SourceForge Podcast
The SourceForge Podcast is the world's largest B2B software podcast published to over 1.5 million subscribers across all major social media and podcast platforms, and to over 667,000 subscribers on YouTube. Interviews with tech and software CEOs, leaders, and changemakers. The SourceForge Podcast by Slashdot Media gives you insight into the cutting edge of software, B2B SaaS, and trailblazing technology.
SourceForge Podcast
Compliance Automation & Risk Management Software: Carbide
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Carbide combines compliance automation with credentialed security advisors who guide companies from gap assessment through audit and ongoing readiness. Its unified platform streamlines evidence collection, control mapping, remediation, and multi-framework compliance, helping teams get audit-ready faster with fewer surprises.
In this episode we explore treating trust as a leadership system, not just a branding message. We speak with Darren Gallop, founder and CEO of Carbide Secure and author of Built to Trust, about how cybersecurity, data privacy, and AI governance are now core business responsibilities.
The main idea is that trust has to be built intentionally from the top down. Darren argues that boards and executives often make the mistake of pushing security and privacy into IT or legal, when in reality leadership sets the priorities, budget, and culture that determine whether trust actually exists.
A big theme is the speed of AI change. Darren explains how agentic AI, generative AI, and new automation tools are evolving faster than governance and regulation can keep up. That creates pressure for companies to move quickly, but also raises the risk of data breaches, misuse, and bad decisions made under duress. They also dig into the difference between compliance and real governance. Darren says compliance checklists like SOC 2 or ISO can help, but they do not automatically mean an organization is secure or trustworthy. In some cases, compliance becomes bureaucracy that distracts teams from real risk reduction.
Follow SourceForge:
SourceForge.net - https://sourceforge.net
SourceForge LinkedIn
SourceForge X (Twitter)
SourceForge Facebook
Interested in appearing on the SourceForge Podcast? Contact us here.
The SourceForge Podcast is the world's largest B2B software podcast.
Hello, everyone, and welcome to the SourceForge podcast. I'm your host, Bo Hamilton. Today we'll be talking about trust and not as a brand value or a marketing slogan, but as a leadership discipline. I'm joined by Darren Gallup, a man of many titles. He's founder and CEO of Carbide Secure. He serves as a board director, he's a thought leader, and he's also author of an upcoming book called Built to Trust. Darren's career spans music, tech startups, and cybersecurity, including building and exiting a global event technology company before turning his focus to helping organizations navigate cybersecurity, data privacy, and AI governance, all of which are extremely important areas with the rise of AI and autonomous agents. Now, much of today's conversation will focus on his new book, Built to Trust, where Darren argues that trust is an operating system for leadership. In a world where trust is harder to earn and easier to lose than ever before, Built to Trust makes the case that protecting data, anticipating AI risks, and embedding ethics into design aren't just IT concerns, they're core to how modern organizations build value, attract talent, win deals, and stand out in crowded markets. That's the synopsis. I think it's a powerful uh message, and I'm excited to unpack it some more in today's episode. So with that said, Darren, welcome to the podcast. Glad you could join us. Thanks for having me. Glad to be here. Of course. Now, um, Darren, I think your book is arriving uh on the scene at a very important time for the tech industry and and the business world um in general. As it seems that, you know, really good uh quality ethics are, I would say, increasingly more sort of difficult to come by, especially as it pertains to the operational side of businesses. Um you make this argument that trust is an operating system for leadership and you know, not some brand value or or slogan. What problem were you seeing repeatedly that made you sort of realize this framing was missing from how leaders think about the topics of security and privacy and AI?
SPEAKER_01Yeah, one of the things that I see often, and I think we all see it, and you said the the word branding or marketing slogan, it's very easy to say things. And marketing departments generally love to find really fancy wording or great slogans that that help facilitate people wanting to trust your brand and buy your product. But as we all know, um, just because a website or a slogan or or some marketing material says that we are ethical and that we are trustworthy and that we are doing all of the best things with the best interest of our customers in mind, that isn't always the case. And so I think traditionally, this concept of trust, it's it's not new. It's been around for thousands of years and certainly hundreds of years in a business context. Fast forward to now, the elements of how technology plays into this, cybersecurity is relatively new, certainly for small to medium-sized businesses. If you go back 15 years ago, what what were small to medium-sized businesses actually doing regarding cybersecurity, not very much. And and same with data privacy. Data privacy or privacy in general is a very old concept. It dates back hundreds and hundreds of years ago. But in terms of how that looks today and how that transpires today through the use of technology and just how much of everything's online and just how much data is being captured by corporations about individuals, it's a very different world. And now we have AI dropped into it, which just increases the velocity of innovation and it increases the way data can be used. So if I look at how most organizations think about cybersecurity in and data privacy and even AI governance, it often just is interpreted at leadership level as being a technical problem, right? So if you're a company selling to the government or you're selling to enterprise, and they send you some questions asking about your cybersecurity posture or your your data privacy compliance. Well, you're generally what most leaders do, and and this has been the case for a while and remains this case, is they think, okay, cybersecurity, that's technical. So I'll send that over to our CIO or CTO or IT folks. Um, if it's data privacy, they may think, oh, this is legal, right? Privacy is regulations, so we'll take it to the legal professionals. And don't get me wrong, there's very, very big role to be played in both cybersecurity and data privacy at the IT level of an organization as well as the legal level of the organization. But there's so much of that that's not just there. And so um the leadership plays the core role to determine what's important in an organization. And if you look at cybersecurity, in fact, most data breaches and most incidents that are of a cyber nature, there's some human element to it, right? It's either you have a CEO being uh being spearfished, or you have phishing emails, or you have somebody being tricked on a phone call or text or a variety of different levels. So there's lots that happens that's not purely technical. That's that falls more into uh you know really engineering thought and getting people to trust an email or trust a phone call or something like that. And then the other part of this as well is that it's it's also the decision of leadership, the board, the C-suite, the CEO of an organization to determine what they're willing to spend money on. So where you put cyber in that mixture is a real, it is very important to factor. And if you just think of it as like, hey, IT folks solve this problem, um, and but not giving them the right budget and not leading by example and not playing your part in understanding what leadership's role is, you're always gonna have a challenge. You're always gonna have a headbutting. And we see this in organizations. You like see these IT teams that are like, oh, this place would be so secure if it wasn't for all the people. And so that cultural element, that the way people behave, the way people treat data is critical. So those are big points of it for sure.
SPEAKER_00Yeah, I think uh I like how you you mentioned like this isn't a new concept, of course. Like this has been around for hundreds, thousands of years. It's really built in the idea of trust, it's really built into kind of what it is to to be humans and and our relationship with with other humans. And um, but I think the the issue is obviously we have this new technology, um, but also placing sometimes we lose you know the importance, the emphasis on on the importance of trust. Um and so it's like a pendulum that swings back and forth, and sometimes um you know it swings the opposite direction, and and business leaders um don't realize maybe the importance and don't value it as as as strong. They're kind of looking more kind of on the short-term side of things. Um and so that's why I really I I like your uh I think your book is really timely. I think we need to kind of move back to to placing a stronger emphasis on that and and from the leadership level, right? Um so I think what's neat with your with your book is you have this inside look, you have this experience of working with execs and and boards over the the span of your career. Um you've seen firsthand how leaders, you know, may say one thing and and sort of do another in regard to certain values around trust. Um I'm curious, um, based on you know your experience, where do you see that the biggest disconnect uh between how leaders talk about trust and how it actually gets sort of built or maybe lost inside organizations?
SPEAKER_01Yeah. And so one of them I mentioned is the the the disconnect of thinking that these are IT or or legal matters. Um and and thus that's a big disconnect that we see. But but it really it really depends on the organization. So when you sit, when you look at boards, say of like a startup, like a venture-backed startup board, although we are seeing some positive changes in in some of those boards, where where most of the emphasis generally ends up is you've got founders and you've got VCs on a board, and you may have an independent or a couple of independents. But generally the focus is in an earlier stage company is on the greatest risk. And so if you think about like, well, what does that usually look like in an earlier stage startup? It's usually that you're going to run out of money before you get to either whatever that next inflection point is, which could be um cash flow positive, but in most venture back companies, of course, it's the metrics required to raise that next round. So that survival becomes the predominant risk that is often addressed in the boardroom. And so the VCs on the board, well, it's their money. So they obviously don't want their money to, you know, they they they wrote a check for however many, many of millions of dollars based on a certain valuation. They're counting on you growing into that valuation. They know that to grow into that valuation, it's really about sales traction, customer retention, right? So that tip typically is the big driver. And of course, the the CEO or the the co the co-founders that may be on that board, they're feeling the pressure. They're in that pressure cooker of you raise the RAM, which is that honeymoon phase, crack the bottle of champagne. And then the next day it's like, oh God, we made a lot of big commitments on the slide deck and this pitch. And they're they're focused on that. So the challenge in those environments is it creates a pressure, and there always has been a culture of like move fast and break things. There's always been a culture of like look bigger than you were. And and that has been accepted. But in this day and age, you've got to be really careful because you can't be careless. And we've seen that we've seen a lot of cases where startups are very careless, where they, those pressures of survival and meeting customer commitments in terms of feature deadlines or the VC commitments in terms of hitting traction often force us to put products out there and put real data in those products and where the stakes are really high. And you have to be very careful with that. So that's that's one disconnect there. It's just the intensity of how risk is looked at in a in a venture-backed board, which is less quantitative or like less of a structured enterprise risk management and more of like a survival risk management element. Um, so that's one side. Now, going into larger organizations, we still see a lot of cases where you've got boards that don't actually understand the technology that is being used or don't necessarily have a really good understanding of the threat landscape. So they're there to provide in these more sophisticated, more established organizations. And often board members are often older individuals that have, you know, they maybe they were a CEO or they were a CFO or they they they had a past career and now they're they're they're offering their experience that they've had in their career to the to the companies in an oversight role. The challenge in a lot of this is though, if they don't understand the technology and they don't understand the threat, they're there to oversight oversee strategy. But without understanding, like strategy and risk is really a seesaw, right? The least risky thing to do is often to do nothing and just not even build your business or launch a new product, but that's not why businesses exist. So you're always taking risks all the time. You have to take risks, but you have to understand those risks. And so what's very common, and I see this a lot in more in more established boards, where you look at their risk register and they don't even understand the categories of threat that that could be existential to the business. So an example would be you could be a 20 or 30 or $100 million company. And if you had a catastrophic data breach in which it turns out you weren't even doing the due diligence and the common best practices, that's catastrophic. And if the organization is not ready to respond to that, that can have a massive effect on the business. And that that violates trust in a way that you can't just build that overnight. Uh, the same thing is when you're talking about artificial intelligence. A lot of organizations are sitting around having conversations at the boardroom about what are they going to do strategically. But if they don't understand, not necessarily the minutiae of the technology, like they don't have to be, you know, write in Python and build an agentic agents, but to understand what the effects of, what's the pace of AI, what is AI doing, what what are people using it for? What are they building? You might be sitting there having conversations without understanding that like all the different ways you're your business that you're you're you're sitting on the board of could actually be in a pr in the process of being blockbustered by some new innovation that either an established competitor is uh is is working on or some newcomer you've never heard of that's sitting in their mom's garage somewhere building out the next big disruptive move in your space, right? So so you have to be aware of this stuff. And I think one of the challenges we're up against, and this is something you see a lot in communities around governance, risk, compliance, cybersecurity, AI governance, is that this is happening faster than anything has ever happened. So the rate of change of how much AI is evolving and agentic AI and generative AI, just how much it's changing and how how innovative and how quickly people are building things, it's happening faster than governance traditionally happens. So you have a bit of a pace challenge here, right? And governance, governments have the same problem. They're governments have not been very good at building regulation quickly. And so now they're constantly in this catch-up role of trying to build regulation to protect society from how corporations that may not be thinking about this with the with the best interest of humanity in line are adopting this technology in fear of being blockbustered by their competitor. And governments are trying to race behind to try to put together pace uh piecemeal regulation to protect people. So this is all going on. And I think it's really overwhelming for organizations right now.
SPEAKER_00It absolutely. I mean, it's overwhelming for, you know, just individuals uh just trying to digest all the all the all the news happening, right? Yeah. I mean, working in the in the field, covering, you know, like reading all the headlines every day. I mean, it's just um it's amazing to see the pace of change. And um, you're exactly right. Like it's the I can't imagine the governance trying to keep up with with you know rolling out new features, but also managing the risk um and like the short-term versus long-term reward. Um, because like when you're talking about with the investors and and also the learning curve associated with like not understanding the full risks when rolling out maybe new features, um, it it's interesting because you you you know, like a business is supposed to have like the main goal is to maximize profits, right? But you can still you can still do that without while factoring the long-term sort of importance of of like bringing in trust and and having a good sort of foundational governance without carelessly violating the privacy or like security standards, right? Because like one, it just takes one data breach, one one security incident to sort of decimate a company. And and um, I mean, you look at, I don't know, 23andMe comes to mind. Uh, there's a lot of examples you can you can uh probably cite, but um it just takes one. And so rushing out to rushing to kind of keep up is like this double-edged sword where you want to race out to to set up to launch new features um and keep up with the competition, but also you want to be careful. Another thing that comes to mind, I don't know if you've been uh paying attention to was it Clogbot? I think it has a different name now. Um it's sort of that AI agenc sort of open source framework that have has sent a lot of people create like uh down the road of automating their everyday life and and various tasks and stuff. And and but there's just so many privacy and security implications around it and how it's not secure.
SPEAKER_01Yeah, the other one is open clause, the other one that that's um again, like and back to your point though, it's almost impossible to stay up to speed with this stuff. Like, I have multiple agentic frameworks installed on uh different sandboxed environments on my computer as as we test and play around with these these things. Like we're doing a lot of agentic stuff right now um with carbide, and there's this real push to to move quickly because the opportunities are really big, but you've got to really think out about how you guardrail this stuff and what are you actually giving it access to. Um, and I and I think, yeah, I think we're there's probably a lot of really bad things happening all of the time that we're not hearing that people are able to like shut it down and like brush it under the rug, and and and and I think there'll be a lot of catastrophic outcomes. And that's that's the way it's gonna be. But you as a business with real customer data, you you do have to you have to have these conversations. And this comes back to like, I mean, we see a lot of boards and a lot of C-suite are like, oh my god, we need to adopt agentic, we need agentic, like everybody's all these companies that are popping valuations off and raising massive rounds and all these these these big rapid growths are all built on this agentic, but you know, a lot of the time too, you have people asking for something, but they don't really understand the use case, they don't understand the use case and the risks. So it's it's challenging. Like all this tech, we talk about technology as making our lives easier. And I think like I would have imagined when when you think about how good tech is even is today, I think myself 20 years ago would have thought, oh, well, we have all this tech, we're not gonna have to work as much and we're gonna have lots more free time on our hands and just relax and enjoy life. I feel like it's the other way. Like I feel this, and and I know I'm not alone, I'm sure we feel the same way. It's like this overwhelming pressure to like you can never, you're never gonna know at all. And you're never like like I went on a trip for three weeks with no tech to India, and I came back, and the amount of things that changed just in that three-week period back in I think it yeah, early October, like ChatGPG launched a bunch of like pretty amazingly like game-changing features, and like a bunch of the other big LLMs did, and like all these different like lang chain and lang flow and all these different agenc things that were blowing up. And it was just, it's just it's really crazy fast. On one hand, it's super exciting. I feel like I feel like it's it reminds me of when I like I'm 51 and I think about when I was when I was young and like the internet came out, so I would have been like, I remember like using the internet in university in '94. And like the internet was very different, obviously, than it was today, and wasn't commonly adopted. It was sort of like nerds using the internet. It was kind of cutting edge edge. There wasn't really like corporate sites and things like that. But just seeing how all that grew and like how how things moved and how laptops went from like these big, clunky, useless things to being like, you know, who even has a desktop computer, the other than like gamers and like audio files and stuff like that. So it was like those were some interesting times, but now all of a sudden it's super exciting. Like, if I think about just in two years, how much how we work has changed because of AI. I was I was writing, I wrote a little thing on LinkedIn the other day because I was like, I catch myself talking like Chat GPT. I'm like, well, why? It's like, well, how often do you interact with with an LLM and how many conversations? And it's like, go look at your history, and you're like, oh my God, like I'm reading a lot more, but I'm reading a lot more, I'm reading a lot less of human-generated things, a lot more of technical. So I find myself almost like, I think it's changing the way I speak and probably the way other people speak. It's just like it's influencing how we work, how we think. So it's like it, it's it really is the changes are on all these levels. And this is why why leadership needs to understand it. This is not just about technical capacity, it's it's it's sitting around talking about well, how are people gonna do this in five years? And like people are gonna pay money for a product to learn how to do something like this, or are they just gonna go to their their favorite LLM and ask it to prepare like a training session, and it's just gonna like do it for them, and then they're gonna build this like interactive, like tailored pedagogy for themselves. So these are the things, right? It's it's the social impact, it's like the the workflow, it's like everything, it affects everything, right?
SPEAKER_00So in your book, like you you introduced this concept I thought was pretty interesting as as or this idea of the trust capital, um, which I think kind of puts the idea of trust in in sort of this more like tangible terms. How would you how should leaders think about trust capital in their day-to-day decision making, especially when you have some of the trade-offs involved, right? Like we've talked about some of the like the issues of shipping new features or delaying them for deeper testing to sort of avoid the the short-term risk around shipping something before it's ready. Um, do you, you know, do you collect more user data to improve personalization and whatnot, or is it you know not really worth the the increased sort of liability there? You know, there's a ton of examples I can think of, but how do you manage the trade-offs?
SPEAKER_01Yeah, and and I think those those trade-offs are are very unique for each business. When I think about the concept of trust capital, it's it's really the idea of a conscious, deliberate commitment. And this isn't this is beyond just you know saying words that you think your customers will appreciate, but like actually embody them and like what does that actually translate? What are we doing for whom and what matters to them? I think one of the things that I think comes from this new world of being able to um consume large amounts of data and get summaries using large language models is I think I think people are going to be less and Less reading the marketing jargon and more and more understanding under the hood what's going on in companies. And we see it even with employee recruitment and retention. Like in my when I was in my 20s, you're basically just went out and it was like, don't treat me too poorly and pay me well, an opportunity for growth in a business. But now people in interviews and especially younger generations, like they want to know that this organization stands for something and and is aligned with their beliefs and their morals, right? And I think that's like that's a piece of trust as well. It's not trust capital, isn't just your customers. It really is the full, the full world of stakeholders for an organization. So that's that could it be your investors, your shareholders, your your your employees are obviously key, your partners, um, and and your customers. So I think it's really about being deliberate about what what are you doing. And and then you make decisions that are deliberate based on what you've determined you stand for as a company legitimately. And it and it has to have a it's a long-term thinking versus a short-term thinking, right? And and I think you really need to look at at your customers and then everything you do or your stakeholders in general, everything you do, you ask the right questions. So, like in a compliance world, a risk assessment happens once a year. A few people sit in the room, they go through the motions, they have a couple of things on a risk register, they give it a random quantified or qualitative score, and they check the box and it's kind of it looks like they're doing their it looks like they're doing it, but it's a little bit of a security or a compliance theater move. But in in a in a real trust capital world, when you look at risks and threats and you make decisions, you actually have the conversation every time you do something. So, hey, here's a new feature idea. Great. What value does it bring our customers? What what financial? Again, I mean, you're they're companies, right? So you you're you're still there to generate cash. So, like, what is this going to bring to us? What is this gonna bring to value to the customers? What are the risks this this brings to us? And what are the risks this brings to the customers? And thinking about that from the onset versus I think the traditional way that we often see organizations is it's like build the feature, build the thing, and then have the security guys or the privacy guys come in and try to like duct tape a solution around it. But if you just think about that from the beginning with this idea of, hey, we're building a trusted organization. We think about this in everything we do, long-term play, then you might make decisions that drastically change the risk associated with that feature. Like maybe you decide, hey, we don't need to get your birth date. We can just use this way of validating that you're above the age of X without having that little piece of data that everyone else is collecting. But do we really need it? And you start thinking about like, can you minimize the risk and maximize the value? And then, you know, if you and then you tell how do you tell that story? So unfortunately, I think we've put the cart before toward the horse, or a lot of organizations have, which is they tell their trust story before they've actually built a culture of trust. And that's theater, or it's kind of bullshit in a way, like it's not real, right? It's like marketing folks just saying, like, hey, we're trustworthy, we care about blah, blah, blah. I mean, you see it all the time. Companies that have big breaches, when it comes out, well, you know, they didn't do this, they didn't put budget in place for this. They they had an audit done two years ago that said they should do this. They never put the money in it. But their website says, look at us, we're awesome. We do all these great things to protect our customers. So you really build real trust capital. It's real, it's discussed at the board level. It's something that's measured, it's something that's prioritized, not just in an IT room or an IT department, but actually at the board table, at the C-suite table, it's tied into the strategy and it's something you build deliberately. You tell that story, you build that, you protect that. And over time, that's how you build. I believe that's how you build the future big brand that people talk about and have real allegiance to.
SPEAKER_00When you when you mentioned compliance, so like when it comes to compliance, we've obviously covered that topic a lot here in the podcast, but it seems like a ton of organizations still default to these compliance checklists. In your view, what sort of separates compliance activity from governance that actually sort of changes real outcomes?
SPEAKER_01Yeah, it's a big topic, and and it's a complex one for sure. So, yeah, a lot of organizations focus on compliance, and a lot of that comes from supply chain or requirements. So we, and this is something that we've we've experienced firsthand. Um, a lot of our customers come to Carbide specifically for that purpose of, well, hey, I've got a company that would need me to be certified in XYZ by some date, or we can't work with them, or you know, we need SOC2 to close deals, or we need this ISO standard, or or this NIST thing. And and and that, I mean, that comes from organizations trying to standardize third-party risk management. And it has really good intent. And I think if done properly, um, it can certainly lift things. But again, these standards are the same problems we're talking about with governance and regulations, trying to keep up with the race, the standards are failing to do so as well. So uh let's say, for example, you could have an organization that has a as a perfect SOC2 report where third-party firms come in, assess that they have controls in place that are working over you know, you know, measured over a period of time that meet all the AI CPA trust principles, but that doesn't mean the company has going to have cash in four months. Like they're they're still siloed in a perspective or in a certain lane often, right? Or that doesn't mean that the the new AI feature they're about to put out is entirely understood and that all of the different risks and threats have been appropriately measured and put in place. So so compliance is it's a step in in the direction, like it forces you to build policies and it does force you to build a governance program, but it it doesn't mean that that program is all inclusive and that that program is going to cover all of the risks that that a particular customer of that particular organization may be concerned about. So um, and and another challenge that we see, and it's and it's I would say an unintended outcome of compliance is sometimes we see small businesses as little as 20 employees, where they are being required through their supply chain or the variety of supply chains they work in to be compliant with like four or five different standards. So what that ends up turning into, unfortunately, is very becomes very bureaucratic. And so if you think of like, well, why do governments and why do enterprise organizations hire smaller startups and earlier stage companies to solve innovative problems? It's often because they can move faster because they're smaller and they're not buried in bureaucracy and politics and all this kind of stuff. And so when you start seeing an organization of 20 people need to do a 20 an ISO 27001 audit, um, they have to have a full set of compliance documentation for, say, like a GDPR regulation, maybe some other privacy regulations, maybe they have to do CMMC for their some of their uh US government and and and defense contractors, and they have a SOC 2, they have all these things. All of a sudden, now, and we see this a lot, not only in small companies, we see it in big companies where more than half of the resources of the cybersecurity team, the team that's there to protect the organization from threats, more than half of those resources are being spent assisting in audits and facilitating paperwork and documentation and and answering security questionnaires. And this is a real common problem out there. And it's, you know, I had this conversation with the CISO of a of a several hundred um company, uh several hundred employee company a few weeks ago. And I was like, well, half of your security team should actually why don't you talk to your CEO about putting them, calling them sales engineers and putting them in the sales team? Because really what they're doing is they're our team, they're telling your trust story in the through the various different ways that it needs to be told, whether that's answering questionnaires or or or or getting on calls with with the third-party risk management teams to your customers, they're actually not spending those two, you have two resources and a four four-person team that are actually not securing anything. They're literally just greasing the wheels of make selling the the security program to third-party risk management teams in your in your supply chain. So, you know, that's that's part of the challenge that we see. So, does compliance equal security? No, that's sort of the industry, I think, mostly agrees that compliance generally doesn't. Um it can if it's done well, but it's hard to do well, um, especially when you have multi-compliance and you have you have you have financial constraints that you you need to meet up with. So, you know, it should all be about risks. It should be all be about what's what you're trying to protect for your own risk appetite and your customer's appetite. And it should be about transparency, like the things that the real risks that your customer has, you need to be able to have those conversations so they understand the risks. And you need to have the documentation and you need to have the ability to tell them and show them what they can do to reduce those risks. Um, and a lot of that stuff doesn't come across, despite all the good intentions of the cybersecurity frameworks and the data privacy frameworks. They don't always cover, they generally don't cover all of the risks. And they're they're one size fit all frameworks, which is really complicated to have. You know, SOC 2, you're gonna have the same trust principles or the same ISO stand, the same ISO controls for a manufacturing company as you are for a software as a service company, as you are for a paper shredding company. And it's really hard to make those that that one size fits all scenario.
SPEAKER_00Yeah, I mean, the bureaucracy, that's something that you know impacts businesses in all sorts of industries um and and governments. And um, I think like you're saying, it's like, well, it's one thing to like pass an audit, um, but I think it's it's a it's a different thing to to sort of meaningfully reduce risk and strengthen trust. Um and so finding uh I don't know, a balance uh between the two or um is interesting. And um the bureaucracy points you made though, I I I want to focus on that for a moment because obviously we've talked about how like founders and companies, there's often this fear that like stronger governance uh it sort of slows momentum, it might hurt the growth capabilities, could hurt the I don't know, bottom line. Um but just as companies scale up in size, how have you you know seen companies scale trust without creating those friction points or the bureaucracy you mentioned?
SPEAKER_01I think it's fair to think that governance slows things down and and and and will create friction. It mostly does. And and I think a big part of the reason it mostly does is because most of the people that are practitioners in the field are too focused on governance and not focused on outcome. And and I think if you go and you try to take a template or a standard and you and you go in and you apply that to your business, it very quickly can be over-engineered or um you you lose clarity. And you know, you you see these organizations that have four or five hundred pages of policies, like could we do this with maybe 30 pages of policies? So I think it's really about it, really is about really being intentional. And it's I think it's a bit of an art to an art that requires understanding of the threats and the risks, but also understanding of productivity. If you're just a protection, if you're just to if you're a practitioner who's really just focusing on risk reduction and protection and compliance, and you don't have innovation skills and user design skills, and you don't have experience in moving fast and delivering and growing the business, then how the hell would you ever get it right in the first place, right? So I think I think that's the part of the challenge, right? Like there's a way governance can be built into organization that I believe doesn't slow it down. It it may slow you down slightly at first, but I think it actually creates a framework for velocity, like it enables you to move faster. And and that is, it's often less is more, but it's the right things. And those require, and this is why it has to go to leadership, because like who's able to make the decisions on what's actually important and what's not important? Where are we willing to accept some risk? And where are we not willing to accept that risk? And then be very deliberate and very, very deliberate and very creative in how you architect what a governance program is. And um, if you do that right, it'll I it will make your organization be able to move more quickly because you'll get a velocity and a pace and you'll reduce the setbacks that come from when bad decisions happen. And it's not always just like I see this all the time, right? It's not, especially in cybersecurity or in product-related stuff, it's not always just as simple as like, hey, we're putting this governance in place so we don't get hacked. It's often things like put the governance in place so we actually, if it's done right, it can help you build better features and get more input. It can reduce the likelihood that you'll have bugs that will reduce that will erode some of that customer confidence when you ship a new feature and it does weird things it shouldn't do. Like most of the data incidents that I see and the data breaches I've seen, there's no hackers involved. It's literally like somebody's gaining access to a bunch of stuff they shouldn't because somebody shipped code under dress and it was it didn't, they didn't take the proper steps and and they didn't think of all the outcomes. So it's not easy, but it's it's able to be done where you build a program that can actually enable a certain degree of safety, but but actually actually move. Again, the least risky thing would be to grind everything down to nothing, but that doesn't that makes no sense, right?
SPEAKER_00Got it. Yeah. So you have to focus on on, you know, reframe it like strong governance can be an enabler. It's not just a constraint, but you have to focus on the right style of governance, one that focuses on the right kind of priorities, right? Of trust and and and discipline.
SPEAKER_01And yeah, and it and it plays back to like when I when I and this is my theory. I mean, you might run into practitioners that disagree with this, but cybersecurity, as an example, has always been a bolt-on. In other words, you build a product, you build a company, and then all of a sudden you're like, oh what, we need to do this thing, and then you bring in somebody and they try to, they try to put all like, but everything's already been built. And this is the problem. This is where governance becomes challenged because everything's already built. You built your process, you built your systems, you have your tools, you have the way you're doing everything, and everybody's just getting on. And now you're bringing in these guys or gals or people that just basically tell us we got to redo all this thing, and then they become the, they become the naysayers. But when you build it right out of the gate from scratch, it becomes really effective. And and back to my point, and both in leadership, but also like, you know, when you bring in governance practitioners that don't understand the problem you're trying to solve, how are they going to be able to be building governance that actually enables people to move fast, right? So I believe this is where I think the future of AI governance, data privacy, cybersecurity goes, is it's less about hiring practitioners that just sit in the cyber office and focus on cyber. I think it's more about people in all the roles of an organization understanding these concepts as fundamental concepts. I mean, technology is not like it's not a department. Like any company, even if you're not a tech company, everybody's using a phone that's like a supercomputer compared to what we had access to 10 years ago in an office. We all have laptops, we all like we're all using AI, we're all using all like technology is everywhere. So it's not like stop treating it like its own, like its own bundle or like its own. It's like you, you if you want to be anything today in any career, you have to have a certain degree of technological like understanding and and and literacy, right? Same with AI, same with so you boltly if you bring that cyber practice in. Like I say to young people they're like, oh my God, we can't get an entry-level cyber job. It's like, well, what else are you passionate about? You're what, you're like 21 years old, like look, you got your whole life in front of you. Oh, I like design, I like building products. Cool. Go take your cyber degree and your cyber, your cyber certificate and go work on what's people building products, and then you'll be able to build for that organization a product, and you can build the cybersecurity, like the security by design by default concept into it. And that's the type of like that's the type of thinking where people, like everybody in the organization has a respect and understanding of what's important, what's not, which comes from leadership. But then everybody in their role understands like what their role is in cyber, right? HR people, training people, people that test people that test code or people that test features before they go live, people that design the workflow of the feature, like even like there's there's a role for ethical AI and there's a role for data privacy knowledge just in how you like how clearly you articulate that workflow. When I go into a product and I'm signing up for something, it's like auto-clicking the check mark to for me to get like a newsletter. Like, stop doing that, right? Like these are design decisions. So, so I I think that's really that's if I were to say, like, what am I trying to achieve with this book? Like, what how would I like this book in a magical world if everything went as planned and everybody read it and it became a it became a popular book? I would hope the impact would be that, that people stop thinking about this as like a bolt-on effect to what they do and and think about it more as an integrated component of the world we operate on and use these concepts both in how they work, how they build things, or how they like design their home, or like, you know, but you buy your child a computer and you let them sign up. Like that just understanding the literacy of the reality we live in and how it applies to your world personally and professionally, if people can start getting into that thinking versus like, I'm not a cyber guy, I'm not a privacy guy, this stuff is not rocket science. Sure, if you want to be like a cryptographer that builds like post-quantum encryption, that is rocket science. But if you just want to be an average human who contributes in whatever context, personally and professionally in your world you do, like you can learn how to be a very effective and understand this concept of like digital trust and what are the skills you need to know. Just a little bit of awareness will change how you look at little things that you do every day. Sort of the contrary to what we were saying earlier, but oh my God, it's all moving so fast. How do you keep up? And yes, that is definitely the case when it comes to A but AI and these things for sure. But when it comes to like usability of technology in general, like I think about when I was go back to '93 when I was trying to use the internet. And like, I mean, computers were not easy to use. Like you waited for a long time for them to boot up. There were often like some command line stuff that you needed to do just to get basic functionality. I also see people that are that are in their 70s and even 80s that have just been like, yeah, you know, I'm just gonna like if soon you take down that barrier and you start playing with it, it's just patterns and and and you know, some some older people are actually really, really good at using some of this very new tech. Like I I know people in their 70s that are like, oh, this AI stuff's great.
SPEAKER_00Like, yeah, well, and there's different, like uh like you using a smartphone is like one thing, but um, and there's certainly outliers I think with with like proficient users um like who are their 70s and 80s and whatnot. But I think what you start to get like run into a lot of issues when you have like the tech being incorporated in like um medical scenarios or something. And that kind of comes down to like, you know, if you just it's not like it's very complex. I think if you just learn the basics of how a touch screen and like the menu system works, I think that's um you know a good start and kind of can can help kind of take the learning curve associated out of it and the scary part of of out of out of it.
SPEAKER_01But I think you're right. And I think AI is also the frontier that again, really great use cases of of of how AI can be leveraged. I think it can also bypass some of that for for people where it, you know, now you don't have to interact with the tablet, the tablet sees you, you look at it, it looks, you know, now you have face recognition and you talk to it and it and it like that that's coming and and the tech, the the tech, the building blocks are there for that now. And I think you'll see you'll see some people like jump over tech in some ways. It's it's like they'll they'll jump over the errors of tech that that that they didn't interact with because they were not techy, and now you have this ability to almost personify the tech to a degree um that has a has a a huge impact potentially on people that are not necessarily super technically um literate. Like I always I say all the time, like I like I use so many different SAS SAS things, and like how many times you're like going around, you're trying to find one thing, right? Like, how do I see my receipts? And you're clicking around, and it's like like like at some point, is it gonna be that your average SaaS interface is just gonna be like a chat bot? You're just gonna be like, hey, can you please like what's my monthly bill? Hey, please, can you cancel my account? Or boom, I want it to cancel on this date. Enter. Do you want to do this? Yes. Like, I think it's almost like if you imagine like communicating with your with your laptop in terminal, but with terminal, you need to have the syntax down. So you need to, you know, you understand that language of being able to talk to it. But I think I think we're gonna see a a future sooner where more and more highly functional applications are gonna start sounding or being interactive like Chat GPT. Like, how many times have been like, hey, Chat GPT, how do I turn on this feature in Google Workspace? And then it goes, hey, click here, go there, go there. What if I'm just in Google Workspace, say, hey, can you please turn on I'm going on a vacation? Can you say uh, hey, thank you. Well, uh, write me a note about I'm on vacation. And then I'll get back to you after this and start it tomorrow morning at three. Whatever, right? Like I think like that's gonna be a phase where all of a sudden people that may have been self-claiming themselves as being technological Luddites are gonna be able to just go in and use like or like conversational compute conversationally with highly powerful tools and and then maybe not have to understand or or or learn some of the learnings that my generation and your generation had to learn in order to be proficient using these technologies.
SPEAKER_00True. I think that yeah, I think there's a definitely some upside there. And I think uh I smartphone apps are gonna be likely a thing in the past. I think you're gonna basically have um an LLM that has all these apps integrated into it. So, like you were saying, you just like just start using your natural language to kind of say, open uh I want to post a real to Instagram because it's already connected with all these different apps.
SPEAKER_01And that's the frontier. I think that's the frontier we're at when we're talking about these like really powerful agentic tools. And and and this is these are the this is the level of power that I think most of us that are you know for AI uh conceptually want to get to. But understanding that the the the amount of understanding of what's good and what's bad and how we guardrail that and how we protect that, because it's like, are you gonna hand the keys to your laptop? Like, you know, I've got a sandbox that I'm playing around with some tools and giving it very controlled amounts of data. But like, do you really want uh like a complete uh LLM system to be accessing, like reading your emails, responding, logging into your Google, buying a flight, like it has your credit card? Like the like I want that, and I'm I'm excited about that and I'm terrified about that at the same time. And I think that's where like these are the frontiers of innovation of like, how do we do this, but have it be dependable and reliable? And how do we create those checks and balances? And this is like the exact conversation that the boards and the CEOs and everybody in in the companies need to be thinking about as they're thinking about how do we do this stuff. You want to innovate. The first per the first organizations that come out and solve this problem in a trustworthy way are gonna be very successful, but you can't just push these super powerful tools out into the wild and hope that nothing bad happens because bad things are gonna happen, right?
SPEAKER_00So yeah, no, I I I think uh that's that's like which organization, which company do you like trust to like pull off a lot of these features? And like, do you feel comfortable with um you know, having access to a lot of your your private information? And like are they the companies that have a really strong sort of um trust philosophy and and great in their governance? Um I I think like that sort of leads me into my next question for you. And um, I've got a couple more before we wrap up, and but I just want to get your thoughts on on sort of what really moves the needle, right? Like for for readers listening um who who are interested and and built a trust and hopefully get a chance to read it when it when it's um released, but they want to turn some of those insights you talk about and and in the book and also here in the podcast into actions, right? Where should they focus in the first, let's say, like 30 to 60 days or so to meaningfully like strengthen their their organization's trust?
SPEAKER_01I I would say the first thing is really actually understanding the the threats and the risks in what your organization is doing. We see I I I sat in the a board room with an organization um probably about a year ago, and I was talking about, well, you know, you guys like how aren't you guys worried about all of the all of the AI that your employees are using? And they were like, Well, our employees don't use AI. I was like, you don't think your employees like you've got a bunch of 20 and 30 something year olds that are all tripping over all the cool LLMs, you think they're just like sitting there just because you didn't provide them an AI tool or you didn't create an appropriate policy on AI and how they can use it. You don't think they got their own like grok accounts and chat GPT accounts? Come on, right? Like, right? Like so, so like that self-awareness is definitely the place to start. And it's and it's looking at what are the threats to the business, what are the different tools people like it blows my mind how many organizations have shadow IT and shadow AI, like just rampant through the organization. I I think if you are too strict, like if you don't give people tools that are good to use, most people are gonna find ways to fill those gaps themselves in a lot of organizations. So understand what you have, what you have in place, understand what's important and and and document it, right? Like so many organizations, like they ask five different people in the organization what's important to the business, and you get different answers. So you have to understand that you have to you have to kind of look internally and understand what what you're doing, what threats are associated with what you're doing. That's a big one. Do an actual risk assessment, not a compliance-driven one, but really put like put the right people in the room. I hate when I see organizations have to do a risk assessment for a SOC too. So they have like a uh, you know, they have some like a couple of junior employees that have no decision-making power, don't even really understand what what the crown jewels of the company necessarily are, and they're doing the risk assessment to go through the motions, but like, no, we you can't have that, right? So that awareness is core, right? And then, and then it's understanding, well, what what do we need? Do we understand the stuff that's going on around us?
SPEAKER_00Yeah, yeah. Having the awareness and understanding, I think, are two are two fundamental sort of pillars. Um, and I think that uh, you know, you also like obviously you want to um embrace some of these like AI tools, like you're mentioning some of these companies are like, don't use those certain LLMs. I'm like, well, they're like you said, these the employees are gonna use them, they're gonna seek out sort of like solutions and the tools that are available. And if you don't provide you know a recommended solution, like they're gonna take potentially like maybe company proprietary information and just start pasting it into Chat GPT, yeah. Uh, which is just opens you up to more uh potential crises. So um, regardless, it's um you've given us lots of insights and and things to think about. And I'm really excited to uh get my hands on a copy of your book. And I'm curious, um maybe you can uh enlighten listeners and and like if uh uh I'm sure a lot of listeners are interested in getting a copy of their own uh of Built to Trust. Where can they go to pick one up?
SPEAKER_01Yeah, so the book is gonna launch on September 8th, and it will be available. Um, Amazon is gonna be one of the big uh online places where you can get it. Uh, we also have a website, it's a companion site to the book. It's built to trustbook.com. And that will be launching sometime in late May. So that'll be launching before the book, and we'll have we'll have lots of resources that are gonna be free resources out there. Um, some of those will cover topics of the book, but there'll also be like templates and and and different things like that. So things that we didn't put in the book. Um, it's also one of the ways that we, you know, try to write a book about this stuff in this changing world. You don't want the book to be obsolete by the time it comes off the press. So we tried to keep the concepts really uh more timeless and around leadership and around uh the the concepts at a high level, and then use the companion site to be able to go out and get um, you know, tool tools and and up-to-date uh ways or techniques or frameworks to apply some of these things in your in your life or in your your business.
SPEAKER_00Perfect. Well, I'm looking forward to it. I'm I'm excited to get a copy. And um, I think uh the the website, stay tuned. Listeners go to builttotrustbook.com. I think that's pretty easy to remember. And there should be links in the description and then the article uh for this podcast over on Sourceforge.net. So Darren, it's been a pleasure. I really appreciate everything you've shared with us. Uh, I really enjoyed this conversation and just um unpacking all the, you know, not just the risks, but the the leadership sort of mindset behind um building something really long lasting with uh, you know, for companies and and for leaders. So um just thank you so much for everything you've shared with us.
SPEAKER_01Glad to be here. Thanks for having me.
SPEAKER_00Of course. Thank you all for listening to the SourceForge podcast. I'm your host, Bo Hamilton. Make sure to subscribe to stay up to date with all of our upcoming B2B software related podcasts. I will talk to you in the next one.