some cases it is, right? Like, Splunk has lost, I think, a decent bit of market share because they are not currently aligned with their customer base. They are— their financial model is broken, right?
Like, they don't incentivize you to give them more data. They disincentivize that. There's an entire niche industry around limiting the amount of data that you send to Splunk because they charge you an arm and a leg to receive that. And on the flip, folks like Snowflake and others are very eager to have all of the data, and they charge you on compute or other incentives. So only at the point where you deliver value through compute do you actually get charged.
And I think that's a much more productive business model. So an example would be maybe the answer is we shouldn't spend more money on Splunk, and then if we should, like, we have to overcome some of those counter-rhetorics to really be convinced, like we hear what you're saying and those are all alternatives, but in addition, we're going to get X, Y, and Z or something like that. So, um, yeah, well, I mean, I currently work in risk management. I'm a principal engineer while I've had hands-on keyboard experience. But, you know, Jason did mention risk management or in deploying that risk.
So we've got a couple of things in play here. We've got, you know, you're telling me not to use Splunk and Jason's talking about, you know, what is the risk here? My answer, if you say we're not going to use Splunk, give me an alternative or something like that, whether it's these other products— again, we're not aligned, or, you know, we're also not against, at least, you know, in this podcast, against any specific product. However, what would you say? I mean, when you're telling me we're not going to put more money into Splunk, my frustration back would be, you know, and of course, since I don't work for you, Pat, I can say this, right?
Is that, well, blank you, right? Because we're not gonna be able to stop these threats. Well, so it's interesting. So I just want to be clear, uh, I think Splunk has a great technology, right? I think Splunk has done a really fantastic job.
But what I was trying to present, and maybe it didn't come across, was an abstract method of thinking through the challenge of getting a particular technology, in this case Splunk, funded. And so what I was saying is, if you make no an acceptable answer, then oftentimes you find your way to yes. But if you don't make no an acceptable answer, as you navigate the debate internally, you're ill-equipped to defend the position that you need to defend in front of your CFO. That's what I was trying to say. So I'm not saying Splunk yes or no at all.
What I am saying is the pattern of preparation and considering a decision is really important to consider the alternative perspective, like the counter. And so this, again, with AI, this is another cool thing you can do is you can say, hey, play devil's advocate for me and ask me the most challenging questions that would undermine this investment. And then you can actually answer those questions with your team. And if you still get to the right outcome, then cool. Like the idea that you can't detect certain attacks that are common in the marketplace today, or the idea that you're not able to fully address the MITRE framework, or the idea— like, those are all interesting things and capabilities that InfoSec wants.
But as a result of having those capabilities, the real question is, what do you deliver to the business? If the only thing that you're delivering is downside risk and you keep asking for more and more to deliver a reduction in downside risk, And it's, and like, there are diminishing returns on all investments, right? And so I think Malcolm Harkins talks about this in his Nine Box. He says, you have to consistently show how you're going to deliver greater risk outcomes with lower incremental spend on the total budget. So if Exactly has this explosive growth arc, and I can say you're gonna spend a smaller amount on the total growth over time, that's a positive narrative, which basically allows Jason to say he's gonna contribute larger and larger amounts of EBITDA to the bottom line and back to our investors.
And if I can also say that we're gonna accelerate the way that we deliver features to our customers, we're adding value to investors and we're adding value to customers. And then, oh, by the way, we're getting these other outcomes. So I always anchor to some of those other things. It's like, How are you going to tell— how are you going to get somebody else to say yes? More often than not, it's by letting them understand how they benefit.
And then, yeah, okay, at some point you're going to say, like, we have to be able to detect all of these MITRE framework attacks because if we don't, we're going to be in the news. And at some point, yes, you have to articulate that too, but it's always my last stop. Like, we'll say— I will highlight the security value or outcome, but it's after the other elements have been there, right? So value and cost are first for me always, and then we have the conversation on risk. Okay, well, I want to take a shift here because we've got about 20 minutes.
I want to ask kind of a fired-up question, so it may take us more than 20 minutes to do this, although I think we have some hard stops here. But here's a question because we mentioned this a couple of times already. Who actually owns the risk of AI? Is it a legal issue, right, of data leakage? Is it a financial issue, or is it an actual security issue?
So I have— that's— yeah, let the lawyer go first. That's a good— we'll let the lawyer go first. But I think this is, again, this is a very fired-up question in here that's going to be hot on everybody's minds. It's absolutely hot. I mean, I will say that this is exactly what I had in mind when I was talking about the easy button in compliance as a product, right?
AI is a great example of that right now, where it's a very complex and nuanced landscape with respect to liability and who is responsible and who— and also with respect to ownership, as in who owns inputs, outputs, training models, all of that type of thing. And so there is a a major shift right now to try and make all of that kind of easily figured out by somebody else in the contracting train. You know, customers want vendors to have it locked down. Vendors want to be able to control it, but have customers kind of agree to terms. And so it's very much a complex influx area right now where everybody is trying to, for lack of a better word, delegate or democratize that liability you're asking about and that ownership you're asking about.
Ultimately, though, I believe, and this is probably my bias as the general counsel, and also, you know, as a privacy attorney by training for the last 20 years doing privacy matters, I believe that you start working your way backwards. And the way it works backwards is, right, ultimately with AI, it comes down to right now 2 large questions. It comes down to ownership and liability. You know, on the positive side, there's the question of who owns all the wonderful things that are being produced in the AI world, whether it's a model, whether it's a You know, kind of creative work that's coming out and there's copyright questions that go into that from a right of authorship and all that type of wonderful stuff. And there's the exciting side, right?
AI is creating a lot of, for lack of a better word, stuff, whether it's works of authorship, whether it's models, whether it's inputs, outputs. There's a lot of great stuff being created. Um, and there's a lot of excitement about who can own that. And that's fundamentally a business imperative. As in value to the business and value creation.
But it's a legal question, right? Because the question of who owns what, and who has rights in it, and who can license it comes down to the kind of legal structure in which that works. So it has to start with legal as the analysis, trying to factor in. With respect to the dark side of AI, which is this liability question, who's going to be responsible for when things go wrong? When the sky falls in and somebody has got a data breach, somebody is being sued for a copyright infringement lawsuit, somebody has to answer to restrictions on when they can or can't use a product that they've sold because the models are included.
Do we have the rights to use the data? Again, I think that is currently at this stage primarily a legal question. There is a business and security imperative behind it. Because they drive a lot of the inputs and factors that have to go into those legal determinations. Who owns data and who is responsible if there is a data breach is a negotiated legal question that either will be negotiated at a national level with things like statutes, just as they were in the heady days of the dot-com bubble when we had all these same questions about who owns all the great stuff we were creating on the internet.
And that led to the creation of laws like the Digital Millennium Copyright Act and the Communications Decency Act. And it all kind of got sorted out that way. And we're seeing it play out that way in various states and internationally in laws like the EU AI Act. Or it's a contractual issue, not by statute, a legal issue not by statute, but by contract and negotiation. And that's where we are, I would say, right now.
For example, Our AI addendums outnumber any other kind of contractual request by 2, 3 to 1 right now, because everybody's trying to figure that out with AI addendums. You know, everybody has existing clients, prospective clients, vendors. There is not a day that goes by that we don't receive multiple AI addendums where everyone is trying to figure this out. So again, it's a legal question. But it is reliant upon the financial and the business imperatives that Jason is kind of in the weeds on day on day, and the security questions, and then the fourth factor, the privacy questions.
So in terms of who owns it, I think it's joint ownership across all of those groups. In terms of who is ultimately responsible for it at this stage in the relay race, I think we're in the evolutionary step. You know, if you imagine those steps of the monkey kind of stepping up through Darwin's trail until it ends up with a, you know, the caveman walking at the end. Right now we're in the evolutionary step where it's with legal, right? We have to decide kind of what is the liability, who, where's the liability going to go?
What are the privacy implications? Whatever. And then it's supported by security in terms of effectuating all of those. Decisions that are made. If we make a decision, you know, as a group that, hey, the ownership of AI data belongs to this person here, this company here, and it can be used for this purpose here, then it's going to be security's obligation to execute and make sure and enforce and be the policeman to make sure that data goes where it's supposed to go.
That the data that has been promised won't be used to train models doesn't leak into a model. I feel like we have a really interesting conversation or story that we could actually share that's very, like, very prominent on the AI front, right? So we have agents released in market today. We have AI embedded in our product. We recognize that those agents have non-deterministic behavior.
We also recognize the state of the art is evolving, and we also recognize that the legal liability framework and the expectations from the legal community are still opaque. There's no established litigation precedent by and large. And then we also have some executive directives on like who owns the legal liability, and so it's a really interesting time. And one of the things that we have done, there are many, you know, in terms of understanding shadow AI, understanding MCP, understanding agentic workflows, but on the non-deterministic perspective, We've brought in a third-party provider to help us do some automated testing and give us statistical outcomes across a variety of tests, whether those be ethical transparency, whether those be, uh, product abuse from a prompt injection perspective, and on down the line, right? And so getting to the decision of should we buy this actually was brought to our AI Governance Council.
And so of course we had to have the conversation with Jason on how much we're going to spend and how that fits into the annual operating plan, which it was unbudgeted. And then we also have to have the conversation with Ian on does it make sense to spend it? Is this a way that helps us position ourselves in a legally defensible way? Because non-deterministic inherently, we can't solve for 100%. There will always be in a non-deterministic outcome some exposure, some risk.
And so the question is, how big is that risk and how do we quantify that? And so in this case, we ran statistical analysis with a series of prompts in order to get us to a point where we felt like we were reducing legal liability, demonstrating state of the art, and also achieving that in a reasonable budget profile. And so I think like that's an example of how the 3 of us shared the outcome of AI risk. Yep. Okay.
Jason, how about some feedback from you on that one?
Generally speaking, I mean, I think, look, the— I think these, from my seat, it is ensuring, because these guys clearly have a handle on a level of detail that the CFO and the CEO don't. We need to have a general understanding, but the specifics, like, we have too much going on, right? So I think from my seat, ultimately, when you ask who's responsible for this, who's the ultimate owner, I went to the CEO who is on the hook for this, right? That role that has been delegated to me by virtue of having Matt Ian on my team, right? But we have other stakeholders in the company who are outside my quote unquote chain of command product engineering, right?
So my job then through that delegated ownership from the CEO to me is to ensure we have an overall mechanism of governance. To ensure that we are collectively elevating our awareness of all of the risks and landmines that exist and then understand how to best mitigate those risks in the context of the resources that we have. In parallel, that's like the technical side of it. I think we also have effectively XMOS. Is that what you exactly mean?
An operating system or is it— Yeah, in part. So I think it's like we have our InfoSec We have our governance committee around AI and InfoSec, right? I think separately, organizational health, which is do we have alignment and accountability and trust within the organization? We spend a lot of time— in fact, we had an offsite this week around building just human-to-human trust, right? Because with trust, you can then engage in healthy conflict to get to the right outcome.
So we as a company focus there. And Matt and Ian know on our team spent a lot of time to make sure that we are building trust. So when we are having— right, again, there's always conflicting priorities— when we are having these conversations, it's coming from a place of, A, we trust each other, B, we are looking out for the best interests of the business. We aren't Matt's not looking out for Matt. Ian's not looking out for Ian.
The head of engineering's not looking out for head of engineering. We have built a culture and a governance structure that together result in getting to the best of our abilities to solve for the right outcome. Well, and, and kind of on that lines here, I'm just gonna shift a little bit here. Well, actually, I do want to go back and talk about how do you build human-to-human trust? I mean, we say it all the time and we talk about team building and you're doing offsite.
Is that really effective? You know, do you— I mean, I think you have to be— I mean, I could talk for hours on this, so thank you for the softball. Look, I think there are— there's a variety of discussion mechanisms to build trust. There's what's called the long version, which is progressively doing what you say you're going to do, right? So over time, you are building, right, that connective tissue that you're eventually— because I know Matt's going to do what he's going to do, and he's done it 100 times.
I built— but that takes a long time. The fastest way to build trust is through vulnerability, right? In other words, exposing things about yourself Right? That could lead to people thinking you're weird or funny or not smart or whatever it is, right? So there are very practical tools that you can do in team-building exercises to enable individuals in a safe environment to be vulnerable.
That is proven to be the quickest way for teams to build trust. And then certainly that is augmented by the continuing to do what you say you're going to do, and collectively you get to the right place. Well, let me give you a counterpoint here, please. Right. And give you a counterpoint, especially, you know, coming up from, from me with a tech head.
I think I'm the odd person out by being a bit outgoing. Most of the people that are in this industry, in the cybersecurity industry, are introverts. Sure. They don't want to talk to people. We don't want to show our vulnerability.
We don't want to show that weakness. So I think that that's the job of the manager to mirror that behavior. Because my experience has been at which point somebody on my team has seen that, hey, you know what, I don't— I have no idea what the answer to that question is. Or yes, my, my personal experience is I totally fumbled on these 3 things in my career. Thank you for sharing that story.
Or once the leader has to expose their own vulnerabilities over time, And I have found that over time it enables an environment for those on my team to then find themselves doing the same thing. So essentially it's falling on Matt's shoulders in this case, right? Matt, you know, I'm your tech head. I don't want to talk to you. I mean, even if we bring back this conversation to Splunk, you know, my answer is blank, right?
What do I have to do to get this blank tool, right? And Your part is, of course, again, as a tech head, I don't really want to talk to you, right? I want to sit down at my keyboard. I want to put my hoodie on, and I don't want to talk to you at all, right? But you know that you need me and I need you.
How do you encourage me to get, you know, the information you need so that you can deliver it to Jason and Ian in a format that will get them to say yes, right? While going back to what you're— you were saying earlier about you know, expect to say no. Yeah. I mean, I think like, so Jason highlighted his theory on building trust. I always go back to Stephen Covey's book on The Speed of Trust and they have concentric circles in the model of building trust.
And they talk about the, they talk about 4 C's. So Jason talked about like in other frames, do, say, but I think there's also competence. Right? Like, just because you've consistently done the things that you say you're going to do, if you're not an eye surgeon, I'm not going to let you do surgery on my eyeballs, right? Like, you've got to have the competence.
So in addition to that, you have some other, there are a couple of others and I think there are, there's a, the nice framework on speed of trust highlights 4s, there are 4 C's. And so without getting into that, I think that's the frame that I use. And you can do a meaningful analysis to know where you're at on the journey in terms of building these concentric rings of trust. And so from my perspective, like, I like to take an individual or a scenario and run it through that framework and understand where I'm at. And then once I know where I'm at, I can think about what are the next steps, right?
So if I have a technical stakeholder, a person on my team in particular, and we need to build some trust, the first thing they need to know from me is that we have alignment on the outcome that they're attempting to achieve. So if what you're trying to achieve is buy Splunk, the questions underneath that have to be the whys. And then if we can agree on the whys, right, then I become your advocate, right? And so then the next piece is how do we collaborate and sell this? And I might say, hey, I don't think that we can get this past the— past Jason because of these counterpoints and we need to bring other stakeholders in or we need to bolster the business case to the point where we can say yes.
And oftentimes I think what happens in that process is you're forced to explore alternatives. And so yeah, so I think your question is how do we get to a decision and how do you engage? I turn it into not necessarily about you being vulnerable But instead about how can I enable and help. And I think that transition, like generally people, it doesn't matter how introverted or not you are, if you believe that somebody is trying to advocate on your behalf for an outcome that you strongly desire, you're going to go along with them on that journey. Right.
And so I think having that genuine intent in the back of my mind will be there. And I may disagree. With your decision that we need to do a thing, but I believe that if we go through that journey of the decision together, you will rationally decide— if I've done a good job hiring people, right? Like, you're a smart technical guy, Frank, so I know that you would decide the right outcome along that journey. And I don't have to say, Frank, I'm going to challenge you, or we're going to participate in some kind of Socratic, uh, uh, conversation in order for you— for me to ultimately reveal to you that what you're advocating for isn't actually the best decision in the business.
And then I think there's also some truth to, look, even if you and I agree and we do our very best to present a very meaningful business case to the business, there may be other things that we don't know or we don't understand that the business disagrees with. And in some cases, our job stops at choice architecture. Our job stops at building the best choice available and documenting that so that the folks who are at the end of the day making the decision are ultimately fully informed and accountable for the decision they made. So if Jason says, Matt, you're not getting Splunk, it's a terrible investment and it's not appropriate at this time, then that's cool. We'll have a paper trail of the business case that was presented, and ultimately we may say, hey, here's the risk that you're accepting, and put a risk acceptance form on the table for him to sign.
And if we've done that, like if we've done all of that, I find that my technical stakeholders will say, look, we presented it, the business did not agree. And at some point you may say, look, the business is accepting wild and crazy stupid risks. We just, this is not the place for us. Like InfoSec is not valued here. And I would encourage those people to go find a better job where their talents and skills are gonna be utilized, right?
I think, but I think you have to do the diligence to get to that point. I don't think that that's the first stop. Like, hey, they're not listening. You know, pull the parachute, we're out of here. Like, that's not the decision-making process.
How does that fall into a legal standpoint? I mean, you mentioned here's accepting the risk from a CFO standpoint. And, you know, from risk management, we say this all the time. But now that I actually have a general counsel in front of me, what does that actually mean? How— give me some feedback on that one, Ian.
Well, in this last and final section here, we're going to be talking about the hot topic from 2025 and assuming to be 2026, AI governance and risk. I think this goes to, Matt mentioned earlier, the kind of AI governance committee, which is a good example of kind of shared decision-making that way. I think for any decision, the Splunk decision would be a similar one here too, right? Which is from a legal perspective, we would be one of the players in that decision-making process. I think obviously the risks that Matt was talking about that have been weighed and assessed and decided, hey, we're not getting Splunk, it's too expensive.
There would have been a risk management component to that analysis, right? It wouldn't just be Jason saying, dude, you've spent way too much money this year. You're not getting that money back. There would be a collaborative approach, which would be like, at the end of the day, Here are the risks that Matt is trying to fix or to plug with Splunk. Here's the liability issues, here's the risk issues, here's our legal obligations and, you know, privacy obligations and risk obligations that we owe contractually, we owe the statutes, we owe the whatever is the applicable duty of care.
Here's what the decision not to get Splunk would mean for meeting those various levels that we have to meet, and that would be factored in, in terms of, okay, is there a way that we can still meet legal requirements without Splunk? It wouldn't be as simple as just, no, it's too expensive, and it doesn't matter if that means that we're going to not be able to, you know, respond to a CCPA request for a data subject, for example. It would be, okay, we still have to meet all of the legal requirements. So that decision to say based no would have being, you know, kind of predicated upon from a legal perspective, can we say no and still be in compliance with our obligations? And, you know, the decision to say, is there a better way to do it?
Is there an alternative way to do it? Matt, if we don't get Splunk for you, how are you going to meet these 5 different obligations? How are you going to be able to respond to a CCPA request for somebody to change their data that's contained in our system, for example? All of that would have been factored in. So I think it's a lot more intertwined, but as simple as Matt would have gone to Jason and said, I want this, here's my security reasons.
And Jason says, no, it's not worth it. We're not going to do it. There would have been legal consultation. There would be my consultation with the privacy function as well. There would have been the stakeholders in terms of who Matt was addressing the various, you know, the sales team, the commercial team on, is this going to be the best way for the client?
For the customers? Is it going to— all of that would have been taking place in some kind of larger governance collaborative process. I mean, usually the consulting version of this is called pre-wiring. I know what Jason's going to say by the time I get something on his desk, and I often don't put something on his desk that he's going to say no to because I already know the answer, right? So I think, yeah, and so I think the hardest conversation— I'm just thinking about the last few years, Jason— the hardest conversations that we have had I feel like the prominent statement that comes out of your mind, out of your mouth, is, Matt, we need to land on the right side of history here, or some variant of that.
Can you talk about the— like, just talk about the— like, there's— it's not an open and closed case. There's some ambiguity here, and we want to make sure that we— can you talk about the way that you think about that? I think that would be interesting. And then I think, um, like Frank, the fact that Ian has general counsel is awesome, but he served as the lead of a privacy practice for one of the major law firms. And so like, I don't have to educate Ian on privacy law, which is different than interactions that many CISOs have with general counsels, right?
So I gain that benefit, right? Like I show up and Ian already knows the answers. I don't have to educate him on possible concerns and encourage him to do like research on case law and other things. Like he already knows that and he's lived it firsthand. So, but Jason, like the history thing, I think that like, this is one of the reasons that I like reporting to you as a CFO is because of this, like your strong bias towards integrity and the history filter.
I mean, I think you're right. I mean, I think, yes, the statement seems self-evident, but it's also a bit nuanced. It's Yes, we want to do the right thing, but the right side of history is open for definition, right? So it introduces the notion that there is judgment involved, there's assumptions involved, and what does it mean to be on the right side of history? The line in the sand is we want to get there, the integrity piece, but how we get there in the definitions and assumptions about what the right side of history is where we have a very healthy conversation.
Okay, well, I mean, I think we can continue this conversation for probably the next 3 or 4 days. I don't— we definitely don't have that time. Are there any final thoughts to this? Any final pieces? Anything else that you might want to add?
I mean, my thought on— I think traditionally the Colorado Equal Security Podcast for this section has been focused on leader journeys and at the end of the day, I think the reason that what I sold to Jason and to Ian for coming on this podcast— because I don't— I think this is pretty abnormal. I don't think that having a CFO and a general counsel and a CISO on a podcast is a very common thing for you guys— was how can we add, uh, how can we add to the community? What is our net contribution to the community? And how can we use this as an opportunity, sure, to expose that Exactly is a great product and whatever, but also just as a very selfless attempt at contributing to the greater community. Colorado Equals Security is a foundation that has created Colorado as one of the strongest security hubs in the country, in the world, you could make the argument, right?
Like, we had some of the early meaningful laws passed inside of our state. I think going back, uh, you know, to a time before this, we had Rick Dakin, who was at some point the CEO of ColdFire before he passed, was advocating and working hand in hand with Mark Weatherford, who later went to California and then reported directly to the president, right? So we have a long, robust history of very strong cybersecurity in Colorado. And the question is, like, what can we actively contribute back to this cybersecurity community that is so strong and that has such a robust history with so many strong leaders? And so for me, the answer would be to expose some of the inside baseball on how decision-making actually occurs when things are difficult.
That's what I was hoping to leave with the group. Um, but Jason, Ian, I guess I would encourage you guys to use this opportunity to, you know, like, you have unique perspectives with unique disciplines, and like, what can we actively contribute back to the community in the most selfless way? You're asking a lawyer how we can contribute to privacy? No, no, no, just try to keep it within the next, you know, like, maybe levity. No, I mean, I think part of, you know, I've spent 20 years now in Denver specifically as a privacy and tech and technology attorney.
You know, I spent the first 15 years at law firms doing it for hundreds of clients. So I have the breadth and the One of the things that I think is always essential and always a great message out there is the degree of, and I think even you reflected it by the choice of who you had on this podcast, Matt, and not just having kind of a security leader on, the degree in which collaboration between the compliance, security, finance, privacy groups really is essential because One of the worst possible things that happens is siloing and fragmentation. And the amount of data breaches, the amount of data responses that I have managed for various clients over the course of my career that have been caused by one hand not knowing what the other hand was doing and decisions made in isolation that are sometimes a happy coincidence, it works out, but more often than not are conflicting or contradictory. I think the idea of a contribution here, but the inside baseball, is that it really is not a one single discipline area. The choice of getting Splunk was a great example, right?
Into Splunk goes, what is the benefit for company? How much is it going to cost? What is the security aspect from security asking for? What compliance needs is that going to help us meet? And will it help us meet all the compliance needs, or should we look at a different secure, uh, different avenue?
What are the contracting implications with respect to now we've got to tell everybody that we take their data, that Splunk is a subprocessor, is that going to cause it? All of these things are very interdisciplinary. And so for, if I was to say anything for inside baseball, contribute back, it's the value of building kind of a shared vocabulary and a shared experience with your peers in all of those other disciplines so that you are all kind of working as a group and a single organism. You know, Émile Durkheim's theory of sociology, right? That society is an organism in which we're all doing our own little piece.
It's the same thing in security and compliance. It's a living, breathing organism in which we're all organs doing our own specialized function, but we're all part of the same body. You know, and so that would be my one contribution back is community over, you know, kind of specialization. Okay. And Jason, any feedback on that?
Any final thoughts from you, sir? I mean, I think pulling on both of those threads, tackling all of what we talked about is a team sport. And as Matt would say, it's a contact sport. But I think what that means is, from a contact perspective, it's in the team that we are working is to have— because we're going to have internal debates and discussions to get to the right outcome— is having some compassion and grace for the individuals and the process. And if we are trying to be effective as a team versus just being right, it kind of drops the ego of everybody involved and we are united in our goal of trying to get to the right outcome.
Okay. Well, and I think again, that last statement about the egos and everything else, that could be an entirely another podcast right there. Right. But we are out of time. In fact, we're actually over time right now.
So I want to thank you for joining, taking time out of your day. If you need to find Matt, Jason, or Ian, we will have their LinkedIn profiles in the show notes. Again, my name is Frank. I am now the president of the Denver chapter of OWASP. And of course, the hosting of this podcast.
We did talk about community events. It's not posted yet. Neither one are officially posted yet, but we will have a community meetup on January 25th. 1st at our usual spot in Dave Buster's. We will have a sponsor out there.
We're gonna be playing the Backdoors and Breaches game, right, for incident response. And of course, I can't leave this podcast without promoting SnowFROC, the Denver OS SnowFROC. We're going a little bit later this year, but we are gonna do a 2-day conference with April 16th and April 17th with Tanya Janke as our keynote speaker. I hope to see everyone there. Again, gentlemen, thank you for your time.
I appreciate it and have a great day. Thank you. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.