The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Lock it Down Podcast

Establishing and Measuring Trust

Lock it Down Podcast · 2026-07-01 · 12 min

0:00--:--

Key moments - from our scoring

Substance score

35 / 100

Five dimensions, 20 points each

Insight Density7 / 20
Originality6 / 20
Guest Caliber13 / 20
Specificity & Evidence5 / 20
Conversational Craft4 / 20

Jim Routh, Chief Trust Officer at Saviant, an AI-era identity security platform, discusses how enterprise software companies can establish and measure trust with customers. Routh draws on 20+ years as a CISO at major financial services and healthcare organizations, plus co-founder experience with HealthISAC, to explain that trust is built by exceeding customer expectations - particularly by proactively sharing information about software resilience, operational practices, and security posture through mechanisms like trust portals and SOC 2 artifacts. Rather than waiting for customers to request security documentation, Saviant trains sales teams to educate prospects about available information before they ask. Routh measures trust growth by tracking the delta between what customers expect and what the company proactively delivers, using customer feedback to gauge whether this gap is widening. This approach appeals to enterprise security leaders, procurement teams, and CISOs evaluating SaaS vendors and seeking differentiation beyond baseline security compliance.

Key takeaways

  • →Trust for enterprise software companies is built by consistently exceeding customer expectations and proactively sharing operational resilience information through channels like trust portals rather than waiting for requests.
  • →Measuring trust requires tracking the delta between what customers initially expect and what additional value is provided over time, using customer feedback as the primary metric.
  • →Enterprise software sales teams typically need organizational behavior change to move beyond providing only requested information and instead educate customers on available security artifacts and best practices they may not explicitly ask for.
  • →SOC 2 certifications and similar security artifacts should be accompanied by proactive education about additional resilience information available to help customers understand broader operational security practices.
  • →Trust is a differentiator that requires journey-oriented thinking rather than transactional thinking focused solely on closing sales.

In this episode

  1. 1Jim Routh's Career Path from IT to Chief Trust Officer
  2. 2Defining Trust as a Business Imperative for Enterprise Software
  3. 3Measuring Trust Through Customer Feedback and Expectation Deltas
  4. 4Building Trust by Exceeding Customer Expectations Proactively
  5. 5The Role of Sales in Delivering Trust-Building Information Beyond Requirements

Mentioned

SaviantSecurity MagazineAmerican ExpressFSISACHealthISACJim RouthJordan ElgerOCCSOC 2

Guests

Jim Routh

Topics in this episode

SaviantSOC 2Trust portalThird-party governanceInformation Sharing and Analysis Center (FSISAC)HealthISACChief Trust Officer roleSoftware as a Service (SaaS) resilienceOperational resilience metricsEnterprise software security

Questions this episode answers

How does Jim Routh define trust from a business perspective?

Trust is an integral part of brand for any enterprise and requires customers to have confidence not only in functionality but also in the company's ability to run software as a service without interruption with the right level of resilience, while exceeding customer expectations.

What metrics do chief trust officers use to measure trust levels?

Trust is primarily measured through customer feedback on proactive information sharing about operational resilience, specifically the delta between what customers initially expect and what the company provides without being asked - such as additional details in trust portals beyond required artifacts like SOC 2 reports.

How can trust be established with enterprise software customers?

Trust is established by setting clear baseline expectations aligned with industry standards, then consistently exceeding those expectations by proactively sharing information about software security practices, resilience measures, and third-party governance details that customers didn't request but find valuable.

What differentiates Saviant's approach to trust from other software companies?

Most software companies provide only essential information needed for purchase decisions, while Saviant trains sales professionals to proactively educate customers about additional artifacts and practices available in their trust portal, going beyond what's asked for to demonstrate commitment to transparency.

What was Jim Routh's background before becoming Chief Trust Officer at Saviant?

Routh spent 20+ years as a CISO at major financial services and healthcare companies including American Express, served on the board of FSISAC, co-founded HealthISAC, and worked as an advisory board member before retiring from active CISO work and joining Saviant as a customer.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

7 / 20

The episode offers one genuinely usable framework - measuring trust as the delta between what customers expect and what is proactively provided - but the runtime is dominated by an extended personal backstory anecdote, sponsor reads, and generic statements about trust being 'integral to brand.' The ratio of actionable insight to filler is poor for a 12-minute runtime.

the delta between what is required and what is offered proactively is kind of how I measure the trust level and whether that's increasing or decreasing over time
most of the sales professionals we work with work on behalf of the customers and give them what they ask for and what they want and aren't necessarily trained to give them what they need

Originality

6 / 20

The 'proactive information sharing beyond the minimum' idea has some practical merit but is not a novel concept in vendor security or customer success. There is no contrarian argument, no first-principles reasoning, and no counterintuitive framing - just a repackaging of 'go above and beyond' applied to security artifacts.

we're trying to provide that information and then provide additive information that isn't requested, but information that might be useful
that gap or delta, if you will, is kind of a differentiator

Guest Caliber

13 / 20

Jim Routh has genuine, at-scale practitioner credentials - first CISO at American Express, five subsequent CISO roles over two decades, co-founder of HealthISAC - which is legitimately impressive. However, the role he is speaking from today (Chief Trust Officer at a vendor) is closer to a brand-advocacy position, and the episode content reflects that promotional posture rather than deep operational knowledge.

you're the first chief information security officer for American Express
I ended up moving to five other chief information security officers or chief security officer roles over a 20-year period

Specificity & Evidence

5 / 20

The only named artifact is a SOC 2, mentioned in passing as a generic example. There are no customer names, no metrics on trust portal usage or outcomes, no timelines, no dollar figures, and no data on how the delta measurement has moved. The entire value proposition of the trust portal is asserted but never evidenced.

our customers may ask for a SOC 2 as an example, a security artifact that's important for their internal third-party management process
we publish information about the resilience of our operational team and our software on a continuing basis

Conversational Craft

4 / 20

The host's questions are textbook surface-level prompts ('could you talk about your background,' 'how is trust defined,' 'how can trust be established') with zero follow-up, zero pushback, and no attempt to probe for specifics or challenge any claim. The host even telegraphs a question as 'the big question every listener has been waiting for,' signalling a scripted PR format rather than genuine inquiry.

So now I've got the big question that probably every listener has been waiting for me to ask, how can trust be established and built?
I love that background. Thank you so much for sharing.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

security21information19trust16software13customers13provide8magazine6today6chief6resilience6officer5enterprise5didn4expectations4available4trying4

Episode notes

Security Magazine Managing Editor, Jordyn Alger, speaks with Jim Routh, Chief Trust Officer at Saviynt, about how organizations can build and measure trust.

Full transcript

12 min

Transcribed and scored by The B2B Podcast Index.

Hello and welcome to Lock It Down with Security Magazine, where we talk about all aspects of security from leadership, security posture, risk management, and much more. I'm Jordan Elger, Managing Editor at Security Magazine. Today, we're here with Jim Routh, Chief Trust Officer and Board Advisor at Saviant, an AI-era identity security platform. Welcome, Jim.

Hey, Jordan. It's great to be here. So getting things started, could you talk about your background and experience within the security industry? Sure.

I actually started in security kind of by accident. And I've talked to many colleagues that have similar experiences, but I was in IT for many years and I was living in Minnesota. And in Minnesota, it turns out the winters are pretty cold. And we got to experience exactly how cold they were because on one night after the third winter, my wife said to me, look, we're moving back east.

Do you want to come? And I said, well, yeah, I think I do want to come. And she said, well, you better find another job then. So I called up my boss and I said, you got to get me out of here.

And he said, well, come to headquarters, which was New York, and I'll get you a job. Might not be in IT, but I'll get you a job. So I said I'd sweep the floors. I didn't care what it was.

And I ended up working in something called econometrics, which today would be data science. But after a couple of years of doing that and enjoying it, he called me to his office one day and said, you're the first chief information security officer for American Express. Now go get to work. At the time, I didn't realize it, but there was a memorandum of understanding from the OCC that required both a information security officer as well as a strategic plan for information security.

And I had to deliver both those things within 24 hours. And so I was a means to an end, but I said, OK, I'm all in. And of course, I went in all in at that time. So I ended up moving to five other chief information security officers or chief security officer roles over a 20-year period, and mostly big companies and financial service and healthcare companies.

I also did some since I was on the board of the FSISAC for many years, and I was a co-founder of the HealthISAC, that's Information Sharing and Analysis Center. So I did that for many years as well. And then about four years ago I retired from active CISO work and started doing advisory work and board work and ended up working with Sabient I was a customer of Saviant and I knew them quite well And they asked me to be the chief trust officer And that was a new experience And so I been doing that for the last three years.

I love that background. Thank you so much for sharing. And so getting into our main topic now, how is trust defined from a business perspective and why is it so important? Yeah, so trust is an integral part of a brand for any enterprise.

And in our case, we offer enterprise software and we run enterprise software for our large customers. And they need to have confidence, not only in our ability to provide functionality that meets their requirements, but also that we can run it in a software as a service model without interruption with the right level of resilience. And that's complex in any environment these days. And so our customers have certain expectations and our job as a company is to try to exceed those expectations.

And part of that is to build trust into our brand. And that's my job. And there are some different ways that I use to do that. One of the first and most important is I share information about the resilience of our software capability through a trust portal that's available to our customers anytime they want.

And I give them information that they ask for, and I give them information that they don't ask for, but maybe they would like at some point in time. So we publish information about the resilience of our operational team and our software on a continuing basis. And that's available at any time. And that's one of the ways that as a software provider, we're trying to provide not only the information that they need to make decisions around the use of our capabilities, but we're trying to go above that and give them information about the resilience of our software that maybe other software companies don't offer.

And we're trying to do that and build the trust and confidence in our customers by offering that and by responding to their cybersecurity requirements as they change and evolve. This podcast is sponsored by the Security E-Newsletter. Security provides management-focused features, opinions, and trends for leaders in business, government, and institutional sectors. Subscribe for free to our newsletter to get physical security insights in your inbox twice a month Sign up today at securitymagazine forward slash subscribe So with trust being so integral for brands as you said how can this trust be measured Are there metrics or are there certain pieces of feedback that chief trust officers can look for?

Yeah, it's primarily feedback from customers. And what I try to discern is customers' reactions for when we provide information to them proactively where they didn't ask for it, and specifically about the resilience of our operations. And so there are oftentimes where our customers may ask for a SOC 2 as an example, a security artifact that's important for their internal third-party management process around third-party governance. And so we'll provide that information and we'll say, by the way, it's in this trust portal.

Take a look at the other information there. And they'll give me feedback. They'll say, well, this is a lot more information than we necessarily need, but we found it quite useful. And we learned a lot.

So, you know, thank you for sharing it and helping us out. So the delta between what is required and what is offered proactively is kind of how I measure the trust level and whether that's increasing or decreasing over time with our customers. So now I've got the big question that probably every listener has been waiting for me to ask, how can trust be established and built? Yeah, it starts by, and it's a great question, because it is a bit of an intangible, but it starts by laying a baseline of expectations that, you know, we provide in terms of here, you can expect us to do these things.

And most of the expectations are pretty much in line with what our customers would expect from other enterprises that other software companies that offer capabilities. So there's some consistency there across brands, if you will, across products. And then the delta between what's expected and what's offered is what we try to measure as the contributions that we're making to improving trust in our product capabilities and our ability to respond to unique requirements of our customers.

And that's what we measure. That's what we look at. So it comes from customer feedback, but it's specifically the delta between what the customer expects initially and what they're provided for over the long term that they didn't necessarily expect. So as we start to wrap things up do you have any last thoughts that you like to share Yeah one of the things I learned is that enterprise software companies and this is true for any software company typically provides the information that's essential to the customers making a buy decision.

And for obvious reasons, that's kind of the critical path for software companies. And what we're trying to do is to provide that information and then provide additive information that isn't requested, but information that might be useful to understand the practices that are in place to manage software security more effectively and achieve resilience. And that gap or delta, if you will, is kind of a differentiator. And we attribute that to trust in our ability.

And so that's essentially what we strive for. And it's a journey that requires a change in behavior. because most of the sales professionals we work with work on behalf of the customers and give them what they ask for and what they want and aren't necessarily trained to give them what they need and may not ask for. And so we spent a lot of time and effort to work with our sales professionals to let them know that we have these additional artifacts available and they shouldn't wait until their customers ask for it.

They should just provide it or at least educate them on what's available. And hopefully that's going the extra mile to not only win their business and confidence, but ultimately their trust. Well, that looks like that's all the time we have for today. Thank you so much for joining us, Jim.

Jordan, thanks. It's great, and I appreciate the opportunity to work with you. Thanks for listening to Lock It Down with Security Magazine. Follow us on Apple Podcasts or Spotify or listen to our podcast directly from our site, securitymagazine.

com. And don't forget to rate and review Lock It Down with Security Magazine as well. This podcast is sponsored by Security Magazine's Today's Cybersecurity Leader e-newsletter. ransomware, AI, phishing, and more.

Enterprise cybersecurity leaders need the latest threat intelligence to protect their organizations. Each month, Security Magazine highlights cyber trends for leadership in the Today's Cybersecurity Leader e-newsletter. Subscribe now at securitymagazine.com forward slash subscribe.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Justin Greis: AI Meets CybersecurityKitecast · on SOC 285 / 100
  • Compliance Isn’t Security: The Biggest Cybersecurity Myth in Healthcare (HITRUST Explained)Cybersecurity at ViVE Podcast · on SOC 278 / 100
  • Building Trust with AI Compliance FrameworksCherry Bekaert: Risk & Cybersecurity · on SOC 267 / 100
  • ISACA Podcast: Why You Should Use the F Word MoreISACA Podcast · on SOC 264 / 100
  • Why Neofin Killed Its Niche and Rebuilt From Scratch. And What They're Launching Next | Svitlanka Sergiichuka, CEO & Co-Founder, NeofinPurpose Driven FinTech · on SOC 256 / 100
  • “Soft Market Surge: Capital Floods In as Risk Industry Eyes New Frontiers”Insurance Intelligence Daily · on Saviant39 / 100

More from Lock it Down Podcast

All episodes →
  • 7 Data Security Stories to Know About (May 2026)
  • What Industry Leaders Can Do to Support Women in Security
  • Credential Management in High Turnover Environments
  • 10 Data Breaches to Know About (April 2026)
  • Why Bridging Siloes Doesn’t Need to Be Complicated
Explore the best B2B Ops podcasts →
All Lock it Down Podcast episodes →