Strategic CISOs | Podcast Series by TrustCloud®
What It Really Takes to Lead Security in Higher Education
Learn how to build a resilient GRC program, earn leadership trust, and make automation work for you
What happens when a CISO with more than 20 years of financial services experience chooses to lead security in higher education?
Join Matthew Martin, CISO at Western Carolina University, and Sravish Sridhar, CEO at TrustCloud, in this new #StrategicCISOs session to learn how Matt is applying lessons from his experience in financial services to the very different realities of higher education, where security leaders must creatively manage serious risk, limited resources, and complex obligations in a regulated environment.
Featuring
Matthew Martin
CISO, Western Carolina University
Sravish Sridhar
CEO, TrustCloud
(Host)
Access Webinar On-Demand
How should a new CISO spend their first 90 days in higher education?
A new CISO’s first 90 days should be spent listening and documenting, not fixing — because the trust built in that window is what makes every later change possible.
That’s the central lesson Matthew Martin, CISO at Western Carolina University, shares in this Strategic CISOs session with TrustCloud CEO Sravish Sridhar. After two decades leading security in financial services, Martin moved into higher education and, by his own account, spent his first month over-correcting — opening tickets and asking teams to change course before he understood why things worked the way they did.
The session’s real value is in the specifics: how Martin turned conversations with IT leaders into the start of a risk register, why he moved from person-by-person access approvals to use-case-based policy, and how AI and automation now let a small team cover a workload that once required a much larger one.
FROM THE SESSION
Key Takeaways
Listen before you fix.
The instinct that got a CISO hired — see what’s broken, act fast — is the wrong instinct for the first 90 days. Early wins in trust matter more than early wins in remediation.
Turn IT’s pain points into your risk register.
Conversations with IT and business leaders about what isn’t working are a faster, more accurate starting point for risk documentation than any spreadsheet audit.
Document inside a framework from week one.
Structured risk language, even imperfect at first, is more useful than an ad hoc backlog of fixes.
Replace person-by-person approvals with use-case policy.
Decisions made one person at a time don’t scale and don’t hold up to audit. Defining the use case behind a request makes the decision consistent and defensible for everyone who fits that pattern.
Trust is a resource you spend, not a given.
Every early interaction is a deposit or a withdrawal. CISOs who push too hard, too early, often run out of credibility before they’ve had the chance to use it.
Influence-based leadership isn’t unique to higher ed.
The same discipline applies anywhere authority is limited and cross-functional buy-in is the real currency — decentralized organizations, matrix structures, and regulated industries with strong business-unit autonomy.
SESSION AGENDA
What We Covered
01
How Matt's journey from financial services shaped his approach to leading security in higher education
02
What it took to lead security in higher education: creativity within constraints
03
How to build a resilient GRC foundation: risk management, automation, and AI in practice
04
Advice for CISOs in higher education and similarly resource-constrained industries
05
Predictions and trends for Strategic CISOs
06
Audience Q&A highlights
GO DEEPER
Companion Reading
Strategic CISOs: A Power Mindset for Your First 90 Days
Our companion article pulls out the mindset shift underneath this conversation: why the instinct to act fast is often the wrong instinct for a new CISO, and what "listening first" actually looks like day to day — including how Matt rebuilt trust with IT leaders and moved from person-by-person access approvals to use-case-based policy.
SESSION CUTS
Highlights from the session
Ghana origin story
Creativity within constraints: the question and the answer
The biggest mistake new CISOs make
Stop talking about people, start talking about use cases
AI is the only way to scale security in higher ed
The four-box summary
Speakers
Matthew Martin
CISO, Western Carolina University
Matt Martin brings more than two decades of security leadership from financial services to his role at Western Carolina University, where he’s built a program grounded in cross-functional trust and disciplined risk management. His work applying enterprise-grade fundamentals to a resource-constrained, highly regulated environment has made him a sought-after voice on leading security where influence matters more than authority.
Sravish Sridhar
CEO, TrustCloud
Sravish is the founder and CEO of TrustCloud, a security assurance platform built to help CISOs at mid-market and enterprise companies reimagine GRC as a continuous, AI-driven function. He hosts the Strategic CISOs series to bring practitioner frameworks directly to security leaders.
WHO THIS IS FOR
Built for security leaders in higher ed and beyond
CISOs and security leaders in higher education, government, nonprofit, healthcare, and other resource-constrained environments
GRC and risk leaders building more resilient, automated assurance programs
Security leaders who need to communicate risk more clearly to boards, trustees, presidents, and executive teams
Teams looking to reduce manual work through automation, AI, and continuous control monitoring
Any Strategic CISO who wants to build a stronger program without simply asking for more budget
FAQ
Questions CISOs ask about this session
What should a new CISO do in their first 90 days?
The strongest new CISOs spend their first 90 days listening rather than fixing. That means talking with IT and business leaders about what isn’t working, documenting risk inside a framework instead of reacting to scattered requests, and building the cross-functional trust needed to drive bigger changes later.
How do you build a security program with limited budget and staff?
Start by treating conversations with existing IT and business teams as your risk assessment — their pain points already point to where the gaps are. From there, apply consistent, use-case-based policies instead of one-off decisions, and use automation to extend a small team’s capacity rather than trying to hire your way to coverage.
Why do use-case-based access decisions work better than person-by-person approvals?
Person-by-person approvals create a collection of individual judgment calls with no consistent rationale, which becomes difficult to audit or defend over time. Defining the underlying use case and applying one policy to everyone who fits that pattern makes access decisions consistent, scalable, and defensible.
How is leading security in higher education different from financial services?
Higher education typically comes with a similar regulatory burden but a fraction of the budget, staff, and centralized authority found in financial services. Security leaders have to rely more on cross-functional trust and influence, since mandates alone don’t move a decentralized institution.
How do you communicate security risk to a board or executive team?
Translate technical risk into the language of institutional priorities and consequences the audience already cares about, rather than technical detail. This session covers how to frame risk conversations for boards, trustees, presidents, and other non-technical executives.
Access Webinar On-Demand
Missed the webinar? Never mind. You can access it here.