Lock it Down Podcast · 2026-07-01 · 12 min
Key moments - from our scoring
Substance score
35 / 100
Five dimensions, 20 points each
Jim Routh, Chief Trust Officer at Saviant, an AI-era identity security platform, discusses how enterprise software companies can establish and measure trust with customers. Routh draws on 20+ years as a CISO at major financial services and healthcare organizations, plus co-founder experience with HealthISAC, to explain that trust is built by exceeding customer expectations - particularly by proactively sharing information about software resilience, operational practices, and security posture through mechanisms like trust portals and SOC 2 artifacts. Rather than waiting for customers to request security documentation, Saviant trains sales teams to educate prospects about available information before they ask. Routh measures trust growth by tracking the delta between what customers expect and what the company proactively delivers, using customer feedback to gauge whether this gap is widening. This approach appeals to enterprise security leaders, procurement teams, and CISOs evaluating SaaS vendors and seeking differentiation beyond baseline security compliance.
Trust is an integral part of brand for any enterprise and requires customers to have confidence not only in functionality but also in the company's ability to run software as a service without interruption with the right level of resilience, while exceeding customer expectations.
Trust is primarily measured through customer feedback on proactive information sharing about operational resilience, specifically the delta between what customers initially expect and what the company provides without being asked - such as additional details in trust portals beyond required artifacts like SOC 2 reports.
Trust is established by setting clear baseline expectations aligned with industry standards, then consistently exceeding those expectations by proactively sharing information about software security practices, resilience measures, and third-party governance details that customers didn't request but find valuable.
Most software companies provide only essential information needed for purchase decisions, while Saviant trains sales professionals to proactively educate customers about additional artifacts and practices available in their trust portal, going beyond what's asked for to demonstrate commitment to transparency.
Routh spent 20+ years as a CISO at major financial services and healthcare companies including American Express, served on the board of FSISAC, co-founded HealthISAC, and worked as an advisory board member before retiring from active CISO work and joining Saviant as a customer.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode offers one genuinely usable framework - measuring trust as the delta between what customers expect and what is proactively provided - but the runtime is dominated by an extended personal backstory anecdote, sponsor reads, and generic statements about trust being 'integral to brand.' The ratio of actionable insight to filler is poor for a 12-minute runtime.
the delta between what is required and what is offered proactively is kind of how I measure the trust level and whether that's increasing or decreasing over time
most of the sales professionals we work with work on behalf of the customers and give them what they ask for and what they want and aren't necessarily trained to give them what they need
The 'proactive information sharing beyond the minimum' idea has some practical merit but is not a novel concept in vendor security or customer success. There is no contrarian argument, no first-principles reasoning, and no counterintuitive framing - just a repackaging of 'go above and beyond' applied to security artifacts.
we're trying to provide that information and then provide additive information that isn't requested, but information that might be useful
that gap or delta, if you will, is kind of a differentiator
Jim Routh has genuine, at-scale practitioner credentials - first CISO at American Express, five subsequent CISO roles over two decades, co-founder of HealthISAC - which is legitimately impressive. However, the role he is speaking from today (Chief Trust Officer at a vendor) is closer to a brand-advocacy position, and the episode content reflects that promotional posture rather than deep operational knowledge.
you're the first chief information security officer for American Express
I ended up moving to five other chief information security officers or chief security officer roles over a 20-year period
The only named artifact is a SOC 2, mentioned in passing as a generic example. There are no customer names, no metrics on trust portal usage or outcomes, no timelines, no dollar figures, and no data on how the delta measurement has moved. The entire value proposition of the trust portal is asserted but never evidenced.
our customers may ask for a SOC 2 as an example, a security artifact that's important for their internal third-party management process
we publish information about the resilience of our operational team and our software on a continuing basis
The host's questions are textbook surface-level prompts ('could you talk about your background,' 'how is trust defined,' 'how can trust be established') with zero follow-up, zero pushback, and no attempt to probe for specifics or challenge any claim. The host even telegraphs a question as 'the big question every listener has been waiting for,' signalling a scripted PR format rather than genuine inquiry.
So now I've got the big question that probably every listener has been waiting for me to ask, how can trust be established and built?
I love that background. Thank you so much for sharing.
Computed from the transcript - who did the talking, and the words that came up most.
Security Magazine Managing Editor, Jordyn Alger, speaks with Jim Routh, Chief Trust Officer at Saviynt, about how organizations can build and measure trust.
Transcribed and scored by The B2B Podcast Index.
Hello and welcome to Lock It Down with Security Magazine, where we talk about all aspects of security from leadership, security posture, risk management, and much more. I'm Jordan Elger, Managing Editor at Security Magazine. Today, we're here with Jim Routh, Chief Trust Officer and Board Advisor at Saviant, an AI-era identity security platform. Welcome, Jim.
Hey, Jordan. It's great to be here. So getting things started, could you talk about your background and experience within the security industry? Sure.
I actually started in security kind of by accident. And I've talked to many colleagues that have similar experiences, but I was in IT for many years and I was living in Minnesota. And in Minnesota, it turns out the winters are pretty cold. And we got to experience exactly how cold they were because on one night after the third winter, my wife said to me, look, we're moving back east.
Do you want to come? And I said, well, yeah, I think I do want to come. And she said, well, you better find another job then. So I called up my boss and I said, you got to get me out of here.
And he said, well, come to headquarters, which was New York, and I'll get you a job. Might not be in IT, but I'll get you a job. So I said I'd sweep the floors. I didn't care what it was.
And I ended up working in something called econometrics, which today would be data science. But after a couple of years of doing that and enjoying it, he called me to his office one day and said, you're the first chief information security officer for American Express. Now go get to work. At the time, I didn't realize it, but there was a memorandum of understanding from the OCC that required both a information security officer as well as a strategic plan for information security.
And I had to deliver both those things within 24 hours. And so I was a means to an end, but I said, OK, I'm all in. And of course, I went in all in at that time. So I ended up moving to five other chief information security officers or chief security officer roles over a 20-year period, and mostly big companies and financial service and healthcare companies.
I also did some since I was on the board of the FSISAC for many years, and I was a co-founder of the HealthISAC, that's Information Sharing and Analysis Center. So I did that for many years as well. And then about four years ago I retired from active CISO work and started doing advisory work and board work and ended up working with Sabient I was a customer of Saviant and I knew them quite well And they asked me to be the chief trust officer And that was a new experience And so I been doing that for the last three years.
I love that background. Thank you so much for sharing. And so getting into our main topic now, how is trust defined from a business perspective and why is it so important? Yeah, so trust is an integral part of a brand for any enterprise.
And in our case, we offer enterprise software and we run enterprise software for our large customers. And they need to have confidence, not only in our ability to provide functionality that meets their requirements, but also that we can run it in a software as a service model without interruption with the right level of resilience. And that's complex in any environment these days. And so our customers have certain expectations and our job as a company is to try to exceed those expectations.
And part of that is to build trust into our brand. And that's my job. And there are some different ways that I use to do that. One of the first and most important is I share information about the resilience of our software capability through a trust portal that's available to our customers anytime they want.
And I give them information that they ask for, and I give them information that they don't ask for, but maybe they would like at some point in time. So we publish information about the resilience of our operational team and our software on a continuing basis. And that's available at any time. And that's one of the ways that as a software provider, we're trying to provide not only the information that they need to make decisions around the use of our capabilities, but we're trying to go above that and give them information about the resilience of our software that maybe other software companies don't offer.
And we're trying to do that and build the trust and confidence in our customers by offering that and by responding to their cybersecurity requirements as they change and evolve. This podcast is sponsored by the Security E-Newsletter. Security provides management-focused features, opinions, and trends for leaders in business, government, and institutional sectors. Subscribe for free to our newsletter to get physical security insights in your inbox twice a month Sign up today at securitymagazine forward slash subscribe So with trust being so integral for brands as you said how can this trust be measured Are there metrics or are there certain pieces of feedback that chief trust officers can look for?
Yeah, it's primarily feedback from customers. And what I try to discern is customers' reactions for when we provide information to them proactively where they didn't ask for it, and specifically about the resilience of our operations. And so there are oftentimes where our customers may ask for a SOC 2 as an example, a security artifact that's important for their internal third-party management process around third-party governance. And so we'll provide that information and we'll say, by the way, it's in this trust portal.
Take a look at the other information there. And they'll give me feedback. They'll say, well, this is a lot more information than we necessarily need, but we found it quite useful. And we learned a lot.
So, you know, thank you for sharing it and helping us out. So the delta between what is required and what is offered proactively is kind of how I measure the trust level and whether that's increasing or decreasing over time with our customers. So now I've got the big question that probably every listener has been waiting for me to ask, how can trust be established and built? Yeah, it starts by, and it's a great question, because it is a bit of an intangible, but it starts by laying a baseline of expectations that, you know, we provide in terms of here, you can expect us to do these things.
And most of the expectations are pretty much in line with what our customers would expect from other enterprises that other software companies that offer capabilities. So there's some consistency there across brands, if you will, across products. And then the delta between what's expected and what's offered is what we try to measure as the contributions that we're making to improving trust in our product capabilities and our ability to respond to unique requirements of our customers.
And that's what we measure. That's what we look at. So it comes from customer feedback, but it's specifically the delta between what the customer expects initially and what they're provided for over the long term that they didn't necessarily expect. So as we start to wrap things up do you have any last thoughts that you like to share Yeah one of the things I learned is that enterprise software companies and this is true for any software company typically provides the information that's essential to the customers making a buy decision.
And for obvious reasons, that's kind of the critical path for software companies. And what we're trying to do is to provide that information and then provide additive information that isn't requested, but information that might be useful to understand the practices that are in place to manage software security more effectively and achieve resilience. And that gap or delta, if you will, is kind of a differentiator. And we attribute that to trust in our ability.
And so that's essentially what we strive for. And it's a journey that requires a change in behavior. because most of the sales professionals we work with work on behalf of the customers and give them what they ask for and what they want and aren't necessarily trained to give them what they need and may not ask for. And so we spent a lot of time and effort to work with our sales professionals to let them know that we have these additional artifacts available and they shouldn't wait until their customers ask for it.
They should just provide it or at least educate them on what's available. And hopefully that's going the extra mile to not only win their business and confidence, but ultimately their trust. Well, that looks like that's all the time we have for today. Thank you so much for joining us, Jim.
Jordan, thanks. It's great, and I appreciate the opportunity to work with you. Thanks for listening to Lock It Down with Security Magazine. Follow us on Apple Podcasts or Spotify or listen to our podcast directly from our site, securitymagazine.
com. And don't forget to rate and review Lock It Down with Security Magazine as well. This podcast is sponsored by Security Magazine's Today's Cybersecurity Leader e-newsletter. ransomware, AI, phishing, and more.
Enterprise cybersecurity leaders need the latest threat intelligence to protect their organizations. Each month, Security Magazine highlights cyber trends for leadership in the Today's Cybersecurity Leader e-newsletter. Subscribe now at securitymagazine.com forward slash subscribe.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.