CXO Spotlight · 2026-08-25 · 44 min
Key moments - from our scoring
Substance score
67 / 100
Five dimensions, 20 points each
Smartsheet's 2026 research reveals a critical governance gap: 94% of workers use AI daily, yet 7 out of 10 use tools their employers don't know exist, with only 1 in 4 companies having governance frameworks in place. Ravi Soin, CISO at Smartsheet (owned by Blackstone and Vista after an $8.4B acquisition), brings a builder's perspective from Microsoft and healthcare software (FX, where he spent 15 years). Rather than positioning security as a blocker, Soin advocates for embedding governance into product development from day one - using frameworks like NIST 8.5.3, threat modeling, DAST/SAST scanning, and AI-assisted code review integrated into the developer pipeline. Smartsheet's Smart Hub provides real-time event logging and auditability for AI interactions, enabling administrators to see exactly what agents do when crossing system boundaries. His dual CIO/CISO lens demonstrates how guardrails and innovation aren't opposing forces; they're complementary. The platform serves 85% of Fortune 500 companies managing critical workflows from satellite launches to manufacturing, making data governance not just a compliance issue but a core product feature. For enterprise operators, this conversation addresses how to implement governance at scale without strangling velocity.
Seven out of 10 workers use AI tools their company is unaware of, while 94% use AI for daily work. Only 1 in 4 companies have governance in place to manage this shadow AI.
Smart Hub provides live event logging that tracks every AI interaction - including when agents cross system boundaries - allowing administrators to see activities in real time and trigger alerts before incidents, not just after them via forensics.
It removes the false choice between speed and security by embedding controls into the developer pipeline (threat modeling, code scanning, AI-assisted review), so governance gates are upstream checks, not post-release blockers.
Smartsheet maps all product controls to NIST 8.5.3, ensuring every application and AI feature adheres to the same compliance framework from day one, not retroactively.
Vista and Blackstone's portfolio scale enables 24/7 global SOC operations (Bulgaria, India), shared best practices across companies, and access to modern tools and talent infrastructure that standalone organizations couldn't achieve alone.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains substantive ideas about shadow AI governance, responsible AI frameworks, and integrating security into product development, but is padded with considerable throat-clearing, repeated points, and conversational filler. Key insights (7 of 10 workers using unknown AI tools, real-time event logging, treating security as a profit driver) are present but diluted across 44 minutes.
Seven out of 10 workers use AI tools in their company don't even know that they don't company don't even know about
the governance and security is actually part of the profit equation because my product is bought for another reason, not just the feature, but because the governance it brings with it
The core framing of security as a revenue driver rather than a cost center is fresh and pragmatic. However, much of the execution advice (defense in depth, NIST frameworks, threat modeling, MFA) represents standard industry best practice rather than novel thinking. The sustainable IT angle adds some originality but receives minimal development.
the governance and security is actually part of the profit equation because my product is bought for another reason, not just the feature, but because the governance it brings with it
AI is a trust enabler, not a prohibitor
Ravi Soin is genuinely credentialed: CISO at a major SaaS platform (85% Fortune 500 usage), former product builder at Microsoft and Sun, 15 years at healthcare software, and won Seattle CIO of the Year. He has operated at scale and holds dual CIO/CISO responsibility, which is rare. This is a practitioner, not a thought-leader-for-hire.
The person who hones the problem here is Ravi Soin, CSO of smartsheet
chief Information Security officer protecting how 85% of the Fortune 500 actually works
The episode includes concrete examples (phishing automation, event logging infrastructure, NIST 853 adoption, SOC with Bulgaria and India centers) and real stats (7 of 10 workers, 94% use AI daily, 1 in 4 have governance). However, many claims lack granular evidence: no dollar amounts for security investments, no named third-party integrations for Smart Hub, no specific vulnerability timelines from Mythos, limited detail on actual Smart Hub capabilities.
Seven out of 10 workers use AI tools in their company don't even know that they don't company don't even know about. And uh, 94% use AI for daily work. Like look at these two stats in comparison. And only one in four company have the governance in place.
we have rebuilt our SOC infrastructure to be very AI, uh, agentic way of tracking things. And How we're leveraging these tools. We are leveraging a global organization. 24 by 7. Right. We're working with folks in Bulgaria, we've got a center as well in India.
The host asks solid thematic questions and creates a structured narrative arc (problem → solution → budget/board conversation → skills → future). However, follow-ups are often soft; when Ravi makes bold claims (e.g., about Mythos or AI-powered phishing response), the host rarely probes with skepticism or requests specifics. The shadow art story is charming but derails focus. Questions frequently lead rather than probe.
You know, I was smiling because this reminded me of a story, and it's a personal story, where my son in the middle school had to participate in like a state competition
Did you have to update your incident, I would wonder. So that with AI and everything going on, you would have to update your incident response very quickly
Computed from the transcript - who did the talking, and the words that came up most.
Ravi Soin, Chief Information Security Officer at Smartsheet, explains why 7 out of 10 workers use AI tools their company can’t see, why governance is now part of the profit rather than just the loss column, and how he answers product teams who want to ship AI agents to Fortune 500 customers in three weeks.Ravi spent 15 years building products and securing them across Sun Microsys-tems, Real Networks, and Microsoft (Education, Windows Office, Bing), before becoming both CIO and CISO at a healthcare software company in a regulated industry for 15 years. He joined Smartsheet, the work execution platform 85% of the Fortune 500 runs operations on, after Blackstone and Vista paid $8.4 billion to take it private. He is now building the AI governance layer for how some of the largest enterprises in the world actually run their work, where the data being protected is not credit card numbers but the project plans, resource decisions, and strategic timelines that define how a company operates.
Transcribed and scored by The B2B Podcast Index.
Speaker A: The platform that 85% of the Fortune 500 users use today and their actual operations proved that with their own data. The person who hones the problem here is Ravi Soin, CSO of smartsheet.
Speaker B: The time to exploit is coming down from it used to be years became months, it became days, and now it's an hours.
Speaker A: Mozilla, uh, found out with Mythos that it found decades worth of bugs in a day or things like that. That almost always will make you feel that this is not enough, what we are doing.
Speaker B: In my mind, AI is a trust enabler, not a prohibitor.
Speaker A: The governance and security is actually part of the profit equation because my product is bought for another reason, not just the feature, but because the governance it brings with it.
Speaker B: You've heard horrid stories about cities losing power because it's all going to data center.
Speaker A: Seven out of 10 workers use AI tools in their company don't even know that they don't company don't even know about. And uh, 94% use AI for daily work. Like look at these two stats in comparison. And only one in four company have the governance in place. So tell me how bad is this reality? Or behind those numbers?
Speaker B: I think the shadow it has been a problem for a very long time. You.
Speaker A: Welcome to CX Spotlight. I'm your show host, Chirag Khanjo. Seven out of 10 workers in your company are using AI tools that you do not know about. And only one in four organizations have done anything about it. And the platform that 85% of the Fortune 500 users use today and their actual operations proved that with their own data. The person who hones the problem here is Ravi Soin, CISO of smartsheet. He started as a product builder at Microsoft, held both CIO and CISO role at ah, the healthcare software company, and was brought in after Blackstone and Vista paid $8.4 billion for Smartsheet. He's building the governance layer today and that is why this conversation is important. Ravi, welcome to the show. How are you doing today?
Speaker B: Good, thank you so much, Chirag. Pleasure to be here.
Speaker A: Awesome. I want to start somewhere at the little bit of beginning before Smartsheet, which is you built education products at Microsoft and now you are the chief Information Security officer protecting how 85% of the Fortune 500 actually works. That's not a typical path into security. Um, what did building products teach you about protecting them now?
Speaker B: Yeah, no, great question, Chirag. As you said, my journey into, you know, being a CISO and CIO at Smartsheet really, uh, started as being a builder, right. I'm a builder at heart. And whether it was back in the day working at Sun Microsystems to real networks, to Microsoft, you know, as you said it was education, Windows, Office, you know, lasting was at Bing, you know to working at FX where we were actually, you know, started out as the healthcare from M, you know, the payer side of the equation and building the technology stack for that. And I was there for 15 years building products, securing it. So I think the vantage point that I have is having been an engineer, knowing what it takes to build products and has really helped to uh, especially coming from a regulated industry like healthcare that EDFX was in for 15 years and now at Smartsheet, right. We as you said, 85% of the Fortune 500 customers, both regulated industries as well as large enterprises. I think that vantage point is really, you know, has been instrumental in how we think about risk and governance, but at the same time uh, keeping pace with the, the speed and innovation that is expected off of software companies. Right. So solving meaty problems, solving, innovating at the scale, you know, and now with AI, you know, innovating the scale of AI cloud first. Uh, right. I mean that, all of these things that we just talk about elastic demand and, and the future of computing and I think security for, for me has become ingrained in what we build because at the end of the day the governance layer has to be there. And I think the other flip side of that I will say is that typically most CISOs uh, come from a uh, risk background. And to your point earlier that you made, I come from a product and engineering background and I bring that to software organization.
Speaker A: I find the second vantage point even more interesting, which is the CIO and CISO lens together. I want to address this elephant in the room because it is so interesting that often in enterprise technology you would find CIO and CISO a little bit at odds with each other because the CIO is being asked to deliver at warp speed. I saw this AI, I want it in next month. And the hurdle behind that is the governance and the security by design and everything. And that's where CISO sometimes is looked at as the blocker. But I've seen these roles very nicely converge and you have had the privilege of having both the roles in the previous organization. So what does that vantage point gives you as an advantage?
Speaker B: No, I think uh, look, at the end of the day, I think from innovation, speed of innovation and leveraging all the awesome work the industry is enabling, right. And the tool sets from a security perspective that organizations have, right. That is enabled that we have at our disposal now. And you hear lots and stuff lately, stuff about AI Mythos, uh, or, and open LLM models that are there. From a security perspective, I think all of these are vantage points that from CIO lens. Right. As a CIO at smartsheet, even the pace of innovation in my mind is fundamentally you can do a lot of great things with guardrails in place. Right. So to your point, right, My vantage point of the expectation that not only I have for myself, but the organization overall of innovating and building great products, enabling our organization to help solve enterprise grade platform and do that in a way that makes sense for our customers. Uh, but at the same time keeping security and risk in mind, I think you have, I think to your point earlier about the risk angle that a, uh, CISO has, I am able to embed that in the innovation that we're building. So we're innovating with governance and scale. Right. And that's the beauty of what smartsheets enabled. And you know, we just launched uh, responsible AI within the company and that was all about, uh, keeping, you know, all the workflows and automation that smartsheet is doing and, but not ignoring, you know, the basics, right. Things around the governance piece, things around putting the guardrails, still having the human in the middle when it comes to some of the AI work that we're doing. So I think that that's just part of, of building secure products.
Speaker A: Yeah, I want to kind of have our audience appreciate a little bit the platform that you're managing. Because smartsheet holds something most people don't think about as sensitive data like not credit card numbers or not health card records, but it's how companies actually run their operating playbook basically. Right. Their project plans, their resource decisions and strategic timelines and all that. I mean it's often thought that if somebody breaches a bank, it's a very serious data. But this is where the operating playbook of a, uh, lot of Fortune 500 companies is actually living. Right? Tell us the scale of it and tell us, you know, the kind of the nuances of it, what you're managing today.
Speaker B: Yeah, no, I think if you look at, you know, Smartsheet has, you know, been around for 20 years. So and serving, you know, when you said 85% of the Fortune 500 customers, we are spanning across workflows that go from launching satellites to space to manufacturing hotels and building hotels, manufacturing shoes. I think this Is, uh, critical, what I would sort of call business critical workflows that enterprises have, and they're really building those at scale on top of smartsheet. Right. And I was a customer of smartsheet before I even came here, you know, back, uh, since 2017. So I've been an avid user and loved using it. And I think that scale and the power of what it allows has been instrumental in how we enable our customers to build workflows on top of Smartsheet.
Speaker A: Yeah. And I think interesting part was that Smartsheet went through an $8.4 billion private with Blackstone and Vista, and you were brought in after that. So when I want to know your point of view, when a, uh, private equity company owns the company, how does the CISO's mandate change? Does it become wider or does it become any different whatsoever?
Speaker B: No, I think with private equity, I think, you know, one which has been. I think we've been very fortunate to have the support of both Vista and Blackstone. I think the first thing I would call out is a community, right? And the community of, uh, other portfolio companies that you can lean on on best practices, what works, what doesn't work. Uh, you also have the best practices of pricing, right? I mean, you want to leverage the best tool sets at your disposal, and you have the scale of a private equity that you wouldn't necessarily have as a standalone organization. And I think I've been very fortunate to work with both of them to build an organization that is leveraging some of the modern tool sets as we make a transformation journey and help enable our customers on this transformation. Like, we are leveraging all of those tool sets internally. Right. So as an example, we have rebuilt our SOC infrastructure to be very AI, uh, agentic way of tracking things. And how we're leveraging these tools. We are leveraging a global organization. 24 by 7. Right. We're working with folks in Bulgaria, we've got a center as well in India. And that wasn't the case, um, frankly, prior to private equity. So, you know, just follow the sun model, leveraging a, uh, 24 by 7 operation, whether it's our engineering workforce and finding the global talent workforce, you know, and then of course, security is nuanced in everything we do, right? Whether it's engineering, that's, you know, so we have engineering talent embedded with security engineers in every location. Um, and that's been a great thing for us to really build post private equity play.
Speaker A: So a lot of access and control and sort of intelligence comes as a part of that, that you can dip into and take use of. Yeah, that's very interesting. I want to move on to something before we figure out how you're solving this different sort of problems at your table. I want to first spend some time on understanding and appreciating the problems that exist today.
Speaker B: Right.
Speaker A: And there's no better place than in our research. When I was reading the Smartsheet 2026 report, your company published this research in January that almost stopped me cold that 7 out of 10, 10 workers use AI tools in their company don't even know that their company don't even know about. And uh, 94% use AI for daily work. Like look at these two stats in comparison. And only one in four companies have the governance in place. So tell me, how bad is this reality? Uh, or behind those numbers?
Speaker B: Yeah, you know, I think the shadow, it has been a problem for, you know, for a very, very long time. Right. I mean I think that that's just. But I think that's also part of the entrepreneurial spirit that many folks have in an uh, organization because they want to try the latest tools and the greatest tools and whether they've been using it in their personal lives. Right. From ChatGPT to, you know, creating deepfakes as a fun prank thing that they've done. Right. I mean, I think these are all things people have done. I think what becomes interesting is how organizations allow for that spirit of innovation and entrepreneurship as I, uh, you know, as we think about with guardrails in place. Right. And I think that's the key thing that I would, would call out, and that's my point about being a CISO and a CIO at smartsheet is that you want to have the governance layer to allow certain tool sets that are enabled. So as an example, you know, we experimented a lot within smartsheet a couple of years back. Right. But we have, you know, we've got strategic relationships with, from the top AI vendors, whether it's uh, on the cloud side and embedding engineering, building our engineering workforce, using AI to prompt based work that some of the associates within smartsheet use. So I think part of that is that governance layer that you want to enable innovation, you want to enable that thought process within the organization with the right guardrails. And that's what we've done, uh, within the organization. So we've brought tools that you can use and cannot use. Right. You know, we've got the auditability trace of anything that, whether it's leaving the organization or agents that you want to build, right? And whether that's within smartsheet as a product or whether that's internal that you're using it. So I, uh, think that guardrails is audibility, that guardrails is allowing the right tool sets after experimentation, trying it, enabling a culture of innovation so that you don't have this shadow it. Right? You got to know what you, you know what you have and what you don't have, right? And discovery, right. I think any CISO would tell you, like, you know, part of the first step is discovering what you have within your organization. That was one of the first things I did is like, let me figure out what tools exist within the organization. Let me do discovery of the shadow it or shadow AI, whatever you want to call it, right? And then let's figure out the guardrails to enable those tools to come into play with the right guardrails in place.
Speaker A: You know, I was smiling because this reminded me of a story, and it's a personal story, where my son in the middle school had to participate in like a state competition for artistic impression where the parents cannot help and you have to express something that you're feeling and then you compete in that. And he made something very interesting, which is very analogous to this shadow idea that you are saying, which was that he split the thing into half. The first half was red, where a student is sitting and there is locks around his head where he's trying to access AI app and spam scam. Everything is blocked. Whereas there is a, uh, student on the right with the green shade and he has specific things open like AI apps, games. But spam and scam still locked it almost. I smile because it almost reminds me this is what the governance means, that let the creativity through and block all the negative thing. In a way, that's why I was
Speaker B: smiling when you were saying no, that's exactly right. And I think you want to enable a culture of innovation. You want to enable a culture of promoting the ability to empower people to do the right thing, right? We say in security, trust but verify, right? I mean, so that verification is really your guardrails in place, right? You have auditability, you know what the tools exist in your environment, what's going out, what exfoliation is happening. But at the same time you're trusting the folks to do the right thing because you're enabling them to with all the tools that are at the disposal.
Speaker A: And I think I found something that you're implementing for that, which was like, smartsheet is building something called Smart Hub. I think a central control pane where enterprise can see and govern sort of every AI interaction on the platform. Uh, walk me through what that actually does and what decisions can an admin make there that they could not make before.
Speaker B: Yeah, I think fundamentally, right, when we were building all of our AI functionality, we wanted to take a very active stance on responsible AI. And responsible AI really stems from this notion of trust. And when you think about trust, it's basically the human element of trust. So we do not do anything within the platform that a human would not be able to do. So as an example, if I give you a credential within my environment or a uh, workflow that's running on smartsheet that's acting, but it's acting on, you know, on behalf of the human, you're ultimately in control at what the workflow can do and not do. And so that notion, when you talk about the Smart Hub or any of the AI functionality, whether it's prompt based thing you want to, you know, have do, you know, there's a lot of work that we're doing around MCP and connecting it to various connectors and the workflows that happen. At the end of the day it's human in control. Right. And that's what we want to enable. And so the second, and you know, so that was sort of the premise of responsible AI. The second thing that I would call out for responsible AI is governance is really gated on auditability. Right. We wanted to enable this notion that anybody at any given point, again put a human in the middle, it can go back and say when an agent does something, you know exactly what it did. If it's crossing boundaries from one system to another, you know what those boundaries that it crossed, what did it do between while it was crossing those two boundaries? Right. And so if I'm connecting myself to, let's say, you know, a third party system that is acting on behalf of my workflow, you want to know exactly how it crossed that smartsheet boundary, went to a third party system and trace for it and you having access to all of that stuff, that was sort of our foundation thing, right? Ah, we built responsible AI in everything we do. So workflows, we're building workflows that our customers are building on top of smartsheet, you have full auto will retrace, you have full governance control, you have human in the middle to check and balance all of that things.
Speaker A: Ah, Surabhi, are we at, is this still foundational and work in progress or are we at a level. So what I'm trying to ask is, is it still retrospective right now? Like I can after the incident, I can retrospectively go and check explainability and audibility and see what where happened? Or is it something that is live that if it is crossing the boundary then I can check. Or is that something that will eventually the modern stage of it?
Speaker B: No. So I think, uh, just to answer your question in two ways, one is both in terms of event logging and APIs that exist today. That's already exists in the platform today. So anytime anything happens, you can go and that's live event logging. It's not a post incident. You can uh, trigger events. You can look at what's happening in the system in real time. So that was our premise from day one, that we wanted to enable an ecosystem of partners that can take all those event logs and do the right thing. So your point about like, hey, if I'm seeing something on a behavior analytics aspect of things, right. So you can imagine the scenario of like, hey, I see before an incident is really happening in real time, I see something as weird as happening with a sheet level, right. Or at a cell level, I can capture that in real time and trigger an alert before a post and incident. Certainly the logs exist that you can go back in time because you've now got this real time event logging infrastructure already in place. And then you can go back in time and do the forensics as you need to. But that was that audibility trace, right. From Live Stream is something that we really wanted to uh, enable, especially for enterprise customers, which are very, you know, we want to enable those workflows.
Speaker A: Yeah, I want to move on to something related to your day in the life. Like here's what's interesting about your role, that you're simultaneously protecting the platform and building the AI that lives inside that platform. So a project manager agent that monitors sort of the progress, flags the risk and recommendation on its own. Right. As a ciso, walk me through the security conversation that you have with your product team when they say that, oh, we want to give an AI agent access to a Fortune 500 company in three weeks. Right. How do you manage that conversation? I'm sure every CISO is having a conversation like this and they would like to know, how do you manage that conversation.
Speaker B: I think the first thing I will say is that you have to have the governance framework, right. That an organization needs to whatever that framework, whether it's nest, whether it's, you know, cis. I mean there's a bunch of These frameworks that already exist, right that are industry benchmarks that, that you have to adopt as a company in a smartsheet. When, when we, you know, while having been an ISO and a SoC compliant organization and you know we adopted uh, as a framework, we said we're going to be NIST853 based and all controls that we do embedded in our product is going to adhere to that. Right. And that was something that we really drove down to the engineering level. So any control that you are building or any application that you're doing has to map to those controls. So that's things like you know, configuration management, change management, you know, auditability, you know, credentialing, right. All of those things that you know, application security, all of those things benchmarks have to be there on day one, right. So that's not non negotiable in my mind from a foundation perspective. The second thing we've done at smartree, which is I think a lot of enterprises are now also starting to do right is uh, building the security framework as part of our product pipeline. So as an example, when I am as a developer checking in code, we're having threat modeling happen, we're doing the DAS SaaS scanning. So you're not worried about it. By the time it goes to production you're already running those scans right up from the check in time itself. So as you know, and AI has really tremendously helped us to expedite some of this application review process. So we leverage Claude Opus and a bunch of these models. We obviously have tools in place for running our DAS SAS scanning. So if I'm as a developer checking in code and whether it's generated using AI or as a human, doesn't really matter. Same pipeline, a standardized pipeline where we go through, through those checks and balances that map again to those controls that I just talked about, the foundation layer. And so I feel comfortable when a developer says hey, like I'm ready to go into prod. I've already done that as part of my check in process and I'm not, I'm not being the gatekeeper, right? As to be enabling an organization to, on a standardized process that has a security gates right built up front to enable the innovation. So when they come and tell me hey, in three weeks I want to release, I'm like go for it because I've already got that in place, right. On the flip side, we also have defense in depth, right? So when you have things like infrastructure things or vulnerabilities that are there, we have tools in place to not only protect our infrastructure from service attacks or anything that may be the case, but also tracking any infrastructure changes, patches, any of that stuff that happens. Right. With tooling in place, from an endpoint protection. So we're catching it on both ends, right? Both in terms of application security when it's going in, and then on the infrastructure side with the tools at play, and then remediating and patching those on the other end.
Speaker A: Interesting thing is that when I talk to you, I feel like you're a systems thinker, you've sorted things out in the right bucket and there is an organized solution in place. What comes to my mind is that this thing called AI, which is overwhelming and disrupting and helping us at the same time, right. And when I hear things about this pace of change, I think about how CISOs and CIOs are worried about their preparedness for this. Right? Because the most prepared person, Department of Defense or whoever, right. Mozilla found out with Mythos that it found, you know, decades worth of bugs in a day or things like that, that almost always will make you feel that this is not enough, what we are doing. Right? But you have to live with that reality, plan with that reality, and then as a systems thinker, settle down and think, this is how I'm going to receive the pace of change that AI is throwing at me. I wouldn't want to know, like how do you perceive that and how do you sort with that sort of.
Speaker B: Yeah, no, I think it's a double edged, uh, sword, Right. I am a big proponent of leveraging AI for what I in my mind call sort of the trust angle. Right. And in my mind, AI is a trust enabler, not a prohibitor. And the way I think about it is, you know, traditionally, you know, we were playing the game as CISOs or security engineers, right? On taking the game of by the time the attack happens, how fast can you protect yourself, right? The ability to leverage AI to take something what used to have multiple man hours. I mean, I'll take a simple, very simple use case of phishing, right. Still today, by the way, 80% of, uh, attack vectors come in through the phishing scenario. But if I'll take a simple use case of phishing, traditionally it used to take multiple man hours to go through a phishing attempt. Figure out, okay, is this really a phishing? Is this a right email? Am I going to go pull this email out from all of my employees in the organization? How far did they get? Did they click on the wrong button and we Sort of enabled as a system of having, oh, you failed a phishing test, I'm going to, you know, give you more training. Right? And so that was a culture that we sort of, you know, that, that I think security kind of came about because of that. I think AI has completely changed the game in this, right? So now as an organization, when we look at when a phishing comes through, you know, you have systems in place, like we have enabled it within smartsheet. I know exactly at a system level what, you know, phish came through on a Friday night, middle of the night, I don't have to wait for anybody. That system goes and looks at, okay, how many people in the organization were impacted. It automatically, from an agent perspective, pulls those emails, quarantines them, right? And then by the time Monday morning comes, I have an engineer, right, that's already said, okay, like this is agent did the right thing or did it not do the right thing? And then if it, you know, if it did the right thing, we're going to approve it. If it didn't, we're going to put it, you know, put it back on a, uh, back on the email. So that was the whole notion of, you know, uh, of SOC and going through the triaging and the alerting and all the incident that was coming in. Uh, AI has completely changed the game of it, right. The flip side, I think, like you said, is also true, right? You know, mythos, I think if anything in my mind has highlighted the notion that the basics don't change, right. Vulnerability management is still the core, core of what we have as an industry, right. Whether it's a software or infrastructure, all of us collectively have to focus on those vulnerabilities and the time to exploit is coming down from it used to be years became months, it became days and now it's in hours. And AI has allowed the bad actors, just like it's allowed the good people to respond and use these tools in a good way, has allowed the bad actors to, you know, do the same thing and you know, do chaining off incidents, right? So when I have chain, multiple vulnerabilities, chaining those and looking at it. So at the end of the day, you know, the good and the bad of anything, but I think the basics don't change fundamentally. We all have to put in our effort to, you know, innovate. I like I said I'm a builder, so I like want to make sure that we have the right checks and balances to when you're checking in code, when you're Having an agent build code for you, right. Making sure those guardrails exist. And uh, at the end of the day the basics will always prevail. And I want to go back to your comment that you made about hey, like Mito's discovered this thing by the way, they discovered it having given access. I mean they were credentialed access, right? So, right. So that's what happened was actually it didn't discover it because you know they were literally given an environment of full credential access to go discover it.
Speaker A: Early access, right? Uh, early.
Speaker B: Exactly right. So I think know the notion that you have, you know, the basics of hey, like you're not allowing credentials to organization, you have MFA in place, you know, phishing resistant MFA and those kind of things, you know, those basics are not going to change. Right? Vulnerability management, that doesn't change. And you know, and I think the other last piece I will end it is we all have to be prepared for an incident, right? And how you respond to an incident is just as important as you are building the product. Right. So with you know, critical infrastructure at play and systems and organizations enabling, you know, whether it's Fortune 500 or critical infrastructure building on stuff, whether it's a DOD and all these things that you talked about, look at ah, the end of the day, you know, we all have to have a uh, tabletop exercise all across the organization. What happens when an incident happens? How do you react? Do you have backups in place to get your systems up and running? Right. You know, and these are all critical in my mind running that incident response plan and doing the right thing.
Speaker A: Did you have to update your incident, I would wonder. So that with AI and everything going on, you would have to update your incident response very quickly because uh, the threat vector and the threat surface increased several fold. The speed increased several fold. So I'm sure the incident response system has to be analogous to the kind of speed and the surface area that increased. So did you have to uh, sort of update your incident response plan?
Speaker B: I think that's an early exercise that every organization must do in my mind and run a full disaster recovery. Uh, and should an incident happen you need to go run the test. So at smartsheet we've done both of those and I think part of that was how do we leverage the systems at play, right? And truly testing and when an environment goes down, how do you get things back up and running, uh, who is you know, defining clear roles and responsibilities in the organization of who's going to act at what time Middle of the night, who's getting the, you know, if we all have pager duty enabled. Right. So who's getting that page and who's responding and how do we leverage that global workforce that we, that I just talked about? So yeah, uh, definitely I encourage all software companies to do that.
Speaker A: Now I want to ask something that is side of the, not of the byproduct, but the causality of, because of which we can do things well, which is budget. The budget conversation. Right. You report into a PV board. Every dollar sort of spent on governance is a dollar not spent on growth. So how do you make the case for AI governance investment when the board wants growth and efficiency, uh, not just more controls, how do you make that case? I'm sure a lot of other leaders have the same situation.
Speaker B: You know, it's, it's uh, ironic. I, I actually find the opposite to be the case. As long as you can argue the business value of it. Right. Whether it was, you know, at my previous organization or here, you know, given that we are an enterprise grade software company from a platform perspective, ensuring that our customers have those governance in place as part of our product features. So I'll give you an example. Right. So when we build within smartsheet, we have multiple security related features that our customers are asking for and also paying for extra for it because they want basics around mfa. We have data classification that we're working on, event reporting broadly, data loss protection in place. These are customer managed encryption keys. These are all things that you would think about from a software play that an enterprise customer would want to expect from an enterprise grade solution, which is what smartsheet is. We are no different in how we adopt smartsheet internally. So when we are shipping products and I'm very closely tied to building that roadmap of what does a security feature look like, how are we going to enable our customers to have that value proposition of an enterprise grade solution? Right. And so when you think about that internally, the problem is less complicated because we're shipping it for our customers and we also have the same set of things adopted internally. So we are customer mindset first. We are building all the things that we are doing internally. We do it for our customers first. How do you want to enable it? And we're getting feedback from our customer like hey, we want this or, or the way whether it's AI work that we're doing, whether it's the future we're thinking about for a region completely outside of the U.S. like Australia, we're going through our Motion of uh, getting IRAP certified and all of these. We're also in the government, so we are a fedramp moderate certified organization. So all of these come into play because we are from a customer centric company. Right? And then you say, okay, now I'm doing this for the customer. I'm going to follow the same guardrails internally. So I, my take on, on to you, you know, in the short, uh, answer would be to look at the customer value prop first. What do you want to offer to your customers? And that's the same thing you would adopt internally because you are ultimately a customer of your own product.
Speaker A: You know, I find this is my favorite answer, by the way. And the reason is because it made a lot of people, including me, learn something. And I'm not surprised you answered it because you have both the CIO and CISO thought process together. Because the traditional thinking, the simplified way in which I have made myself understand a CIO conversation versus a CISO conversation at board level is sort of like this. That board cares about P and L like profit and loss. And profit is what growth, what features, what things you are building for me. Right. And loss is if something goes wrong, what is going to go wrong. And the CISO is sort of addressing the loss part of it. Like this can go wrong. And that's the usual suspect of how the conversation will go. One will appeal to the P and other will appeal to the loss. Right. But this is the first time hearing somebody say no. The governance and security is actually part of the profit equation because my product is bought for another reason, not just the feature, but because the governance it brings with it.
Speaker B: That's right.
Speaker A: So that's a phenomenal way that now you are part of. Profit and loss both benefit. Uh, I think that's an incredible value in a, uh, conversation starter for a board conversation.
Speaker B: And that was in fact my very first board meeting was exactly how I had actually walked in with. Here's what our product has from a security and governance framework. Here's what we want to build from a roadmap perspective. And then let's look at the corporate environment, how it maps to those exact same thing that our customers are demanding of us. I did this also at uh, my previous organization, same story. We were in a highly regulated healthcare industry where phi data was sacrosanct to anything we did as a business. So how are we enabling security fundamentally for solving our customer needs? Right. Same purview. So I think you have to frame it in the context in my mind and it's ultimately, uh, how. I'm a builder, as I told you. Right. So how do we think about what I want to absorb if I'm a CIO from um, the supply chain software is what I would want to enable for our customers.
Speaker A: Interesting. I want to know one thing which is like the byproduct of doing AI very, very fast. Right? And my, one of my favorite part of research was finding out why you won the Seattle CIO of the year. What was the reason? And I found that, uh, the sustainable IT project behind it. And then I felt that how, how much more relevant can a thing be? As we are on this maddening path of AI, we all want to do AI, the consumption, the data center, the power consumption is going to go through the roof, right? And sustainable it becomes even more important because now you need to have these sort of smart thought processes that you put at Edifix together, which were recognized, uh, as a part of that. But that is always right now is almost has become like a afterthought that let's do first progress and then we'll think about. I think a lot of people got tree hugger stuff, right? But, but then this is for us. We are the mankind and we need to think about, uh, the right thing first. My question to you sort of is that how should C suite executives think about their technology footprint with sustainability in mind, how should they proceed?
Speaker B: No, Great. Again, I think it goes back to some framework in mind, right. I think that was something that we. Data effects. You know, it took almost, I would say a decade to go build this, that charter. Right. We took baby steps, right? We started, okay, like what are we going to start tracking our data center span? Then we went to, you know, cloud the SaaS migration. What does that look like? Then we started looking at our procurement processes and what does that look like? Then we started looking at, okay, what is our offboarding process and how can we become efficient in repurposing some of these machines and so forth. And then, you know, by the end of sort of, I would say a decade of taking these babies every, every year we had a couple of initiatives that we were at, right? And we would keep adding one or two initiatives around it. Sustainability. And that was sort of our core to what we were doing. Right? And we were. And you know, frankly, it's become sort of ingrained in me, you know, to some degree. And one of the things that I, we've started doing within the smartsheet as well is we use the, uh, sustainable. It has a great framework that they've, you know, published. It's a publicly available, that they share. You know, how do you look at, at a control level all of the things that you do. AI is by the way one of them. Infrastructure, data center, all of that stuff is, is, is part of that framework. So we've actually started tracking that within smartsheet. It's, you know, it's a, it's, you know, I, I don't expect it to be an overnight, you know, thing that we're going to do. It's going to be a long journey, which I'm very committed to doing. I think we started looking at very simple things. Our procurement process was one of the things that we looked at. How do we ensure that our supply chain from a procurement perspective is sustainable. And then we said, okay, when we are life cycle of a machine, whether it's three years or four years depending on the organization because um, the machine still has life. Can we repurpose them in, you know, whether it's in. People don't necessarily have access to laptops or machines. Right. So we're already, you know, engaging with schools and churches and so forth and how we can deploy them. Right. And you know, and so I think these are some basic things you can start doing and then when you start adding in the workflows of AI and how that's really manifesting itself on the energy utilization as you called it. Right. And the cloud span and so forth, we've already started tracking those. Right. So and I think the first thing that we're doing is just collecting metrics and against those foundational elements that sustainable IT has published. So we took that foundation, we started tracking the metrics on it. We're taking one baby steps on each of those. Okay, what are we going to do in smartsheet around those goals and set a target for ourselves? Okay, we're going to reduce this by simple 5%, 10%, whatever the goal is, did we want to buy each control and we're going to measure ourselves and work through it. As you said, we always want to leave behind a legacy beyond just what we've dealt from a technology perspective, a sustainable environment. And it is a big play. Especially look at cloud spend and data centers and all that stuff and the energy utilization. You've heard hard stories about cities losing power because it's all going to data center and how do you leverage that is something that uh, I'm very passionate about and I think like you said, a part of the CIO community within Seattle, we're all collectively Discussing some of these things and meaningfully making a change as a community together on this.
Speaker A: Yeah, that's wonderful. Another part of giving is giving to your peers and in the enterprise tech industry. So we are almost at the end of this. And these are the two things that I asked beyond just work, which is that you started as a builder at Microsoft, you're a builder at Core, and ended up as a cioc, so winning, you know, the Seattle CIO of the year. Now playing this role there at Smartsheet. For someone who's a builder today or is in the security lane today and wants to be in something like your role or the journey that you have had, how should they invest in their skills today? What should they focus on? That would be your advice because you have a great vantage point.
Speaker B: Uh, my advice is, you know, don't be shy to rolling up your sleeves. Right. I think as, you know, regardless of the level of the organization you're in, you know, I think it's important for labor tools. There's so much out there, you know, I, I'm still, you know, looking at in my spare time that we, you know, beyond the 20 hours that you talked about. Right. Things I do is, you know, I look at open source stuff that's there. We, you know, play with new models that are out there, whether it's, you know, I. Just this past weekend, I downloaded a library off of GitHub that was looking at red teaming. Right. I mean, there was, you know, penetration tests and how can we do it much more efficiently and doing it at Spiel and, you know, injecting it as part of your dev life cycle, so you're not having to wait for it post deployment. Right. So I think that's something that I encourage everybody to be doing, regardless of what level is. Be willing to roll, you know, be vulnerable. Right. Be willing to be, you know, roll up your sleeve, try different things out. It's a very exciting time to be, frankly, be alive. And because there's so much out there, there's so much energy in this industry, you know, I think we're just starting to see the, you know, the beginnings of AI and, you know, and, and we have now, you know, I think it's time to harness that, that energy that's there and enable us to do more. Um, you know, quantum computing is coming. Play with it. I mean, I think this is all stuff that we should all be, frankly, trying out and giving a shot.
Speaker A: Very cool. What's the one thing that excites you the most for the next two years. What are you most excited about for the next two years?
Speaker B: I think the power of AI and what it enables for, uh, civilization as a whole and how it scales productivity. I think it's going to be an immense, immense. Whether it's, you know, things that, that agents can do on our behalf and help us scale better as humans. I think it's going to be. I'm very excited about that.
Speaker A: Yeah. Well, that's all we had for today. This was a wonderful conversation, and thank you for being so kind and candid in sharing the information and your opinions. I think it's a very unique vantage point, like we said, and I really wish you the best and Smartsheet the best in your ventures.
Speaker B: Thank you so much, Arag. I appreciate it. And good luck on your venture as well.
Speaker A: Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.