The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Secure Talk Podcast
Secure Talk Podcast artwork

Considering Security, Compliance and Revenue with David Grazer

Secure Talk Podcast · 2026-06-16 · 42 min

0:00--:--

Key moments - from our scoring

Substance score

43 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality10 / 20
Guest Caliber11 / 20
Specificity & Evidence5 / 20
Conversational Craft8 / 20

David Grazer brings a unique perspective to security economics by positioning trust as a quantifiable business metric rather than soft language. After spending 15+ years building security, privacy and trust programs at high-growth tech companies - including a $2B creator platform (Wrapbook) and work at Tavora during the GDPR transition - Grazer has developed a framework that ties security practices directly to customer retention and revenue impact. The conversation explores why ISO 27001 certifications and compliance frameworks function as customer acquisition tools (point-in-time attestations) while real trust requires continuous daily proof through practices like minimal data collection at onboarding, transparent security communication before incidents occur, and thoughtful support team training on controls like MFA. Grazer's background uniquely bridges growth hacking, OSINT, privacy engineering, identity and access management, and product work - giving him insight into how every department from engineering to customer success contributes to security outcomes. For B2B operators, the episode offers a business-language translation for security investments: just as finance teams impact every business decision, modern security must be embedded across product, support, and executive functions to meaningfully move customer churn metrics.

Key takeaways

  • →Compliance certifications are point-in-time attestations useful for customer acquisition, but continuous security practices and transparency drive the customer retention and revenue that truly matter.
  • →Trust can be measured by customer churn rates - micro-intentions like collecting only necessary data during onboarding and how support teams communicate security controls directly impact retention economics.
  • →Security teams must understand how the company makes money and what data actually drives revenue; collecting data for compliance without business purpose creates scope without value.
  • →Security program success requires understanding human decision-making and incident protocols in real time, not just technical frameworks - experience inside organizations as an operator is critical for effective consulting.
  • →Every department, from support to product to executives, plays a measurable role in building trust; security is now a second pillar alongside finance that touches all business decisions.

In this episode

  1. 1Origin Story: From Growth Hacking to Security and Privacy
  2. 2Building Trust-Based Security Programs at Tavora During GDPR
  3. 3The Consultative Approach to Security and Understanding Business Context
  4. 4Trust as a Measurable Economic Asset and Customer Retention
  5. 5Identity Management and Data Stewardship in Entertainment Payroll at Wrapbook
  6. 6Trust by Design for Product and AI Teams at Steadfast Partners

Mentioned

David GrazerJustin BealsSteadfast PartnersStrikeGraphMicah SpielerCloudflareTavoraWrapbookEdelmanMelanie EnsignRachel BotsmanCharlie Munger

Guests

David Grazer

Topics in this episode

CloudflareGDPRMulti-Factor AuthenticationISO 27001Identity and access managementSteadfast PartnersWrapbookTavoracontinuous compliancetrust by design

Questions this episode answers

How do compliance frameworks like ISO 27001 differ from what actually builds customer trust?

Frameworks like ISO 27001 are point-in-time attestations that win customer acquisition deals, but trust that retains customers requires continuous daily proof through practices like transparent communication before incidents, minimal data collection, and how support teams handle security requests like MFA enablement.

What metric should security leaders watch to understand whether their programs are building real trust?

Customer churn rate is one of the most honest security metrics available - it reflects whether continuous security practices, transparent communication, and usable controls are actually retaining customers, not just whether certifications are current.

Why does David recommend understanding how a company makes money before building security programs?

Companies often collect data and scope systems into broad compliance frameworks without those data sets actually driving revenue or business growth; understanding revenue streams lets security teams rationalize scope and potentially retire unnecessary data collection and controls.

What's the difference between how security should approach acquisition versus retention?

Frameworks and certifications drive customer acquisition; retention requires focus on continuous practices like support team communication, privacy-first data collection (only gather what you need when you need it), and customers hearing about security practices long before any incident occurs.

Why is hands-on operational experience inside companies important for security consultants?

Real security decisions happen during incidents and under pressure - having experienced the 2am call, managed executive involvement in incident response, and worked with product and engineering teams day-to-day lets consultants empathize with actual pain points and pressure-test programs realistically.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

A handful of genuinely non-obvious ideas surface - compliance frameworks as acquisition tools, customer churn as a security metric, and MFA accessibility failures - but they're distributed across a transcript heavily padded with personal origin story, vague AI commentary, and meandering analogies about film sets. The signal-to-noise ratio is low.

frameworks, to me are about customer acquisition. And that's great. That's the first element. But real great businesses are built on the value that you create over time. That's more a retention. So you have the great programs. You want to get your program focused more on the retention pieces. So a good metric for that can be customer churn.
the first time a customer hears about your security and your privacy practices should not be during an incident. It should be way before that.

Originality

10 / 20

The reframe of certifications as acquisition assets and continuous trust-proof as a retention mechanism is a useful and underarticulated idea in GRC circles. The MFA accessibility angle is genuinely underexplored. But the Munger quote opener, generic AI caution, and 'security is everyone's job' observations are all well-worn territory.

a certification is a historical viewpoint. It is an attestation about a moment or period of time in the past.
it's frameworks first in a lot of conversations versus we're building this product and we have this data and we need to make sure that we're doing the right things

Guest Caliber

11 / 20

David Grazer is a genuine practitioner with real operational experience inside a $2B platform and a GDPR-era privacy practice, and he brings an uncommon product-background lens to security. However, he is now a fractional/consulting figure rather than a sitting operator at scale, and the conversation doesn't surface depth that validates exceptional seniority.

led security and privacy initiatives for a $2 billion creator platform
I've never gotten the 2am call. They've never had to take an executive off of a channel because they're not allowed to be inside during a privacy or security incident

Specificity & Evidence

5 / 20

The episode is almost entirely abstract. Cloudflare is cited as a trust-moat example but only one behavioural trait is described in one sentence; Wrapbook is discussed without a single metric, incident, or concrete outcome; and even the customer churn idea - the episode's most actionable claim - is offered with no numbers, benchmarks, or case data whatsoever.

Rachel Botsman and Edelman does really good work with their trust barometer
Cloudflare in particular, what I was kind of getting at was they've always been very good about being consistent with their communication

Conversational Craft

8 / 20

The host's prepared intro monologue is genuinely sharp and frames the guest's worldview better than most hosts manage, and a few questions (on the VCISO market critique, on MFA fragmentation) show real subject-matter engagement. But the host consistently lets the guest meander without redirecting, never pushes on an unchallenged claim, and accepts vague answers as complete - leaving the episode's best ideas unexcavated.

When you say osint then would it, uh, and that motivation is that including like crime or issues or vulnerabilities or how people are engaging from the other side?
Tell us about your early career at Tavora, your privacy practice, practice lead

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B69%
  • Speaker A31%

Most-used words

security33privacy24trust17data17folks16customer15different13interesting13product11build11part11compliance10teams10david9first9trying9

Episode notes

Most companies chase certifications to win deals - but what actually keeps customers is something no audit can measure. In this episode, vCISO David Grazer makes the case that trust is a measurable economic asset hiding in plain sight: your customer retention rate. Drawing on 15+ years inside high-growth tech companies, David explains why compliance frameworks are customer acquisition tools, not retention strategies - and how the gap between the two is costing businesses more than they realize. This episode is for founders, security leaders, and C-suite executives who want to connect their security and privacy programs to real business outcomes.

Full transcript

42 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello and welcome to SecureTalk, a podcast where we explore the critical world of information, security, innovation and compliance. I'm your host, Justin beals, founder and CEO of StrikeGraph. Together with our expert guests, we'll provide you tools and tips to help your business thrive in the rapidly evolving cybersecurity environment. Hello everyone, and welcome to SecureTalk. I'm your host, Justin Beals. Before we get started, I just want to let you know that our Chief Product Officer, Micah Spieler, will be at Identiverse, uh, next week, June 15th through the 18th. And we'll be speaking on a panel there about agentic identity management. Um, so if you're in the neighborhood at Identiverse, uh, please stop, uh, by his panel and uh, let him know you said hello. Ah, now onto our episode. Charlie Munger said that trust is one of the greatest economic forces on earth. My guest Today opens his LinkedIn profile with that line. And after our conversation, I understand why. Now, most of us treat trust as something soft, a kind of thing you talk about but never put a number on. David Grazer argues the opposite. Trust is a figure you can find on your balance sheet and the place to look for it is customer retention. Now here's the argument. A compliance framework will get you in the door. It is a customer acquisition tool. You earn the certification, you clear the security review, you win the deal. But a certification is a historical viewpoint. It is an attestation about a moment or period of time in the past. The trust that keeps a customer with you for years is something you have to prove continuously in the present. It shows up in the way your support team talks to a worried user in the data you choose to collect at Onboarding. And whether the first time a customer hears about your security practices is during an incident or, uh, long before one ever happens. Now, David has spent his career on both sides of that equation. Building products and then running security and privacy programs to protect them. We talk about why frameworks are the beginning and not the end, why a customer churn might be one of the most honest security metrics you have, and why the controls we bolt on for safety like multi factor authentication, so often fail the very people who need them the most. Now, David Grazer is, uh, a principal and VCISO at Steadfast Partners with over 15 years of experience building and leading security, privacy and trust programs for high growth technology organizations. With a product driven background, David specializes in integrating security into fast moving environments that support innovation while maintaining strong controls and customer trust. Now David brings, uh, a deep expertise in trust by design programs, enterprise identity and access management, fraud prevention, privacy program development, and ISO 27001 readiness and certification. He has led security and privacy initiatives for a $2 billion creator platform, supported regulated fintech environments, and partnered closely with product and engineering teams to deliver secure, compliant and enterprise ready capabilities. At Steadfast Partners, David serves as a fractional security leader, helping their customers navigate complex security reviews, unblock enterprise deals and translate technical risk to into clear business decisions without the overhead of a full time executive. Join me today in WELCOMING David to SecureTalk. David, thanks for joining us today on SecureTalk. We really appreciate it.

Speaker B: Thanks for having me. Appreciate the time.

Speaker A: Excellent. All right, well, we always enjoy a good origin story on SecureTalk. Uh, all of our paths are a little twisted in how we got to our current professional space. Maybe you'll tell us a little bit about how you first found your way into privacy and security. Sure.

Speaker B: So, um, yeah, I've been thinking about this. So, I mean I grew, I grew up, um, you know, watching. My dad introduced me very early to James Bond and Indiana Jones. And you know, I was um, you know, I love Iron man, but I was a Batman kid and um, you know, Star Wars. So I always kind of had this view of building and using technology to kind of help people. So there was some, something in there, I think.

Speaker A: Yeah.

Speaker B: Um, and then my dad was, my dad was in like the hardware tech startup spaces and was, you know, fairly techie. So kind of it was in the ether. And um, so, you know, spent a lot of time as a kid playing playing sports and then I was making movies and was trying to like make my own Star wars or like these kind of, you know, unique things. So a lot of my tech experience actually was in how do you make certain things work. And so that was kind of how I did it, which I think is a little different than a lot of folks in security, but um, in privacy and then you know, kind of fast forward. I ended up in, you know, tech startups and was in, in early days I was more so like on the growth hacking side. So like, so actually I got fairly good at osint, which is interesting and then hopefully they'll be okay with me saying this. And then my, my eldest niece was born and I had two cousins who I'm very close to who were kind of coming online at the same time and was like, I, I think it could be better for them. And so that kind of motivated me to transition from more of the growth and that side of things in the tech world. To security and privacy foundationally. And I've kind of moved between the security and the privacy teams and the product teams kind of for a variety of. For a bunch of years now. So a little older than I look.

Speaker A: Um, we don't often hear about a path where someone. You know, I think of gross hacking as like a marketing expertise, maybe even sales. Yeah, yeah, we don't often hear about that transition into wanting to build the product first off, because as someone told me early in my career, uh, if you want to make the most amount of money, Justin, go sell. Don't, don't build things. Yeah. So it's not, not that often that you see someone move the other direction.

Speaker B: Yeah, yeah. I don't have a good explanation for it. Yeah, it's all building. And you know, I work for a consulting firm now, so we are selling all the time and that's part of it. But, um, yeah, I think when you're doing, at least for me, when you're doing growth hacking really well, I mean you're seeing a lot of. I think where we thought it would go is now with the GTM engineering pieces and all that. It was always fairly technical. It's all about data flows and connecting them and trying to get things to work. And you know, it's just kind of advanced from there. So it was a good training ground. And um, yeah, kind of, I don't know, it was creative. And again, the OSINT piece of it is very interesting to me. You start learning a lot about how people get motivated to, to do certain things. So it's cool.

Speaker A: When you say osint then would it, uh, and that motivation is that including like crime or issues or vulnerabilities or how people are engaging from the other side?

Speaker B: At that time it was, it wasn't necessarily about. That was more so what are they doing? How can you create? How can you put the right messaging in front of people at the right time? But then as I made that transition, it was always about, um, the way, you know, when I would go into engagements with folks and do an assessment. It wasn't always about like a certain framework or whatever we were doing at the time. It was, you know, I would kind of think about what is the actor going to try to do at your company? What's the, what's the risk or threat landscape for you? And you kind of start trying to build around there.

Speaker A: Yeah. So, uh, tell us about your early career at Tavora, your privacy practice, practice lead. And that was, uh, during the run up to gdpr a Lot was changing in the market, uh, from a privacy perspective.

Speaker B: Yeah, yeah. Um, I mean, it was a lot. I had a really great mentor and she, I mean, she was an incredible mentor to many. But I kind of came in with this idea that the way that we were data really was the new oil and the way we were going to use data and that's how companies were going to create a lot of moat and economic value. Um, and there wasn't, there's that. There was that information asymmetry that people talk about all the time and that kind of led to that us starting and growing that practice. Um, it was interesting because I think it was fairly, it was fairly legal. I mean, at the time it was. We were one of the few firms who were technical first, business second, and then kind of we brought the legal end of it. That's how we kind of tried to construct the pro, you know, the practice and then. Yeah, so it was kind of trying to. How do you build these technical systems around this, this new regulation and also contend with how businesses are making money, um, and how they're creating value for their customers? And so it was an interesting time. And I think we're still. That to me is, is. This is the sneaky element of this new. If we're calling it an AI world, I mean, say go whatever direction you want to go with that. But, um, that's privacy. And the privacy engineering piece in particular, I think is going to be very. We still got some work to do.

Speaker A: You know, the consultative nature of your work, where you're like working with a particular customer and really crafting either some particular initiative that they're trying to achieve. You seem to have really enjoy that and built businesses in that modality, starting with work at Tavora. Um, tell me how you see the relationship in the larger ecosystem as a consultative effort in security. There's a lot of other players. There's platforms, there's technologies, there's, um, assessors. Uh, it's pretty vibrant.

Speaker B: Even Joe's system, um, it's a good question. So I think the way I look at it is I've spent. Actually, if you, if I've done the math a couple times, I've spent more time inside of companies than I have in the startups, than I have on the consulting side.

Speaker A: Yeah.

Speaker B: Um, but I think that that's kind of where I've seen the best consultants. One, Most of them can pick up the, picking up the tech piece. They, they're just curious by nature. So if they don't understand it they haven't built with it, they're going to go build with it. That's AI just like has rapidly enabled that for folks who may have had, you know, time constraints over time. But I think that is kind of, it's like the learning is just massive and rapid at the same time. The other piece is that I think for me, and you know, this isn't a plug for our business steadfast or anything, but I think one of the big benefits is I've been inside and outside and I think you have to. The best consultative engagements that I have is one we can work in the nuance because a lot of these programs to build like high quality risk intelligent security and privacy programs, which to me is really what you, you need to do. Um, you can, you have to be able to see the gray areas. You have to understand not just the technical system, but the human element around the system, how the decisions get made in that system. You have to know like where in an incident who can actually make a decision. And if you haven't been. I think what is tough for some is they've never actually had to be in that seat. They've never gotten the 2am um call. They've never had to take an executive off of a, of a channel because they're not allowed to be inside during a privacy or security incident or whatever. And that's, those are big decisions you have to make in real time. And um, I think that's how I try to set us there, set myself apart, is I kind of, I empathize with the pain you're going through. And these are the technical things we really need to get right and early and think about, you know, the usability of the controls and all of that. And, and then this is how we pressure test it and this is how you keep building on it because it's continuous.

Speaker A: Every customer is unique is something we always say. Do you agree with that? I think that's part of the reason consulting has been such a massive market in security privacy. And now as we get into compliance more heavily.

Speaker B: Yeah, I think it's uh, I grew up in a family that was a lot of finance, a lot of financial views. So I always kind of go back to it's, it's two things. First it's how, how does the company make money? What's your top line revenue? How does that happen? And then what's the data and the systems that kind of underpin that. And then from there you can kind of go. But you have to be very clear about how you're making money. Because what's always an interesting conversation is, well, we have all this. You're in these regulations and you have all these different scopes and you have to apply these frameworks because you've collected all this data and that's fine. But you don't make any money with this kind of data or it doesn't help your business grow in any way, shape or form. So how can you kind of peel some of that off or be very cognizant about. We have this, and it's for this reason should put a revenue stream around it at some point and then it makes, then it makes sense. And so I would just kind of try to come back to that. And that makes every company slightly different, um, and where they're actually finding value and they're able to pull their margins up, et cetera.

Speaker A: Yeah. Speaking of the economics, uh, your LinkedIn opens with a quote from Charlie Munger. Uh, trust is one of the greatest economic forces on earth. And, you know, I think you line that up a little bit. You've written about how Cloudflare is built on a trust moat by publishing its security practices openly. Um, yeah, let's dive in there a little bit. What do you mean by trust is a measurable economic asset? It's oftentimes talked much more esoterically.

Speaker B: Yeah, yeah. Um, so there are people in this space that are academics and experts in it. I would point to Rachel Botsman and Edelman does really good work with their trust barometer. Um, so if folks want to dig in more to the academics of it, I would kind of go there. But for me, it's more about. And, um, the essence. I think what Mr. Munger was talking about was say what you do and have the receipts to say that. I think you're seeing a lot of that with a lot of the chatter around GRC engineering, um, and continuous compliance. I know you talk about a stripe straight graph. It's happening in all, in all different walks. And I think it's more so saying if you do this, you can show it at any point in time and prove to customers and users, which are slightly different, um, that you are doing the things that you say. And I think there's, you know, there's an unfortunate byproduct that's happened, which is a lot of folks just look at the certification stamp and they think that everything's okay, but really that's just, you know, it's a point in time and they're attestations in a lot of cases. Of something. But security teams talking to one another, customers investing heavily in your product or your company, that has to be continuous daily in, you know, in milliseconds. Right. And to me, that's where you kind of have to. You have to get to. And it's also, you know, um, there's a lot of. With Cloudflare in particular, what I was kind of getting at was they've always been very good about being consistent with their communication. Melanie Ensign talks about this a lot. Like, it's the first time a customer hears about your security and your privacy practices should not be during an incident. It should be way before that. And you can do that with the continuous compliance and starting going there, showing the receipts, showing how you're making decisions. But it's also in going back to. Very specifically, my privacy work is collect the data you need when you actually need it, not necessarily collecting all the data up front. Like you don't need an address during an onboarding. Then don't go collecting it necessarily. You can, but it's these little, like, micro intentions that build trust. And then I think what I've been trying to talk to a lot of folks about, and it's, it's not a perfect metric, but it's more so about. You have frameworks, to me are about customer acquisition. And that's great. That's the first element. But real great businesses are built on the value that you create over time. That's more a retention. So you have the great programs. You want to get your program focused more on the retention pieces. So a good metric for that can be customer churn. So, so how often are customers churning away from you? And it's those little pieces that you can do. And it's not just everything the security and the privacy teams do. It's how even the support teams talk to the customers. I mean, that's at least for me, uh, when I've been inside as a leader, talking to the customer success teams or the support teams and how they're communicating, like turn on MFA or, you know, whatever it is, and how they help you through some of those problems. Those things build trust. And then you can see that in the customer retention and that customer retention has a direct revenue, a revenue line. And I think that's kind of where you can start to go find that really intriguing.

Speaker A: You know, we, I do tell, especially our customers, but folks that I talk to, I don't like framing, just cybersecurity. A lot of times, uh, I think it's. I get that you're Looking at a particular technical problem to solve. It's certainly intriguing to me, but I think one of the things you're describing is that security is a very broad practice at a company. It involves almost everyone on some level. Uh, it's funny, uh, the only other thing I can think that touches every part of the business that way is finance or budget, in a way. And I think it's the second pillar now in this modern era that has to be available in the business. It was started with articles, incorporation started with a balance sheet. And now you have to ask yourself, what does resilience and security look like?

Speaker B: Literally talking to a cfo, uh, a good friend of one of my partners, and he was. We were all like. We were both decided, like we were trying our pitches out on each other just, like, randomly. And his pitch was exactly the same as ours, just swapping finance for security and privacy. And I think that you're, uh, you see a lot of that people are talking about. It's this, like, translation, like, speaking more in the business language, but it's even a little bit more than everyone's just really addressed trying to solve the same problem just using completely different language. And I think that's. It's that empathy, right? It doesn't.

Speaker A: That.

Speaker B: That's how you can make sure that everyone knows, like, hey, you do have a part to play in this. Because in a lot of. In a lot of. In. In the tough times, um, security and privacy teams can't always make some of the containment choices.

Speaker A: That's.

Speaker B: It's not on them. It's the. It's the partners. And everyone has to kind of be involved in that and understand their part. And you have to figure out these, like, translation layers.

Speaker A: Mm. Yeah. Yeah. Um, let's, uh, let's talk a little bit about your last operational role then. Some, you know, you, uh, were at wrapbook product, um, manager. You built identity and data stewardship for entertainment payroll. So it's a very entertainment industry gig. Right. Uh, a lot of maybe risk in the data that you guys stored. Were there any, you know, how did you approach this new role? Um, what's some of the first steps? Because as we mentioned, each company is unique. Right. So there's some analysis up front, I'd imagine.

Speaker B: Yeah. I mean, I will say I also had a really great, um, counterpoint who oversaw fraud as well. So it was kind of a dual effort. But, yeah, I mean, Rapbook, what is they're solving? You know, it's really the financial services area of the entertainment space, and they're doing. You know, I'm obviously biased because I was, I was there doing a really good job of that. Uh, and it's a, it's a complex, it's more complex than people think behind the scenes. There's a reason that the credits are so long in a movie. Um, and so, and it's also, it's, you know, it's the original gig economy in a lot of cases, um, you know, or the, I guess the more modern gig economy outside of the studio system. And so every, a lot of people are freelancers and they can hold dual roles. You know, they can be a, uh, grip and a camera operator. They can be a, uh, you know, a production assistant or, you know, whatever, on the same, same week, different days, same, same movies and TV show, same commercial. And it just so, you know, I think for us it was about really just being very clear about the Personas and trying to kind of declutter what was going on. Then kind of with that very key understanding of that's how, how the money moves, then you can start kind of building the right guardrails around who someone is. And um, I won't get into some of the specifics of it necessarily, but it was, you know, we had two sides of it. There was the business, the business folks, the production companies, etc. Who are bringing the, the movie or the project, uh, to scale. And then there's the folks that were helping, they were working on the project. And so it's kind of separate identities. There's more of like an enterprise type of account element. And then there's the more, more freelance kind of side of it. And you had to kind of, you kind of marry both. And, um, there's a lot of, a lot of fun kind of problems to work with. And it's a, it's a great group that continues to work on it.

Speaker A: The, the business person in me thinks, uh, about this and it, yeah, what a, what an interesting set of complexities. Like, I'm, um, from Atlanta. I have a lot of friends that work in the, um, work in film, you know, help on set, uh, quite a bit. And, uh, even the companies are ephemeral. They'll stand one up and film something and then that disappears. That makes identity management really change.

Speaker B: Challenging.

Speaker A: We don't even think about it in that way in most of our systems. Yeah.

Speaker B: Yep. It's interesting. I, I, I always kind of said that movies are, I think films and commercials kind of lend themselves best to this. Even TV shows, I guess, but they're all like they're, they're very like startups, right? Tech. They're all kind of the, the same. They're like these little worlds that have to exist and they spin up and then, you know, hopefully they spin up for a long time. Right. And then, but then even in a movie, it's, there's an end part to it, right? Yeah, yeah. Um, so that's, that's always kind of the way I've, I've looked at it.

Speaker A: Um, now you're at Steadfast presently and, uh, they describe one of your specialties as trust by design for product and AI teams. And so we talked a little bit about your work on the product side and privacy and security. Security. Uh, let's crack open the AI space. Uh, maybe we'll just start with, you know, did you have a lot of prior background in data science and machine learning and your other product roles, or have you been coming into the environment a little bit?

Speaker B: Um, I have experience in the data science and the machine learning pieces in different roles in. And in different kind of ways. Yeah. So, I mean, that has been kind of the, the growth of it. Um, and it's kind of just continued to ex. Expand. I, I guess I, I think we're

Speaker A: still,

Speaker B: still early days and it's, and it's exciting and I'm, I'm cautiously optimistic, I think, about where, where we're going. I think it's going to be very interesting. I think, you know, I'm a parent, so I have both sides of the hat on. I think about it from a technology perspective. It's really interesting. And then you think about it as, as a parent and you know, focusing on like the core fundamentals of things, um, that, that your children need to learn. Um, but yeah, we're, we're continuing to evolve in that space, but I think what keeps coming back, what we keep coming back to is it's the fundamentals still for a lot of companies, it's just, it's really honing in. You know, like I was saying before, it's honing in on how the revenue piece, how are you making money as a business. And if as you implement AI, whether you're going to host something and build your own model, you're going to go in that direction or you're going to go at it from using some of the foundational models that are out there today, you just have to be really clear about what, what you're doing, what you're, what you intend your outcome to be. And then you can kind of, and then you can structure everything around there and start putting your own governance or guardrails around it and in the code or in the way that you just operate, um, as a, as a business.

Speaker A: Yeah, I think um, you know, it could explode, like shadow it. We certainly have that. But I think you're expressing a sense of intentionality into, you know, where to layer it in and to look back at the business for the risk areas or rewards, um, from those decisions. Right.

Speaker B: Mhm.

Speaker A: Yeah. Um, I wanted to get to the vciso model a little bit. It's what you're working on lately. Um, and uh, you know, I think you guys probably started steadfast as somewhat of a critique against solutions that are in the marketplace or in some form differentiation. You know, tell me a little bit about what you see as some things you want to improve in the vciso marketplace. Habits that you don't think are as beneficial as could be or maybe even deleterious to an outcome.

Speaker B: Yeah, yeah. Critique's an interesting way of looking at it. I, I think it's more so that we've, all of us have been in this space for a while. So you know, I think when you collectively look at it, it's I don't know, 30 plus some odd years, which I think makes all of us feel a little bit older than we thought we were. But um. Different conversation. Yeah, but we, we really think that there's an opportunity for um, companies to get ahead of some of the, the tough questions that they're going to face. And that's, you know, really what we've tried to do. And we, you know, with the experience that we've had, all of us have been inside, so all of us have in some way shape or form been inside a company that has to comply or think about data, data risks, however they kind of show themselves and that's really the way that we tried to approach it. And we also. I've uh, spent a lot of my career in this, you know, the startup world, so younger companies and there's things that we did well and things that we could have improved upon and we can now looking back, say we could have made this decision earlier and that would have made it easier for us to get into this new market or um, we miscalculated on this and it cost us too much money or uh, you know, there's a variety of little nuances that you kind of play with and that's more so again, I'm not sure it's necessarily a critique, but that's more so how we Kind of present ourselves as we've been in your shoes and we're going to help you make the best choices so that you're focused, you know, get you to that compliant level that helps you get into the game, helps with the buy in, but doesn't necessarily. But then you're not necessarily worried about every new regulation, every new market and every new threat because you're making more risk based decisions. You're improving your decision quality around, you know, how you make money now and in the next six months and 12 months or whatever it may be and how you can kind of, and we can coach around those, those problems and apply the right technology in the right places.

Speaker A: So 30 years the industry has been around a little bit. Um, I'm, I'm newer to it. Right. I've been um, working at Strike Graph now for six years. Uh, plus. But uh, has it changed the, the part of your conversations that are about compliance when you think broadly about the marketplace or has it always been a big part of the discussion? Sometimes I imagine that it's gotten more a part of the discussion recently.

Speaker B: I think it is, I think there's, yeah, it's become more a part of the conversation. And you know, I think uh, there's a variety of folks online who have kind of re reminded me of the reason we came to all these frameworks, which is it was to attest to the programs that we've built. And I think that's the piece that it gets glossed over a little bit. I think everyone has really good intentions with the way they're approaching it. But it's interesting that it's frameworks first in a lot of conversations versus we're building this product and we have this data and we need to make sure that we're doing the right things so that we can get an attestation to help us get into these markets or work with these partners. But we also want to build a 50 year company, 100 year company. We want to be the, you know, whatever unicorn level you want to be like yeah, those things come beyond just kind of your foundations. You have to build on the foundations. Um, but I do also in kind of that compliance conversation being very heavy, you're also seeing it kind of flip to what it means to do compliance now, which I think is really great that more folks, um, on the, on the GRC side of things are being asked to embrace more like DevOps style, uh, workflows and that will one helps them have more empathy for how things are working in the infrastructure which is just so crucial. But also it will make compliance live at a level that it can really live, which is there is confidence at that compliance level. But you have to show continuously to make that confidence. If you go back to trust, trust is typically earned. You have to earn that trust and you show that by living up to what you're, what you're saying you're doing.

Speaker A: Yeah. One of the common misconceptions I see is people imagine that a framework or a set of requirements will tell them what to do. I find that to be very rare. You know, a lot of the people that wrote these sets of requirements, as I read them, I find them to be very smart dealing with a challenging problem, that they want to maximize the use of the content they're writing and that can make it very generic in the way they write it.

Speaker B: Mhm. Yeah, it's there. I mean there's a lot of nuance in the implementation,

Speaker A: which probably brings us full circle to why it's nice to have someone that knows the business and someone that's an expert in implementation making some of those decisions.

Speaker B: Yeah, there's a lot, there's a lot of. I think the great thing about the security and the privacy community and I look at it, I'm not the only person, but I look at it very broadly. Right. I think there have been people in my experience who are just, they level up your view of what high quality is. Um, and I've in particular in the last like five years I have met some incredible DevOps engineers or infrastructure reliability engineers and these folks just raise the bar on security and they don't align themselves and don't call themselves security folks. But I can tell you that the great ones, it's embedded, it's just a part of the cake. It's the ingredient. It is by design that you want. Um, and that I think is, you know, just that continues just to bring everything up a level. So. Yeah.

Speaker A: Now you describe, uh, yourself I think in some of the background work that we did as an independent researcher, done some great work in the intersection of technology, people, society and responsible AI. So I'm just a little curious about what's interesting you today. Like what, what are you enjoying looking into? Where is your curiosity leading you?

Speaker B: Yeah, um, it goes all over the place. Uh, but I, I mean I think there's two areas I, I think broadly speaking the, where digital and physical meet. So I think those experience, I think those experiences are just going to continue to be very prevalent. They're going to be and they're going to be increasingly, uh, astounding. And there's going to be some unique questions around privacy and security in there. And so I've. And so I think a lot about that right now. And you know, that convergence. I think the term that a lot of people use is phygital. So I think about that piece a lot.

Speaker A: I have to say. I haven't heard of phygital. So would you describe it for us?

Speaker B: Yeah, it's physical and digital.

Speaker A: It's okay

Speaker B: a lot in the retail space, but yeah, that's where I've been thinking a lot. And then I think the great experiences to come. There's a lot of great experiences today, but when you get to the physical and the embodied AI and you kind of add the spatial computing that we're seeing advance, those new experiences, those new physics around that are just going to be so interesting and the way that the data flows is just going to be something to kind of think about. And then I'm always kind of curious, I'm always very interested in. Heidi Trost is a great focus on usable security and privacy. Um, and I've been thinking about that for a long time, but in particular around folks that have different types of abilities, around technology. So something as simple as multifactor, uh, is not necessarily accessible or inclusively designed for everyone. And we try to bolt it on. And for me, that is, um, something we have to continue to think about. There's a lot of, there's nuance in the way we apply mfa. Yes, you should. It's incredibly helpful. But you have to also think about the Personas that live inside your user base, your customer base. And I continue to think about that as kind of a research problem. And I think that will expand, you know, obviously, as, as AI becomes, you know, more of an avatar or an autonomous agent for, for certain folks.

Speaker A: Yeah. I have to say, lately especially, I've been really disappointed with the MFA implementations. It is so confusing. And I use computers. I feel like a lot of the time I program them myself. I've set up, you know, identity management systems and some of the software that we've built over the years. And it's like I've got 15 different choices, six of them commercial that require a subscription, none of them a thing that I carry around with me everywhere. Um, and it gets really, like, frustrating. Um, I complain that we left too much room for the commercial in the MFA work. I think we needed almost like a standard methodology. It was the same all the way around. And it's almost like we left too many different lanes for the implementation possibilities. Yeah, yeah.

Speaker B: I mean, there's a variety. I mean, there's a bunch of protocols that are, you know, we have our tried and true protocols that we use under the hood to do it, so I think that's fair. I also contend that we thought about very specific groups of folks. This isn't accessible. It's. It's very difficult and you know, even like the complex, the complexity requirements and that has been in my head for years now. And um, so I, I kind of go back to that piece. Is there also needs. There needs to be. I agree there needs to be maybe less choices, the paradox of choice. But there also needs to be a lot of flexibility in the way that some of that gets delivered to certain, um, to certain segments in your users.

Speaker A: Wow. I love that area of investigation. It's been a lot of time in the, um, education space and certainly had to deal with the 501C3 work and making sure that systems were useful for a really broad population with difficulty, differing sets of needs. Yeah, absolutely. Well, David, I really appreciate you joining us today on SecureTalk and sharing your expertise with our audience.

Speaker B: Of course. This is a lot of fun. Thank you, Justin.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Eric Ries on Why Good Companies Go BadPodcast Archives · on Cloudflare92 / 100
  • CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno LecoqSecure & Simple · on ISO 2700189 / 100
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ GongSecurity & GRC Decoded · on ISO 2700186 / 100
  • Enterprise Software Buyers Now Demand a Vendor AI Training Data Provenance AuditB2B SaaS Talks with Fexingo · on GDPR80 / 100
  • AI and Cybersecurity in SMBs: Insights from Bruno LecoqSecuring the Realm · on ISO 2700179 / 100
  • Navigating AI Risks with Trevor Horwitz from TrustNetB2B Automation Spotlight · on ISO 2700179 / 100

More from Secure Talk Podcast

All episodes →
  • CMMC Is an HR Problem, Not an Enclave Problem - Here's the Proof95 / 100
  • Why you could fail your CMMC Level 2 C3PAO audit | Secure Talk with Logan Therrien
  • Mark Zuckerberg has an AI twin. Who Is Mark Zuckerberg?
  • The ROI of Security Tested: What a new paper reveals about security value | Secure Talk with Minh Nguyen and Thi Tran
  • They Sold AI to Play God. China Never Got That Memo.
Explore the best B2B Engineering & DevTools podcasts →
All Secure Talk Podcast episodes →