Podcast

Drata And The Rise Of The Chief Trust Officer In The AI Era

Have you ever wondered why “compliance” still gets treated like a slow, spreadsheet-heavy chore, even though the rest of the business is moving at machine speed?

In this episode of Tech Talks Daily, I sit down with Matt Hillary, Chief Information Security Officer at Drata, to talk about what actually changes when AI and automation land in the middle of governance, risk, and compliance. Matt brings a rare viewpoint because he lives this day-to-day as “customer zero,” running Drata internally while also leading IT, security, GRC, and enterprise apps.

We get practical fast. Matt shares how AI-assisted questionnaire workflows can turn a 120-question security assessment from a late-afternoon time sink into something you can complete with confidence in minutes, then still make it upstairs in time for dinner. He also explains how automation flips the audit dynamic by moving from random sampling to continuous, full-population checks, using APIs to validate evidence at scale, without hounding control owners unless something is actually wrong.

We also talk about what security leadership really looks like when the stakes rise. Matt reflects on lessons from his time at AWS, why curiosity and adaptability matter when the “canvas” keeps changing, and how customer focus becomes the foundation of trust. That theme runs through the whole conversation, including the idea that the CISO role is steadily turning into a chief trust officer role, where integrity, transparency, and credibility under pressure matter as much as tooling.

And because burnout is never far away in security, we dig into the human side too. Matt unpacks how automation can reduce cognitive load, but also warns about swapping one kind of pressure for another, especially when teams get trapped producing endless dashboards and vanity metrics instead of focusing on the few measures that actually reduce risk.

To wrap things up, Matt leaves a song for the playlist, Illenium’s “You’re Alive,” plus a book recommendation, “Lessons from the Front Lines, Insights from a Cybersecurity Career” by Asaf Karen, which he says stands out for how it treats the human side of security leadership. If you’re thinking about modernizing compliance in 2026 without losing the human element, his parting principle is simple and powerful: be intentional, keep asking why, and spend your limited time on what truly matters.

So where do you land on this shift toward continuous trust, do you see it becoming the default expectation for buyers and auditors, and what should leaders do now to make sure automation reduces pressure instead of quietly adding more? Share your thoughts with me, I’d love to hear how you’re approaching it.

Useful Links


Subscribe to the Tech Talks Daily Podcast

administrator

Recent Posts

Miro CIO Tomás Dostal Freire On Reclaiming Creative Time With AI

Why do so many of us feel busy all day, yet struggle to point to…

6 months ago

From 1.16 BillionReactive Logs A Day To Proactive Insight: Storio Group And Dynatrace

How do you protect millions in revenue during your busiest hour of the year when…

6 months ago

How The IOWN Global Forum Is Reinventing Financial Infrastructure With Photonics

How do you design financial infrastructure that keeps running when the unexpected hits, whether that…

6 months ago

Rethinking Prevention And Recovery With Barracuda XDR

Can designing for human error become the strongest cybersecurity strategy in an AI-accelerated world? In…

6 months ago

Atlassian On Why AI Must Deliver Measurable Business Outcomes

At Davos this year, some of the biggest names in tech sent a clear signal.…

6 months ago

AI Everything Cairo: Capgemini And Egypt’s Moment On The Global AI Stage

After stepping off stage from moderating a panel, a Senior Frontend Developer from Capgemini waited…

6 months ago