451 Research report on Cyber Risk Assurance fueled by continuous control monitoring. Read the report →

Strategic CISOs | Podcast Series by TrustCloud®

What It Really Takes to Lead Security in Higher Education

Learn how to build a resilient GRC program, earn leadership trust, and make automation work for you

What happens when a CISO with more than 20 years of financial services experience chooses to lead security in higher education?

Join Matthew Martin, CISO at Western Carolina University, and Sravish Sridhar, CEO at TrustCloud, in this new #StrategicCISOs session to learn how Matt is applying lessons from his experience in financial services to the very different realities of higher education, where security leaders must creatively manage serious risk, limited resources, and complex obligations in a regulated environment.

Featuring

1723405844513
Matthew Martin

CISO, Western Carolina University

SravishSridhar
Sravish Sridhar

CEO, TrustCloud

(Host)

Access Webinar On-Demand

How should a new CISO spend their first 90 days in higher education?

A new CISO’s first 90 days should be spent listening and documenting, not fixing — because the trust built in that window is what makes every later change possible.

That’s the central lesson Matthew Martin, CISO at Western Carolina University, shares in this Strategic CISOs session with TrustCloud CEO Sravish Sridhar. After two decades leading security in financial services, Martin moved into higher education and, by his own account, spent his first month over-correcting — opening tickets and asking teams to change course before he understood why things worked the way they did.

The session’s real value is in the specifics: how Martin turned conversations with IT leaders into the start of a risk register, why he moved from person-by-person access approvals to use-case-based policy, and how AI and automation now let a small team cover a workload that once required a much larger one.

FROM THE SESSION

Key Takeaways

Here are the top highlights on leading security in higher education, building trust, and using automation to scale.

Listen before you fix.

The instinct that got a CISO hired — see what’s broken, act fast — is the wrong instinct for the first 90 days. Early wins in trust matter more than early wins in remediation.

Turn IT’s pain points into your risk register.

Conversations with IT and business leaders about what isn’t working are a faster, more accurate starting point for risk documentation than any spreadsheet audit.

Document inside a framework from week one.

Structured risk language, even imperfect at first, is more useful than an ad hoc backlog of fixes.

Replace person-by-person approvals with use-case policy.

Decisions made one person at a time don’t scale and don’t hold up to audit. Defining the use case behind a request makes the decision consistent and defensible for everyone who fits that pattern.

Trust is a resource you spend, not a given.

Every early interaction is a deposit or a withdrawal. CISOs who push too hard, too early, often run out of credibility before they’ve had the chance to use it.

Influence-based leadership isn’t unique to higher ed.

The same discipline applies anywhere authority is limited and cross-functional buy-in is the real currency — decentralized organizations, matrix structures, and regulated industries with strong business-unit autonomy.

SESSION AGENDA

What We Covered

01

How Matt's journey from financial services shaped his approach to leading security in higher education

02

What it took to lead security in higher education: creativity within constraints

03

How to build a resilient GRC foundation: risk management, automation, and AI in practice

04

Advice for CISOs in higher education and similarly resource-constrained industries

05

Predictions and trends for Strategic CISOs

06

Audience Q&A highlights

GO DEEPER

Companion Reading

Strategic CISOs: A Power Mindset for Your First 90 Days

Our companion article pulls out the mindset shift underneath this conversation: why the instinct to act fast is often the wrong instinct for a new CISO, and what "listening first" actually looks like day to day — including how Matt rebuilt trust with IT leaders and moved from person-by-person access approvals to use-case-based policy.

SESSION CUTS

Highlights from the session

Ghana origin story

Creativity within constraints: the question and the answer

The biggest mistake new CISOs make

Stop talking about people, start talking about use cases

AI is the only way to scale security in higher ed

The four-box summary

Speakers

1723405844513 1
Matthew Martin

CISO, Western Carolina University

Matt Martin brings more than two decades of security leadership from financial services to his role at Western Carolina University, where he’s built a program grounded in cross-functional trust and disciplined risk management. His work applying enterprise-grade fundamentals to a resource-constrained, highly regulated environment has made him a sought-after voice on leading security where influence matters more than authority.

SravishSridhar
Sravish Sridhar

CEO, TrustCloud

Sravish is the founder and CEO of TrustCloud, a security assurance platform built to help CISOs at mid-market and enterprise companies reimagine GRC as a continuous, AI-driven function. He hosts the Strategic CISOs series to bring practitioner frameworks directly to security leaders.

WHO THIS IS FOR

Built for security leaders in higher ed and beyond

CISOs and security leaders in higher education, government, nonprofit, healthcare, and other resource-constrained environments

GRC and risk leaders building more resilient, automated assurance programs

Security leaders who need to communicate risk more clearly to boards, trustees, presidents, and executive teams

Teams looking to reduce manual work through automation, AI, and continuous control monitoring

Any Strategic CISO who wants to build a stronger program without simply asking for more budget

FAQ

Questions CISOs ask about this session

What should a new CISO do in their first 90 days?

The strongest new CISOs spend their first 90 days listening rather than fixing. That means talking with IT and business leaders about what isn’t working, documenting risk inside a framework instead of reacting to scattered requests, and building the cross-functional trust needed to drive bigger changes later.

Start by treating conversations with existing IT and business teams as your risk assessment — their pain points already point to where the gaps are. From there, apply consistent, use-case-based policies instead of one-off decisions, and use automation to extend a small team’s capacity rather than trying to hire your way to coverage.

Person-by-person approvals create a collection of individual judgment calls with no consistent rationale, which becomes difficult to audit or defend over time. Defining the underlying use case and applying one policy to everyone who fits that pattern makes access decisions consistent, scalable, and defensible.

Higher education typically comes with a similar regulatory burden but a fraction of the budget, staff, and centralized authority found in financial services. Security leaders have to rely more on cross-functional trust and influence, since mandates alone don’t move a decentralized institution.

Translate technical risk into the language of institutional priorities and consequences the audience already cares about, rather than technical detail. This session covers how to frame risk conversations for boards, trustees, presidents, and other non-technical executives.

Access Webinar On-Demand

Missed the webinar? Never mind. You can access it here.

g trusty thumbs up