
Security & GRC Decoded · 2026-03-10 · 1h 6m
Key moments - from our scoring
Substance score
64 / 100
Five dimensions, 20 points each
Bryan Culp brings a unique perspective combining 20+ years in cybersecurity with dual oversight of both customer trust and third-party risk at Box. The episode centers on his prediction of a GRC reckoning - a fundamental shift in how governance, risk, and compliance work over the next two to three years, driven by automation, GRC engineering, AI adoption, and significant venture capital investment. Culp argues that GRC transformation stems from competing pressures: leadership wants faster certifications and market access at lower cost, while GRC professionals themselves seek to improve actual security posture rather than just checking compliance boxes. Customer trust, which Culp carefully distinguishes from GRC, is about packaging and communicating security and compliance work to customers through standardized frameworks like SIG (Shared Assessments), CAIQ (Cloud Security Alliance), and HECVAD. The core challenge he identifies is translating complex operational data - vulnerability scans, remediation timelines, policy compliance across engineering teams - into quantified risk metrics that C-suite executives can understand and compare. Culp emphasizes that real progress requires automation of data collection and correlation with financial impact, enabling GRC teams to speak the language of senior leaders: dollars and cents. The episode tackles why enterprises struggle to quantify risk and explores how AI might serve as a universal translator to consolidate fragmented data sources.
Customer trust takes the work done by GRC, security, and privacy teams and packages it to be consumable by customers - typically through Q&A repositories, standardized frameworks like SIG and CAIQ, and audit support. It also involves customer conversations and audit support, whereas GRC focuses on internal governance and compliance operations.
Customer trust teams build question-and-answer repositories aligned with standardized frameworks (SIG, CAIQ, HECVAD), which cover 80-90% of typical customer questions. They normalize language across internal stakeholders, create audit toolkits that map controls to questions with evidence, and conduct regular reviews with subject-matter experts to keep answers current.
Senior leaders and boards speak the language of money and business risk, not compliance jargon. Quantified risk enables apples-to-apples business comparisons and lets GRC professionals communicate with executives who are not security experts, making it easier to drive informed decisions about security investments and posture.
The transformation is being driven by a combination of factors: leadership pressure to reduce costs and accelerate market access through certifications, GRC professionals' desire to improve actual security posture, significant venture capital investment in GRC automation and engineering, and emerging AI capabilities that could act as universal translators for fragmented data sources.
Organizations need to automate the collection and curation of operational data (asset management, vulnerability remediation, MFA adoption, logging), then correlate that data with financial and business impact to translate security activities into risk metrics that executives can understand and compare.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid practitioner insights about customer trust, GRC transformation, and real-time assurance, but much of the content rehashes established industry frameworks (SOC 2, ISO, CAIQ, SIG questionnaires) and relies heavily on forward-looking speculation rather than concrete lessons learned. Bryan offers useful operational perspective on translating GRC data for customers and AI tooling, but there's significant padding through restated premises and hedging language that limits density.
80 to 90% of this is being covered by industry templates like SIG, CAIQ, HECVAD
what I'm suggesting is that in the next two to three years, we will see more viable options of truly bringing this together
Bryan articulates a thoughtful vision of GRC transformation and real-time assurance over 2-3 years, and his dual perspective on customer trust vs. third-party risk management offers genuine value. However, the core arguments - automation will change GRC, AI will help translate standards, hygiene matters before advanced threats - are well-circulated industry consensus rather than contrarian or first-principles thinking. The framing is mature but not particularly fresh.
in the next two to three years, the way we are doing GRC is going to be different
I'm optimistic in terms of AI being able to be somewhat of this quote, universal translator between the different standards
Bryan Culp is a highly credible operator with 20+ years in cybersecurity, hands-on experience building GRC teams at enterprise scale (Cisco, Box), and the rare dual-hat perspective of running both customer trust and third-party risk management. He speaks from direct responsibility for real outcomes (new ARR impact, vendor risk decisions) rather than theory. This is genuine practitioner caliber, though not a founder or C-suite exec.
Bryan has 20 plus years in cybersecurity. He has done almost everything in cybersecurity, from strategy planning to operations and to building enterprise-grade GRC teams
I have the customer trust team and the third party risk team. So we both are looking at the vendors as well as responding to customers who see us as a vendor
Bryan offers few concrete examples, numbers, or named case studies. He references large banks as 'canaries in the coal mine' and mentions Box's use of AI in third-party risk workflows, but lacks specifics on impact metrics, timelines, vendor names, or quantified outcomes. Most claims remain at the level of industry observation and aspiration rather than grounded in hard data or named examples.
we report out, for example, on the percentage of new ARR that we are impacting each quarter
we got a bunch of these docs, just run it, we get a report on that vendor, right?
Raj asks solid follow-up questions that surface Bryan's thinking on risk quantification, the tension between certs and actual security, and the dual perspective on vendor relationships. The host pushes on hard problems (why certs don't prevent breaches, why quantification is difficult) and doesn't accept surface answers. However, some questions feel slightly leading or restated rather than truly challenging, and Raj occasionally validates Bryan's points rather than probing deeper disagreement.
How do you reconcile the fact that we are putting all these efforts from a GRC and a customer trust perspective, but we are still open to this big surface area and attack that we are vulnerable to?
There is a lot of time and energy being spent on certifications and attestations...but whenever we hear breaches, right? Massive breaches, it's not for the lack of the certifications, right?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Bryan Culp , Senior Director of Customer Trust at Box , to explore how governance, risk, and compliance is evolving beyond certifications and into real-time trust. Bryan shares why the next two to three years will fundamentally change how GRC operates - driven by automation, AI, large financial institutions demanding real-time internal metrics, and growing pressure to translate security posture into business language. From managing both customer trust and third-party risk at Box, Bryan offers a rare dual perspective: how companies present assurance to customers while simultaneously evaluating vendors themselves. This conversation challenges the idea that certifications alone create security and makes the case for risk being the true language of leadership. Key Takeaways : Customer Trust is not traditional GRC - it translates security and compliance work into business confidence for customers. Certifications enable market access, but they do not eliminate breach risk. Risk must be communicated in executive language to influence real business decisions.
Transcribed and scored by The B2B Podcast Index.
Raj Krishnamurthy (00:01.031) Hey, hey, hey, welcome to another episode of Security and GRC Decoded. I'm your favorite host, Raj Krishnamurthy. Today, I mean we have the fantastic Bryan Culp with us.
Bryan has 20 plus years in cybersecurity. He has done almost everything in cybersecurity, from strategy planning to operations and to building enterprise-grade GRC teams. He's currently the senior director of Customer Trust at Box. Bryan, welcome to the show.
Bryan Culp (00:30.318) Thank you so much and thanks for the intro. Raj Krishnamurthy (00:33.651) So Bryan, what is one controversial opinion, heart take you have on GRC and customer trust?
Bryan Culp (00:40.044) Yeah, so taking big picture and looking at GRC, I don't know so much controversial, but I think in the next two to three years, we are doing, the way we are doing GRC is going to be different. I think we will still call it governance, risk and compliance. Some of the titles may be the same, but fundamentally, if you pull back the covers, what the individual is doing GRC is going to be pretty different.
I think this started up, started gaining critical mass in the last two years. And I think, you what's the purpose of the podcast right now? It's dated in time, put a pin in it. As we look to January, 2029, you know, for us to then evaluate and look back just to what extent have we really seen transformational change that what we're doing in our day-to-day jobs and how we're doing it is just really that much different.
Raj Krishnamurthy (01:37.075) What makes you say that? Bryan Culp (01:39.692) So, and again, like to me, this isn't rocket science.
I think it's everywhere as we look around. So in the last two years, the critical mass around GRC automation, GRC engineering, then you add on AI, everything everywhere. We are seeing more and more vendors come into the space, a lot of investments, a lot of innovation. We're even seeing, you know, open source ideas of putting together a GRC stack and publishing that.
And so, you know, I'm not going to sit here today and say who's going to be the quote unquote winner. But what I am comfortable saying is the next two to three years, we are going to see how this plays out. And in three years, I don't necessarily know that there'll be one, you know, vendor or particular style that's the absolute winner. But I think we'll have a better sense of where things are.
at that time. Raj Krishnamurthy (02:38.355) Got it, got it. And I want to talk about customer trust in GRC, but before I do that, this is a very interesting take, Bryan.
So GRC is a very old discipline and function, right? It has been there for years and years and years. What is causing this sudden transformation that you're thinking of? Bryan Culp (02:57.
23) Very good question. So I think a lot of it is the attention to how do we do things more quickly and reduce the costs. I think big picture in terms of external focus on GRC. lot of that is becoming from GRC plays such a key role in market access.
So get the certification to get the market access. And so there's a lot of that visibility. But at the same time, we're seeing leadership not wanting to pay as much for that. And then on the other side, and in this, representing GRC professionals, and I think so, for all of you out there, part of what we're wanting to use this leverage for is really to lift the security and compliance posture of the environment that we're working in.
And so... I think many of us kind of have these mixed feelings about that, you know, great leadership loves the market access, the certs, et cetera. Like we'd like that, that we'd like that attention, but truth be told, we want to have more focus on that security and compliance posture as well. And so we're trying to have it both ways.
And so I think the, the mix of these different incentives from the different players is what's driving it. Along with just a lot of investment coming into this area. And so. Raj Krishnamurthy (04:23.
42) price. Bryan Culp (04:24.338) I think a lot of the investment obviously is being driven because people are starting, they think that they're going to get those returns. And so, you know, we'll see how this plays out.
Raj Krishnamurthy (04:34.258) Got it, got it. So you're saying a tops down movement from new market, new revenue, new opportunities and a bottoms up movement in terms of better visibility and operational compliance is what you're saying is driving a lot of this up. Bryan Culp (04:45.
154) I think you did a fabulous job of summarizing what I meant in that. Like, I'm just gonna use that. And yeah, if that shows up in a post somewhere, or if I share it with my friends, you and I will know that it actually came from you. I think that that's a good, that's a really good summary.
That's a good summary. Raj Krishnamurthy (04:59.858) Thank you, Bryan. I just restated what you said.
Bryan, you have a very interesting profile. You actually started with cybersecurity strategy in operations. Maybe why don't you walk us through from your days of journalism into cybersecurity, into running customer trust right now. What was the journey like?
Bryan Culp (05:23.512) Yeah, I knew you were gonna work journalism in this. yeah, hello to your daughter, I think, if I remember that correctly. So personal information you shared is that she's in journalism and so you've had a chance to learn a bunch about that.
So for me, yeah, so my undergrad was in journalism. This goes back to high school when I listened way, way more to my parents and bought into this idea of do a major where you can get paid for as opposed to what you just. feel passionate about. really love writing and so I went that path.
But really in terms of the career in this particular space, a lot of people in GRC grew up through Big Four Consulting. My path is a little different. So for those of you who didn't, I'm an example that it can still work. And so my path was more through MBA with a focus in marketing and I was very fortunate to do an MBA internship at Cisco.
And so that was really you know, how things started off. I was in marketing for a bit of time, really, really enjoyed it. I still like messaging, communication, et cetera. But ultimately I found myself a lot more excited about strategy planning and ops and had a great opportunity in engineering also at Cisco.
And then my boss moved over to the security and trust team and asked if I wanted to join her. Very, very fortunate that I did that. Just absolutely fantastic experience. I had previously done some work with US public sector and US federal sales.
So was kind of familiar with that cybersecurity area. And then ultimately what happened to really get me on the path that I'm on today is there was an opportunity for people leadership for the team that we now many of us refer to as customer trust. And so, you know, I asked and ultimately had the opportunity to do that going back to 2016. So you know, before, again, before, before we were calling it customer trust.
kind of, kind of in those early days, and then just to close out to the present, about five years ago, I left to come to Box to stand up the customer trust team, and then was fortunate enough to be asked to take on third party risk and also the policy program. And so I've kind of the perspective I have that very few of us have across industry is I have the customer trust team and the third party risk team. Bryan Culp (07:49.888) So we both are looking at the vendors as well as responding to customers who see us as a vendor.
And so it's pretty cool to see both sides of the conversation, especially the way some companies approach it differently, depending on which side of the equation. So, you know, that's me in a nutshell. Raj Krishnamurthy (08:10.648) And is customer trust more than GRC, different than GRC?
How do you put it? Bryan Culp (08:16.366) 100%. So really, really glad that you brought that up for everyone out there, particularly those who aren't as familiar with customer trust.
I would even go so far as to say customer trust doesn't necessarily need to be in GRC. I've seen it in other places, for example, sales operations, deal desk, you know, with the SEs. Ultimately, when you're stepping back and looking at customer trust, what we do really is we take all of the absolute fantastic work being done by GRC, Governance Risk and Compliance, being done by security, privacy, and other groups, and we essentially package that up to make it more readily consumable by customers.
This is way more prevalent in high tech, especially SaaS companies. It's in other companies as well, but I think it gets a little bit more attention there as well. And then also, as you can imagine, some customers, especially those who are paying a lot more and tend to be more highly regulated industries, they also wanna have conversations. And so a lot of customer trust is getting on calls, having meetings, talking through things.
It's also supporting audits where customers have contractual audit rights, which essentially... if I were to be this is you know somewhat cynical or snarky, but you know if you look at a lot of these certifications You know ISO SOC 2 FedRAMP PCI, etc, etc With a lot of those controls a lot of times the audits are essentially walk me through these controls and show evidence Kind of regardless of the fact that we already have had a third part reputable third party go through and do that Right?
And so that's why we see across industry, LinkedIn, et cetera, a lot of people talking about pushing back on questionnaires or audits, because essentially the certifications address a lot of that, but there's a little bit of kind of natural tension there because at the same time, it's a really big customer. They're spending a lot of money. You know, they negotiate those rights, but that's kind of an ongoing discussion, both internally at companies as well as across industry. Raj Krishnamurthy (10:36.
562) Correct. Box is a phenomenally great brand. establishing customer trust should be easy, right? That was a sarcastic question.
Bryan Culp (10:44.654) Thank you very, that's, yeah, fabulous. I appreciate that plug there. yeah, for the record, did not have, we did not work out that in advance, but yeah, very nice.
Thank you. Yeah, mean, to kind of like the, like the more, like appreciate it, but the more kind of like serious gist of the question, I think it's absolutely true that a lot of customers are predisposed to trust certain brands. I think many, many of your viewers are working at some of those customers, some of those companies as well. At the same time, it's a huge responsibility because just like in our personal lives, once you break trust, really, really hard to get it back.
And so, we gotta be ever vigilant to maintain that level of trust. And just like in real life with friends family, etc A lot of it is communication and frankly a lot of it is if stuff isn't necessarily going right, you know You got to be at fun about that. Now. There's nothing wrong with putting on your best face and things like that mean we all do that every single day But it's extremely important.
Maybe even the number one top priority You know thou shalt to be accurate, right? So you cannot share incorrect information with customers or put it out there. That's just like the easiest way to break trust. And once you break trust, like I was saying, really, really hard to get it.
Raj Krishnamurthy (12:20.805) Herb is it Herb is it. And so you made some fantastic points, right? I think your primary job or your team's job is to package, distribute, and more than that, have a conversation with customers and establish that trust.
How do you consume information from within, particularly the GRC teams, some of the teams, some of the functions which you manage as well, right? How do you take that information and package? What I particularly ask is that what challenges do you run? in translating the information from within to outside.
Bryan Culp (12:54.51) I appreciate you making it sound super complicated and difficult. I think for those of us doing it day to day, it's fairly straightforward. Maybe if you start completely from scratch.
But the key thing is putting together a question and answer repository. But at the same time, there's a lot of industry templates, again, that many of your viewers will be very, very familiar with. The SIG from Shared Assessments, the CAIQ from Cloud Security Alliance, the HECVAD, which is focused on the education market. So these are attempts to put together, quote unquote, standardized questions, even though the SIG is so...
customizable these days, you could argue it's not truly standardized, but that's a separate conversation. So if you look at those kind of starter questions and you look at customer questions that are coming in, seriously, 80 to 90 % of this is being covered. And then if you look at some of your larger customers, especially if you have some of the big banks that have a tendency to ask a few more questions. then you get questions that may or may not be outliers.
And so you add that. But some of those banks are a little bit of a canary in the coal mine. So what they're asking now, six months later, other industries could be asking. And so that's a way to monitor it.
But a lot of it really is putting together that question and answer repository. And then at the same time, building what we refer to as an audit toolkit to essentially have those questions and really, you know, questions, control, it's kind of, they're asking the same thing, just the language is a little different, but the underlying question or the underlying control is often the same. And so if you look at an audit workbook and it lists all of these controls that they want to go through, those match pretty closely to questions.
And then the difference, Bryan Culp (15:10.594) for the audit is you then need to provide evidence. And so that's usually showing the language within the policy and then showing some evidence. And the trick there is, many of your viewers will know, there's a little bit of a difference between evidence that would be shared with your third party certs auditor and what you would share with a customer.
And so that kind of needs to be worked through. but that's kind of what goes on behind the scenes. And once you've built that up, it's really a matter of making sure you don't just let it sit. You've got to have a regular cycle for reviewing answers with SMEs, adding new information, and that's got to be set up as a regular part of the team.
Raj Krishnamurthy (15:58.322) Now, I think I'll take maybe a specific example because this, in my opinion, I think you make it sound very easy, but I'm sure your job is a very, very difficult job. Bryan, and the reason I'm saying this is that a lot of what the sick questionnaires tend to be are the cake is along abstraction of the information that you get. Let's say, for example, you have many different teams within Box, engineering teams, and they all have applications and they scan vulnerabilities as part of their pipeline.
And they have policies to remediate within a timeline. A lot of this is about collecting the data, reconciling the data, whether the teams are doing the job or keeping the promises that they make. And this is lot of data, right, that you are then abstracting into simplistic terms to your end customer saying that, we meet the threshold, right, or yes, we meet our policies. How do you go from that enormous data collection, reconciliation, to this simplified set of statements that you are presenting the customer, because you cannot present that data to the customer at all, right?
Bryan Culp (16:32.962) Yep. Yep. Raj Krishnamurthy (16:57.
925) So how do you sort of bridge that gap? Or is there a gap? Bryan Culp (17:02.484) no, I get what you're saying.
and, and so I appreciate that, that it's seen as being so complicated, but a lot of it is having really good relationships with these different stakeholder teams. A lot of it also is understanding what do they do? What are their drivers and working with them? And then a lot of it is having almost, inherent understanding of how to share this with customers, right?
Because, you know, if you take something straight from engineering, as an example, or from security, sometimes it's absolutely factual, but it's not necessarily worded in the way that you would share it with a customer. And so that is part of a sort of behind the scenes value that the customer trust team adds is kind of Raj Krishnamurthy (17:44.049) Mm-mm. Bryan Culp (17:59.
982) doing that translation. But I guess one of the things I'm realizing in talking this through with you is it's just sort of something you take for granted for the people that are doing it, because that's really part of the value add. And then another part of the value add that just comes to mind as we're talking through this is the way the different groups may think about things could be a little bit different, or they might use language in a little bit of a different way.
So as we intake that information, we quote unquote normalize it so that, because ultimately if it's all coming from our company, we want it to look as if it's coming from the same voice and not necessarily the voice of some of these SMEs. And so we definitely do that as well. Raj Krishnamurthy (18:48.561) Okay, when we spoke last time, Bryan, and we were talking about G and R and C, and I was asking you what your perspectives are, one of the things that you said is that we need to have a lot more risk focus.
Am I saying this right? Why did you say that? Bryan Culp (19:02.691) Yes.
Bryan Culp (19:06.286) So to me, this is not like a big reach. And I think a lot of us across the industry think this and are saying this. So the reason I'm driving this is because a lot of senior leadership is interested in what customer trust does because we can report out, for example, on the percentage of new ARR that we are impacting each quarter.
New ARR, very, very cool. Like that metric, everybody can get their head around it, right? Also the compliance, the certifications team, typically within the compliance team, gets a lot of attention because they're on the front line for getting the certs, which senior leaders are rightfully seeing ultimately as market access, right? But compliance does a lot of other things too.
They're not just the compliance search team. They're also involved in other areas as well. And so my take, so I understand the focus on those areas. I appreciate that.
I have one of those areas myself, right? At the same time, ultimately, I'm in the camp where I'm looking to lift the security and compliance posture of the whole company. And to me, the best way to tee up an informed discussion with leadership is in terms of risk, right? And then as lots of people are talking about, and you've had guests on talking about that, the extent to which we are able to quantify that, to be able to talk to the CEO and the CEO's reports and the board of directors in terms of risks that are quantified so that these leaders who may know a lot about GRC and cybersecurity, but...
Typically, that's not where they've spent the bulk of their career. That's not their primary focus, right? And so we need, it's incumbent upon us to make it easier for them to digest this information and make apples to apples business comparisons. And so to me, that's what I meant, or that's kind of the background behind this notion of focusing more on risk and trying to have risk more out in the forefront.
Raj Krishnamurthy (21:21.937) But water, mean, typically some of the, I mean, we had Tony Martin Vague, I don't know if you know him. He actually, no, I think he did, so, but one of the challenges, Bryan, is that. Bryan Culp (21:28.
343) That was the exact conversation I was referencing. I'm trying my best to not like call out vendors or people's names, but yeah, that. Raj Krishnamurthy (21:43.909) We see customers and enterprises find it extremely difficult to quantify risks.
Why? Bryan Culp (21:49.166) Chris. Bryan Culp (21:53.
16) because the model is per se. So, so as we're trying to quantify risk, so the risk isn't truly known. So how are we using math to essentially build out a risk model that can make sense? Right.
And, you know, there's lots of people that have done a lot of work on this. Tony obviously can go super deep on it. But if you're talking about something like fare, you know, sometimes it takes a little bit of time and it's a little difficult to roll that out in some companies, some companies it works. I've seen it go both ways.
But ultimately, whatever it is, I think that in order for us in GRC, and I think to a certain extent, security is in this boat as well. It really, really helps the cause if we can speak the language of senior leaders, which is really talking about things in terms of money, dollars, cents, right? And ultimately that requires that quantification. Raj Krishnamurthy (23:11.
153) Got it, got it. I think there are two aspects to this, right? Bryan, one is about what is operationally happening, right? I mean, do all the users have MFA, which is, I think we are way past that today, using that as an example, Vulnerability management, are you maintaining your assets properly, are you logging properly?
And all these are fantastic hygiene, brush your teeth, eat your vegetable stuff. But that, Bryan Culp (23:19.789) Yes. Bryan Culp (23:25.
324) I hope so. I hope so. One can hope. Bryan Culp (23:36.
504) Yes. Raj Krishnamurthy (23:39.084) In some ways, we have to automate the collection of the data and the curation of the data and then correlate that with dollars and cents so that it can be bubbled up to meaningful numbers that leaders can sort of talk about and think about, right, like you're saying. Do you see challenges in making that happen?
you're... Go ahead, go ahead, please. Bryan Culp (23:52.462) 100 % Bryan Culp (23:58.
318) No, no, please go. Yeah, there's huge challenges. I mean, that's why we're not there right now. But, you know, when we started off and you asked me for kind of my take and I talked about this notion of the next two to three years.
So, you know, like I've seen this going in a positive direction the last two years, building up critical mass. And so what I'm suggesting is that in the next two to three years, Raj Krishnamurthy (24:08.731) Exactly. Bryan Culp (24:27.
64) we will see more viable options of truly bringing this together, right? And as we talked about at the beginning, part of this is connected to the notion of automation, GRC automation. And then I think also, I'm optimistic in terms of AI being able to be somewhat of this quote, universal translator to bring together information and sort through it a lot more quickly or in ways that frankly we haven't been able to by applying people or existing technology to it. I don't know exactly how that is gonna work out.
but there's a lot of smart people and a huge amount of money that are making various bets in different ways for it to work out. And in my view, the next two to three years is enough roadmap to see how that plays out. But to go to the question that you're asking right now, yeah, it straight up is in an automated fashion, being able to internally within your company, have a level of assurance that these things that we're calling hygiene are in fact being done, right? And then ultimately, how do we then look at other risks?
my view is that once we have the hygiene, people talk a lot of times about adversaries, they don't necessarily need a zero day. They don't just go grab somebody's credential. You know I mean? If the door is unlocked or it's wide open, you don't need a whole bunch of sophistication.
And so a big part of what I'm looking for, and I think a bunch of others think this way as well, like, let's just make it a little harder. know, like, let's lock the door. Maybe it was a really good lock, you know? But then once that happens, then the adversaries, like, they're also innovative, they're productive, they have technology.
You know, it's essentially an arms race and they're gonna be figuring out other ways. And then we'll be focusing on what are those risks. Raj Krishnamurthy (26:47.419) Got it.
And I'm not trying to throw a curve ball at you, but... I think you've been on both sides, Bryan. You work with customers, you're customers on establishing the trust, and you also run the third party risk management program for Box, which means that you also deal with vendors. You see both sides.
Bryan Culp (26:52.034) That means you're trying to throw. That means you're going to throw a curveball. Thank you for setting me up.
Yeah. Bryan Culp (27:07.104) Yep. Yep.
Raj Krishnamurthy (27:12.421) There is a lot of time and energy being spent on certifications and attestations, right? SOC 2, ISO, so on and so forth. But whenever we hear breaches, right?
Massive breaches, it's not for the lack of the certifications, right? So we might have, Target may have, and I'm not trying to use Target as an example here, but any company can have all these certifications in the world, but they go through some very extraordinary breaches, right? And that is bound to happen. Bryan Culp (27:17.
176) Yep. Yep. Raj Krishnamurthy (27:40.557) How do you reconcile the fact that we are putting all these efforts from a GRC and a customer trust perspective, but we are still open to this big surface area and attack that we are vulnerable to?
Bryan Culp (27:52.142) Yeah, that's like the trillion dollar question, right? I mean, a lot of it goes to so many of these attacks are related to the software and the number of bugs per X thousands of lines of software and how that gets fixed and how that gets discovered. A lot of it goes to the fact that business leaders have are essentially incentivized from a fiduciary responsibility to limit, to identify and limit risk, but not necessarily erase risk because of the cost associated with that, as well as detriment to innovation and basically the advance of the business, right?
The classic conversation about like, have it totally open or totally locked down. So the thing is, Like, I think we all know the problem statement, right? And we've talked about it. And we're kind of all facing it, our own flavor of it, you know, depending whatever company or government agency we're working in.
But yeah, I mean, I don't have, you know, like some pat answer that's gonna completely solve this. But I appreciate you teeing it up. Is there something you could ask me about that I could answer? I mean, like I get it.
I get it. You know, I mean, like you said, I've got the third party risk team and we're looking at all this assurance documentation. We're having conversations. you know, there, there is a general recognition and understanding that third parties are one of the more predominant attack vectors.
Right. And so. Raj Krishnamurthy (29:19.376) I Bryan Culp (29:44.
97) But then at the same time, there's so many more companies and they're innovating and everybody wants what's new. And so how do you really evaluate all of those? And it becomes like a point in time, moment by moment business decisions by various leaders because they're still going to want those companies that have that most innovative product that helps them innovate more. And so it's a healthy discussion that's going on in our companies.
and the government like every single day. But I don't have some, like I'd probably be doing something else if I had some kind of like super pat answer for that. Raj Krishnamurthy (30:17.306) Totally.
Raj Krishnamurthy (30:25.646) Now, some of these questions are very tough, right? And they are difficult as well. But let me, actually, you said something very beautiful at the beginning of the call, which is that you can tie new ARR impact, right, from a customer trust perspective, right, in new markets, and which is a great statement.
The other side of it, which is, is there a way where you can show the return on investment on GRC, especially in terms of prevention of some of the impact? One is the upstream about getting new customers. The other one is how do you continue to retain customers but avoiding some of these attacks or whatever that can happen through better hygiene, eating your vegetables, so on and so forth. Bryan Culp (31:06.
828) Yeah, no, it's great. it sounds good when we talk about it. But I think in kind of real world scenario, it's very, very tough to quantify money saved by stopping something. It's kind of like when we hear about some attack was, you know what I mean?
Like there's so much that we're not hearing about that's getting stopped. Raj Krishnamurthy (31:13.156) Mm. Raj Krishnamurthy (31:23.
086) Got it. Yep. Bryan Culp (31:36.59) and we don't actually know how bad it would be.
People can do projections and things like that, but it's very, very tough. That's why you have a situation where so often, you know, there's a big breach and then all of a sudden all this ton of money gets thrown at security. Well, it's like, well, you know, that kind of fit within the risk before. Why wasn't there more money going there?
You know, you could argue it's your fiduciary responsibility as leaders to make that assessment. But oftentimes, there's trade-offs that they're needing to make at their level. And so oftentimes you don't get that investment until something bad does happen. And people don't get enough credit for the badness that they stopped every day.
Raj Krishnamurthy (32:20.56) Got it. Got it. Now, in your role, how much do you have to understand the SEC materiality rules and work with other teams on SEC materiality and things like that?
I mean, my point is that you have a point of view on the recent Bryan Culp (32:35.182) Um, not really. So, so we have a different group within legal that, that works on the reporting of documents. Um, I think one, one area from a customer trust perspective where that does come up is, you know, there are certain reporting obligations and so about different areas.
so sometimes when we get questions, the way to talk about it, is to go back to the publicly reported information. But I would say on a regular basis, that's not really something I'm directly involved in. Raj Krishnamurthy (33:14.992) Got it, got it.
When we spoke last time, Bryan, and I think you sort of articulated this beautifully. I think you see automation as a key towards GRC transformation. And one of the things that you said, if I remember right, you said the big banks, the real-time internal success metrics are becoming very common. Do you remember that?
Bryan Culp (33:33.708) No, no, I know exactly which part you're talking about. Yeah. Yeah.
Do want me to go there? Cause I was thinking about mentioning that before, but yeah, I appreciate you bringing that in. Yeah. So for everyone out there, what Raj and I were talking about before, especially as we look to the future and kind of the intersection of GRC transformation and customer success, what I was mentioning, and this goes back to the idea of the large financial services companies being kind of a canary in the coal mine.
Raj Krishnamurthy (33:36.034) Okay, can you? Yep, absolutely. Bryan Culp (34:03.
63) What I'm talking about is we are increasingly seeing large banks and globally, and you know who they are, but I'm not going there. They are asking for more what we would refer to as internal metrics, and they're wanting to see them more kind of like real-time sorts of metrics. And so we all have heard the messaging about how certs, or a quote unquote snapshot in time and like, wouldn't it be so great if we could have the equivalent of that in real time? you know, intuitively, logically all makes sense, but there's a lot of work, lot of, you know, devil in the details kind of work that needs to get done.
And so what I was speculating on, and this goes back to the whole two to three years timeframe, what I was speculating on is that for significantly larger customers, I don't necessarily, in the beginning certainly, I don't see this being broad. I can envision a world that for very, very select metrics, we essentially, and I'm gonna talk, this is just across the industry, any particular company that I'm at or was at or whatever, I'm just speaking for myself. I can envision a world where we have that tie in to the environment, particularly when we're talking about the production environment, which is what I think customers would really be more focused on because that's where their data and content is.
I can see that happening. And the other point that I was sharing with Raj is, if you say in the beginning for certain really, really large SaaS players, that's happening with maybe five financial services companies, and let's just say we're focusing on five metrics, right? That becomes like a pilot to see if it actually works. And then if it does work and the access control and the security and kind of what would be reacting, what wouldn't and legal is okay, all that kind of devil in the detail stuff gets worked through, then it becomes a lot less troublesome.
Bryan Culp (36:29.474) to add more metrics or to add more customers. And then over time, this could expand. And then the other point that we talked about just a little bit, but not as much, is the difference between having vendors trying to facilitate to help this happen versus having the companies do it themselves.
What is... You know, like as a company really gonna have an appetite for a vendor going in there. Is it scalable for it to do that? You know, there's all kinds of questions.
So again, the theme, the theme I'm starting to notice here is we're teeing up a lot of the kind of, you know, gnarly challenges that we're working through as an industry and don't necessarily like have super clear answers for it. But yeah, I think it's interesting to have your viewers be aware of this as a potential. to see if it's something that they agree with, can help make happen, or if it's just kind of in our imagination. Raj Krishnamurthy (37:33.
316) No, that's a brilliant way to put it, Bryan. I just want to do a shout out for, so CSA Cloud Security Alliance had this work group called Continuous Assurance Metrics, CAM. In fact, this was two years ago. I was one of the co-authors for the first set of metrics that we put out together.
There were like 32 metrics. These are all focused on cybersecurity metrics, right? But I think what you said is beautiful in the sense that Bryan Culp (37:53.003) Okay.
Raj Krishnamurthy (38:00.675) I think if we as a community can agree on some standard metrics, the finance teams, when you look at balance sheets and things like that, you have a set of metrics, you have the return on net assets, you have all these different metrics that we can all agree on. And if we can do something very similar for cybersecurity, I think it at least establishes a baseline by which we can transact with each other. Bryan Culp (38:22.
382) Yeah, no, so I definitely agree. I don't think anybody's gonna conceptually agree with that. But the point that I've just gotta jump in real quick to add is we've been down this path so many times. how many times we have conversations with people when we hear this cliche story, right?
Like we've got 17 different standards. And so we need to have one standard. And so somebody comes out with the 18th standard. And so that's why, mean, like I've got a lot of respect.
Raj Krishnamurthy (38:44.649) Ha ha ha ha ha ha Bryan Culp (38:51.566) for those company, especially startups that are, you know what, we're not gonna go down the path of like doing another essentially bespoke standard and saying that it's all better. And that's why I've got the hope in AI to help to be somewhat of this kind of universal translator between the different standards.
And especially if it's quote, know, gen AI predictive to. Raj Krishnamurthy (39:14.095) Beautiful, isn't it? Bryan Culp (39:19.
892) essentially write in the answers based on a corpus of knowledge. To me, that's because it's just sort of human nature. Everybody wants to like apply order to chaos and come up with a standard and help make things work better. And like that's just kind of wired in us.
But as a result, we just have so many different standards. Raj Krishnamurthy (39:43.93) No, 100%. I think you said something beautiful.
what you're saying, what I hear you say is that in some ways, the day and time that we are living in, especially the maturity of the existing, the large learning and thinking models, if we can present the right data and if we can present the right knowledge corpus, you can abstract a lot more dynamically to what you want, meaning everybody can write their own story based on the data. Bryan Culp (40:08.334) 100 % I mean and just to kind of riff off that tying back to customer trust and I know you didn't ask this directly, but I just gotta go there.
I mean ultimately as we talk about the direction and evolution of the function of customer trust, right? We talked in the beginning about question and answer repository. OK, so I'm seeing us move more towards a world where. We have knowledge papers, we have narratives, we have a bunch of, probably the questions and answers as well, but you have this, as you refer to it, corpus of knowledge.
And so the customer trust team is really more focused on the nurturing and development of that content, working with the SMEs cross-functionally that we talked about before. And then AI goes in and gets those answers when we're talking about question and answer. So then that's one part of the team. Then the other part for that human interaction, conversation, meeting, I don't necessarily see that going away.
I think a lot of customers that are paying larger money will still want to have that. And so we'll really have both sides of it, where on one side things are way, way more automated and fast, almost kind of getting to the point of machines, talking to machines, and customer trust nurtures and develops the content. but then the customer trust people, they have to maintain that level of knowledge and ability to communicate it because I don't see the conversations with the customers going away, right?
Raj Krishnamurthy (41:46.511) Absolutely, brilliantly said, brilliantly said. And Bryan, you actually had published a post recently, I'm trying to scroll up and look up as well, where you had talked about three ways that your box is a phenomenal technology company, you're also an AI first company in many ways, right? And how do you use that within customer trust?
It looks like you do some of the tools within box in your function. Bryan Culp (42:09.678) You are so cool. just appreciate the call out there for the team.
yeah, so happy to shamelessly brag and promote the Trust team. And so yeah, in September I did a blog. I don't necessarily recall the name of it, but essentially it was talking about how the Trust team. has been using BoxAI and other Box products internally.
And so one example that probably gets the most headlines is the third party risk team sent up in AI-agentic workflow, because we all know that there's a whole bunch of assurance docs that come in. And so as opposed to having a human look through all of that, AI-agentic workflow is essentially just, you know, a series of detailed prompts that also include what we want the output to look like. And so you can imagine we got a bunch of these docs, just run it, we get a report on that vendor, right?
And so what was very, very fascinating, and I will do a plug for somebody, you know, that Barbara then called out on the team, because I asked her, like, okay, well, how much time is this really saving you? you know, because everybody wants to hear how we're saving time. And she said, it's saving time to get where, where she's at. But what she's then doing is she's finding that she's having the time to go deeper.
And so to me, ultimately, like, like, that's the promise of AI, right? Like, I think it's fairly short-sighted business leaders out there who are using AI to like cut costs to Raj Krishnamurthy (43:46.831) Yes. Bryan Culp (44:02.
722) to juice the next quarterly earnings report. More power to them, I hope the stock goes up a little bit, fine. But ultimately I see this as a long-term play. And what it's really about is how do you do stuff faster so you can have your people work on more value-added areas to get more innovation, to come out with better stuff, to be able to get more market share, et cetera, et cetera.
Because this is really, in my view, like a grow and expand time, you know, and like, I don't see this as the place where you're kind of like, try to cut here and try to cut there. It's more, how do you figure out the right place to invest and really go there? And so, yeah, the third-party risk team has been quite, quite happy with this. And in fact, I'll even say that, yeah, we had a little bit of attrition and it's really helped them kind of stay alive as we've looked to fill that.
Raj Krishnamurthy (44:59.705) Do you expect to convert that into a product or open source it or do something? Bryan Culp (45:07.534) Not me necessarily, but what is cool.
So for that, then also the policy team used Box AI and apps and metadata. So previously the policy team, like probably so many of us, was essentially tracking all of our policies in Excel. When's it come up for renewal? Who owns it?
Who's the approver? Et cetera, et cetera. So very, hard to keep up to date. And so now we have it set up within Box to basically have a living document based on metadata from the policies.
So we just can see that. And if we want to see what ones need to be reviewed that quarter, just put in Q4 and it shows. If we want to know. you know, what policies are for security, just put in security and it shows us, you know, if a particular senior leader is a signer, which policies and it shows us.
So the reason I bring that up is because marketing team and sales team and the SEs have been talking to the policy team about how to represent that in conversations with customers, basically to show customers how they can do that themselves. because of course, probably everybody that I'm talking to right now, their company or agency has like tons of policies, right? And so I wouldn't say that we are directly, directly involved in creating it as a quote product, but more in telling the story of how this technology could be used for people to do this themselves in house.
And it's just kind of pretty straightforward. Raj Krishnamurthy (46:57.23) Absolutely. I think what is beautiful about this is that no longer are these policies some files sitting on a shelf in a PDF files that are static and stale, but they are living breathing things that people can interact touch and feel.
Bryan Culp (47:12.526) They absolutely can. At the same time, to be fair, from policy perspective, I would love to have it more actionable and in front. I think in policies in general, there's still lot more progress that we can make, but definitely agree with how you describe it.
Raj Krishnamurthy (47:33.934) Where do you think GRC teams should sit? Bryan Culp (47:39.162) I love the segue there.
Where should I say it? So if you take the kind of classic textbook, you'll often see them sitting in security in the CISO org. This is particularly true because I think the reality, you pull back the cover, a lot of times when we're saying GRC, what we really mean is security GRC or technology GRC. My view, and this is probably more aspirational than anything, is that when we talk about GRC governance, risk and compliance, absolutely security is a huge part of that.
every one of like governance, compliance, risk, when we break down those words, they all are applicable across the enterprise, right? Like compliance is way, way bigger than just security. Literally there is such a thing called. enterprise security.
So when we talk about the importance for GRC of risk being an output, right, to have it called enterprise risk, you know, by definition that goes across the whole enterprise. But if GRC is only focused on security, it's kind of difficult to make that leap. I've also seen it sit in legal and it works. Sometimes a lot of it depends on the people and the personalities involved there in their kind of experience.
But in my view, as long as, so like, if GRC is in legal, it's gonna have to have a close relationship with security. If GRC is in security, it's gonna have to have a close relationship, you know, with both ways, right? And you just really don't usually see GRC as its complete standalone organization. So.
I know I kind of punted a little bit on that question, but I can see it being successful in both, and there's a lot of kind of other factors for making that decision. Raj Krishnamurthy (49:47.395) How technical do the customer trust and GRC teams need to be? Bryan Culp (49:52.
654) Technical, for sure. I mean, there's a lot of variability in that word technical. Technical means a lot of different things to a lot of different people. So I think sometimes when we use words, we need to kind of like step back and be, you know, like call out what we're actually talking about.
So I think it's important for customer, certainly for customer trust to have a very, very broad view, but it doesn't need to go incredibly, incredibly deep, right? And so, you know, like take encryption, like we can go to a certain level talking about encryption, key rotation, you know, all that sort of stuff. If somebody really, really wants to go deep and talk about entropy and all of this stuff, you know what I mean? you know what I mean?
Like that's why we have SMEs. And if somebody really wants to have that conversation with them, they're probably going to be super excited to have it. But on the other hand, if it's just the straight up stuff about encryption, a different type of encryption and who holds the keys and how that's protected and how often they're rotated, et cetera. you know, those should be things that a customer trust team should be able to handle.
In terms of the other aspect of this, and I think a lot of what we're hearing across the industry, when it's kind of in vogue right now to say GRC needs to be technical, I think it's very, what is important is to be able to speak the language of your audience. And so when we're talking about talk, you know, working with GRC, excuse me, with engineering, and especially in terms of quote GRC engineering. So much of that is knowing the business and technical drivers of your audience and also the language that they speak in.
At the same time, I think it's sort of like a fundamental thing that we've been told since we were kids, right? Like know your audience, right? So if you're go up and talk to somebody, Bryan Culp (52:11.328) Understand what they really care about and what's the best way to message it with them and do that, you know to me that doesn't necessarily mean something someone is super technical but you know, if you're talking with a technical person about a technical problem like You got to be able to follow the conversation.
You got to be able to come up with ideas Otherwise, you're not really adding value to the situation. So Yeah, I think they need to be they need to be technical but not not necessarily as much as like a domain expert in a particular niche area. You know what mean? Like, let's be realistic.
Raj Krishnamurthy (52:47.406) 100%. Now, I think the way that it is commonly used is, and GRC is a very interesting place, right, because it's a layering of skills, and it is not one thing, right? It is about specialization of being generalist, right, which is that you need to understand security, you need to...
Bryan Culp (53:04.366) We gotta pause for that moment. The specialization of being a generalist. I just wanna call attention to that.
Like, what a sentence. Raj Krishnamurthy (53:14.758) But so you have to understand the compliance regimes. You have to understand the security infrastructure.
You have to understand to a reasonable extent the cloud infrastructure and so on and so forth. But I think what I hear most common when people say technical and GRC engineering, what they are basically saying is, should they code? Do they code? And the reason that they make that argument is primarily because that allows the GRC teams to be self-sufficient, right?
That can integrate with different sources, pull data, automate, and they are not dependent on other teams for automation. That's the usual thing that I hear. Bryan Culp (53:52.514) Yeah, well, and again, this goes back to this whole vision of the next two to three years, right?
And so what I think many of us are seeing is that if GRC is building its own automation and essentially customizing, you know, at least it did require certain elements of coding. Now, to what extent you can get away with not actually coding because of other technology that exists, and then you have the whole conversation about, but of course, you're better able to use AI to code if you actually understand coding, et cetera, et cetera. So my take on this is I'm not gonna sit here and say, if you have a GRC group in order to get into GRC, if you're starting out that you need to code.
Now at the same time, If you are starting out, it's gonna be a huge plus because probably a lot of people in GRC won't be able to and the future of GRC is in that automation. But, you know, like if you have a team of 10 people, it would be great to have at least one that's able to do that. You have 15, you have 20, maybe you have two or three, right? On the other hand, if you're only able to have two or three people, and everything needs to be automated whatsoever, maybe almost you wanna have like half the people being able to do it, right?
If it's a really small group, because so much of it is based on that automation. It's just, like if I had a choice, do I have somebody who really understands the controls and understands them well enough? to have a sense of knowing about compensating controls and why they really matter and et cetera, et cetera, right? Like I'm still going to prefer that as foundational rather than, this person can code, let's just plug them in.
Now, ideally you kind of have both and they grow together and learn each side, but yeah. Raj Krishnamurthy (55:59.747) God bless. Makes sense.
You manage third party risk management, Bryan, and when you hear statements like, get SOC 2 within 48 hours, 96 hours, and I don't know if you've ever seen this, and maybe I'm exaggerating it, but the point is, has commoditizing the idea of SOC 2. What is your take? Is it good, is it bad? Bryan Culp (56:27.
182) it makes me very, uncomfortable, right? It's kind of like, almost like you're driving down the road and there's a car wash and people are saying, come on in for 10 99 and there's a price for it. So yeah, definitely I'm uncomfortable. I think that that's, that's kind of a natural response, especially, for those of us who have been doing this stuff for awhile.
you know, At the same time, I do have an appreciation for this sense of better something than nothing. And if that, what it really comes down to is what's the value and what's the quality, right? And so it's kind of like anyone innovating and coming out with a lower priced offering, oftentimes, like manufacturing is easy example, right? You come out with something low cost, maybe it's not necessarily as good and everybody seems how it's flimsy, but it's low cost and then all of a sudden you get more and more volume and by getting more and more volume, you reduce your costs, you're able to innovate and the next thing you know, you're moving up the stack, right?
And so like that having cars are an easy example of seeing how that has happened over the decades, right? So I think that's to be seen. think when we talk about like the next two to three years and how are things going to play out and there's different models that are competing with each other, I think that's part of it. What I would say, especially to anybody out there involved with the buying decision, you know, insist on having meaningful certifications.
because like if it's just gonna be a rubber stamp and that gets the market access, then people behind the money are gonna go with that, or at least enough of them will go with that, right? But on the other hand, if it's not the quality or using the car example, if it's a car that actually doesn't work, like even though it's inexpensive, why are people still buying it? And so I think it's... Bryan Culp (58:46.
958) it's something that we need to do as an industry is to insist on having quality certifications that are actually meaningful, not just a piece of paper so that procurement can sign off on something. Because if we don't, then that whole kind of, and I know you're exaggerating slightly, but like, know, 24 hour, 1099 sock, you know what I mean? Like, it will win if that... helps that company close deals, right?
Raj Krishnamurthy (59:19.501) No, very well said. We are approaching the end of the segment, Bryan, and you rose through the unusual rank from journalists. So what advice would you have to anybody who's listening to the show who is in the non-usual aspects of cybersecurity and who wants to come up with the cybersecurity ranks or the customer trust ranks?
What advice would you give? Bryan Culp (59:46.35) So first of all, differentiate a little bit between security and GRC. There's definitely cross-pollination.
I've seen lots of people be successful going back and forth between them and understanding both. I think if you're looking at things from a GRC perspective, you've just got to have that foundation around controls. We talked earlier about SIG, Cake, Heckvat. You know, if you're working at a company most likely that company has a sock to if you're able to get a hold of it actually read the whole thing.
They're very, long, especially the like appendix stuff that goes into all the controls, you know, get get a sense of what that is. Talk to the people in your company that are involved with that. If they've recorded the walkthroughs, ask if you can watch them. You know, there's just a ton of ton of content online.
There's podcasts. I mean, like I'm happy to plug your podcast and Compliance Cow. Lots of good speakers that will talk about various things. Obviously there's a bunch of other podcasts out there as well.
There's influencers on LinkedIn. So it's almost kind of like there's too much information. And so, you know, get your head around it, get comfortable with it. And the other thing is, if you're not already, go all in on AI.
So if you're just starting out in your career, my hunch is you probably already are all in on AI. And once you start working, you'll probably be able to teach people how they can use it. And you can kind of use that as leverage to understand more about the business processes and the content. And I think that that's a very, very successful model.
Looking at things from The security side, the classic, so I did not necessarily do this, but the classic path there is a sock and being an investigator and kind of like hands on, so many people that I've talked to, they put in their time, hands on keyboards, essentially getting alerts and doing investigation and put in their time. And it kind of seems like a lot of people pay their dues that way. Bryan Culp ( ) And then since you brought it up, I'm just gonna go for it and say that if you're looking at something from the GRC perspective, the more you can learn about security, the better you're gonna be.
And I would even suggest that if you're on that security side, the more that you can understand things from the GRC, because not everybody does that. And so to be able to have that more holistic perspective will help you to connect dots. And then as you communicate about that, you should have... more and more opportunities.
Raj Krishnamurthy ( ) brilliantly said. I want to give you the last 60 seconds for any closing statement, whatever you want. Bryan Culp ( ) Just whatever I Raj, this has been a blast. yeah, a lot of stamina.
I don't know how you do it. So hats off to you and to your company. I really, really appreciate it. The chance to kind of speak with you as well as across the industry.
If I were to kind of step back, top of mind, some of the themes that came up to me just right now. Definitely focus on controls and those understanding of controls. I would also say that in a certain way, everybody's in customer trust because everybody wants to establish the relationship. It's almost cliche to say everyone's in security, everyone's in privacy.
It's all true. I also think everybody is in customer trust. And then going back to kind of how we started from the beginning, this notion of how things are going to evolve in the next. two to three years, we all have the chance to drive that change.
It's not like this is happening to us. At the same time, what I would leave everybody with is if we as individuals and our companies or government agency, whatever, if we're not directly involved in driving that change, that change is going to happen to us. It may not be absolutely exactly two years or three years or whatever, but like, We are on our way right now. And I personally don't want to wake up and go like, wow, the whole world's changed around me.
I would much, much rather be a participant in helping to drive that change with many others, giving my input based on whatever I know and experiences. And I just think that we all kind of are in that boat. And so if you're not already doing that, I would just invite you to do that because your perspective, your experience matters. and we can kind of work together to create that future.
Raj Krishnamurthy ( ) think with that brilliant call for action, Bryan, it was a blast having you on the call. Best wishes to everything that you do. Thank you very much. Bryan Culp ( ) Thank you so much.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.