What you'll learn
Why Matt Hillary isn't sold on "Chief Trust Officer" as a title but is convinced the function is real — every objective his security and GRC teams write traces back to building and keeping trust, and the CISO is the one standing in front of customers answering for it.
How an executive mandate of "zero exceptions on all audit reports" drives one of two behaviors — people hiding failures, or a massive automation build-out — and why the second path leads to continuous assurance and the end of screenshot sampling.
What being a CISO at a security company actually costs: Matt calls it "3x the role," and he walks through the burnout that had him asking his wife whether he should quit, plus the specific guardrails he built afterward.
Description
Matt Hillary is the CISO at Drata, his fourth turn in the seat after Instructure, Weave (where the company was public), and Workfront, with earlier program-building work at AWS, Adobe, and Lumio and audit years at Ernst & Young. At Drata he also owns IT, business applications, and AI enablement — plus the field-facing work, customer calls, and customer-zero product influence that come with running security at a security company. Matt has been making the argument for a while that the CISO role is drifting toward Chief Trust Officer, and this conversation puts that claim under pressure: is it a real change in what the job is, or a new label on the same deck of cards?
Matt's answer is more useful than a yes or no. He doesn't think the title sticks, because trust is built by the whole company — product, customer experience, executives — and security is one stone in that foundation. But the function is real: in B2B SaaS, and especially security B2B SaaS, customer trust questions land on the CISO's desk, and every objective on the security and GRC roadmap only makes sense as an answer to "why?" From there the conversation runs through the AI governance problem (a McKinsey study Conor cites found 59% of organizations name it as the principal blocker to AI adoption), ungoverned internal agents Matt compares to Forky from Toy Story 4, the shift from audit sampling to continuous assurance, and the GRC-engineer career path. It closes with the most candid burnout discussion this show has had. If you run a security program, work in GRC, or answer to customers for what your company does — this one's for you.
What we cover
"trust is built in drips and lost in buckets" — why the stakes are higher for a security-company CISO, and what Matt learned watching breached security vendors respond in public.
"if I call you three times in a row, it means, dude, something's wrong" — the incident call order: Chief Legal Officer first, CEO second, a trusted peer CISO third.
"Hey, so we have these little Forkys running amok with our organization" — the discovery problem with internally built AI agents cobbled together from vibe-coded parts.
"you know what kind of behavior that drives? One of two things" — how a zero-exceptions audit mandate either breeds hiding or forces the automation that becomes continuous assurance.
"we are now technologist on the GRC team, not just auditors" — the GRC engineering mindset shift, and why "day one integrate, day four audit" skips the homework.
"I can take this component of my brain and wholesale offload it on you and generally trust that you're going to do 80 to 90% of what we expect" — why agents don't earn the trust a seasoned hire does, and the checks you have to architect in.
"the creative art of being a CISO is truly applying what matters for that particular company at that particular time" — the blank-canvas approach versus running the same playbook everywhere.
"Should I just quit? This is way too much on a human right now." — burnout, boundaries, therapy, meditation, and EDM festivals as recovery infrastructure.
Thank you to our Sponsors:
RISC Point is security & compliance consulting tailored to your business. Talk to RISC Point.
Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North.
Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending.
The conversation
Every objective on the roadmap answers the same question
Matt opens with a story from annual planning. The security team wants to burn down criticals and highs, get detection and response fully capable, put AI on all of it. The GRC team wants zero audit exceptions and another framework. Matt asks each of them: why? His directors find the question strange coming from a security practitioner. He keeps asking anyway, because the honest answer underneath every one of those objectives is the same.
"It ultimately comes down to building and maintaining the trust of others, whether that be internal or external."
— Matt Hillary
That's the core of the Chief Trust Officer argument — and also its limit. Matt isn't convinced the title takes over, because the CISO can't manufacture trust alone. Customers trust a company because the product delivers, the customer experience team takes care of them, and the executives hold values consistently over time. Security is necessary, not sufficient.
"We're just one just material foundation stone in that whole story."
— Matt Hillary
Stuart pushes on whether this is exaggerated by where Matt sits — a security company selling to security people. Matt concedes it: at a door-to-door solar company, nobody was asking him these questions. But he's watched security vendors get breached, and he quotes a line from one of their executives that stuck with him — "trust is built in drips and lost in buckets." The stakes at a security company are higher, and the pressure compounds daily. What he took from watching those companies wasn't fear. It was how they responded: openly, with bias toward "this is what we learned, hopefully you can learn from us."
CLO first, CEO second, peer CISO third
There's a practical thread here about incident response that's worth pulling out. Conor tells the story of a CEO who insisted on being the first call in a breach, and Conor telling him no — the Chief Legal Officer is the first call, the CEO is the second. Matt agrees completely, describing the CISO-CLO relationship as an unofficial marriage: "if I call you three times in a row, it means, dude, something's wrong."
Matt adds a third call to the list — a peer CISO you trust, someone you can lay it all out for and just ask, "What can I do?" He credits the CISO community's integrity for making that possible. The thread ends with Conor's story of working a breach on his tenth wedding anniversary — a subsidiary popped before acquisition, the threat actor sitting on the data for three years, then detonating it on his holiday weekend. The incident cost him a dinner reservation and the next three months of his life. The therapy bill, Matt suggests, should be a line item in breach recovery costs.
The Forky problem: agents nobody discovered, governed, or trusts
Conor brings the McKinsey number — 59% of surveyed organizations name AI governance as the principal reason they're struggling to bring AI into the enterprise — and offers his frame for what trust in these systems actually decomposes into: security (show me I'm free of an adversary), safety (does the system work within its boundaries), and reliability (does it work under adverse conditions). Matt takes the frame and runs with it, because the problem he sees inside his own company is more basic than any of those three: discoverability. Teams across product, go-to-market, IT, and security are building agents, and some of them are cobbled together in ways that remind him of Forky from Toy Story 4 — the craft-project toy made of a fork, pipe cleaners, and googly eyes that walks around announcing "Hi, I'm trash."
"We have these little Forkys running amok with our organization."
— Matt Hillary
The governance question that follows is about human attention, not just controls. Matt reaches back to Little Snitch, the Mac network monitor that asks permission for every connection until, around the hundredth yes, you stop caring and approve everything. Agent governance has the same failure mode: approve everything and you've trained yourself into rubber-stamping.
"We're just like YOLO, full send, just like do whatever you want to. Obviously, we got to be careful and put some guardrails around it."
— Matt Hillary
His answer on architecture is blunt: agents need checks you would never put on a human. Hire a GRC professional with ten years in the field and you can offload a component of your brain and trust they'll deliver 80 to 90% of what you expect. An agent gives you no such warrant — "Foundational model just got cut. Wow, this foundational model decides to just break out and start hacking these other companies." So the checks either get trained into the model or built around it — what Matt calls "AI agent in the loop on steroids." The unsolved part is the one he keeps circling: "how do you actually measure good judgment? I think that's what we're struggling." Stuart's rejoinder — that's the struggle with humans too — lands, but doesn't make the problem smaller.
Zero exceptions is a behavior problem, and continuous assurance is what it forced
Matt worked at a large organization where a C-level annual objective was zero exceptions across every report — SOC 2, ISO, major and minor non-conformities, all of it. He's direct about what that mandate produces.
"You know what kind of behavior that drives? One of two things. One, like people are going to hide this stuff and really like not fix it, or like, hey, it's going to drive some unethical kind of behaviors."
— Matt Hillary
The second path is the honest one: build enough automation to monitor every instance of a control operating, so that when it fails you can catch it and recover. That's the origin story of continuous assurance as Matt tells it — driven partly by executive mandates, partly by nobody wanting to spend their life taking screen prints of 25 randomly sampled items. He was at Ernst & Young when the AICPA's standard was the answer to its own question: "What does reasonable assurance mean? It means reasonable assurance."
Continuous assurance created its own problem, though. Monitor everything and "'brrr' goes the money gun of findings of control failures" — the GRC operations team wakes up to a hundred failures a night thrown over the fence. That's the gap Drata's newly released AI agent governance platform is aimed at: agents that discover other agents, map where they sit in critical flows, monitor them, and help remediate control failures — with the whole loop logged so an auditor can look at what the agent found, what actions it took, and trust the outcome. Whether the industry finally kills sampling, Matt won't promise. But he wants it dead as much as Conor does — and he wants grace built in for the times a control legitimately fails.
The GRC career path is engineering now
Asked where GRC careers go from here, Matt doesn't hedge: the builder side. The mindset shift he demands from his own team is total — "I'm no longer an auditor. I'm no longer a GRC person" — no more spreadsheets, screen prints, and sample selections thrown over the fence. The new work is APIs, connectors, and evidence pipelines.
"It's required that mind shift change where we are now technologist on the GRC team, not just auditors."
— Matt Hillary
But the tooling isn't the hard part — intentionality is. Matt sees teams adopt a platform and sprint: day one integrate, day two findings, day three fixes, day four audit. What they skip is stepping back to ask what a control even is — in his words, "a control is a point in the process that helps mitigate a what-could-go-wrong or a risk that we can stop that from happening." Some teams are auditor-fearing and set their goalposts at whatever the auditor grades. Some are risk-fearing and try to prioritize everything. Neither has asked what the goal actually is.
Conor connects this to Aayush Fadia's line from a prior episode — if your GRC program can't surface a novel insight to your CISO, it has failed its purpose — and to Andy Ellis's How to CISO material on risk: "Ask the question, what is an unacceptable risk?" An airline pilot has a clean answer — don't lose a soul; the plane is negotiable. Most companies haven't done that work, and Matt has watched the language gap firsthand: security, legal, and finance speak risk natively, but put a CEO or CRO in the room and the response is "Wait, wait, risk, what do you mean?" Their risk is missing the quarter. Starting from unacceptable loss is how you get both sides into the same conversation — and Matt's CFO anecdote ("I'm not okay with losing $10,000") shows how far apart the thresholds can be.
3x the role — and what it did to him
On the difference between being a CISO at a security company versus anywhere else, Matt gives two principles first. One: treat every company as a blank canvas. The common threads exist — every company needs MDM, endpoint protection, a CSPM — but running a checklist playbook produces worse results than doing the creative work of figuring out what matters for this company at this time. He extends the metaphor to inheriting a predecessor's program: it's cover-up tattoo work, and he never speaks ill of the prior leader — "You're going to find shit that I missed, and I'm going to feel so bad, and please, please be nice." Two: relationship building isn't optional. Thirty minutes learning where someone's from pays off when things get hairy, because "we're going to be in the funk together here."
Then the security-company part. At Drata he runs security, GRC, IT, AI enablement, and business applications — then adds the podcasts, webinars, and stage talks, the customer calls where buyers want to hear it from the CISO directly, and the customer-zero mandate to influence product strategy. "It's like 3x the role." His biggest fear in life is being bored, and this has been the most action-packed three and a half years of his career. It also broke him.
"I woke up right before Black Hat, turned over to my wife, and I was like, 'Should I just quit? This is way too much on a human right now.'"
— Matt Hillary
What he built afterward is specific: daily meditation with the Waking Up app, real therapy for the panic that hits thirty seconds before every stage walk, and boundaries — a lifelong people pleaser learning to demand an ROI on every event and cap travel so he can still be a dad to four kids. His outlet is EDM festivals, where the lasers and sound somehow put him in his most peaceful state. And he shares the line from an HR colleague that reframed everything while Matt was sobbing on a Zoom call: "Matt, it's just a fucking job." He tells the story because the mental health cost of this role is massive and mostly unspoken — and as Conor admits on the recording, it turns out a whole lot of us are in the same boat.
Show notes
Guests — Matt Hillary, CISO at Drata; fourth-time CISO (previously Instructure, Weave, and Workfront); built security programs at AWS, Adobe, and Lumio; former Ernst & Young auditor; also runs IT, business applications, and AI enablement at Drata.
Books mentioned — None named in the conversation.
Frameworks / models / tools named — SOC 2; ISO; SOX; AICPA assessment criteria ("reasonable assurance"); Drata Control Framework; Drata's AI agent governance platform (released day of recording); Conor's security–safety–reliability trust frame; Little Snitch; Claude / Claude Code; ChatGPT; Grok; CyberBench; MDM, endpoint protection, and CSPM as baseline program components; Waking Up (Sam Harris meditation app).
Other people / shows / resources referenced — McKinsey AI adoption study (59% cite AI governance as the principal adoption blocker); Aayush Fadia (prior Zero Signal guest, GRC engineering); Andy Ellis and his How to CISO series; Mark Manson's podcast; Sam Harris; CrowdStrike's incident response as a PR case study; Benjamin Franklin ("an ounce of prevention is worth a pound of cure"); Toy Story 4 (Forky); Idiocracy; Ernst & Young.
Hosted by Conor Sherman and Stuart Mitchell.