Learn How to Invest in Yourself Your Business Your Executive Connections

Learn How to Invest in Yourself!

How Leaders Can Govern AI, Reduce Risk, and Build Trust at Machine Speed | Patrick Sullivan

Summary Keywords

Speakers

In this episode of Executive Connect, Melissa Aarskaug sits down with Patrick Sullivan, VP of Strategy and Innovation at A-LIGN, TEDx speaker, AI ethicist, and member of the ISO committee helping shape international AI standards. Patrick explains why leaders cannot afford to treat AI as just another IT project and why governance, ethics, cybersecurity, culture, and strategy must work together.

The conversation explores the growing overlap between AI and cyber risk, the role of ISO 42001, the EU AI Act, unified compliance frameworks, and why ethical principles only matter when organizations can turn them into measurable practices. Patrick also explains why leaders should resist chasing technology simply because competitors are doing it.

The core message is simple: responsible AI starts with clarity. Leaders must define what they are trying to create, understand the risks and costs, and put the right checks, accountability, and governance in place before moving at machine speed.

Chapters:

(0:36) Meet Patrick and the race to govern AI

(1:32) What has changed most in technology

(3:27) Why basic cybersecurity still gets neglected

(5:35) What cybersecurity teaches us about AI risk

(6:30) How bad actors are using AI tools

(8:21) Balancing innovation with regulatory rigor

(8:53) Why innovation should happen incrementally

(10:52) Staying ahead while regulations evolve

(11:30) Building an operating system for AI governance

(15:39) What international AI standards are trying to solve

(16:03) Understanding the EU AI Act

(19:50) How global standards affect real AI systems

(20:08) The missing accountability in AI regulation

(23:13) What ethical AI actually looks like

(24:18) Turning ethics into measurable business practices

(27:21) Why AI governance cannot belong only to IT

(30:35) How culture changes when technology changes

(33:34) Why unified compliance frameworks matter

(35:48) The role of automation in compliance

(38:59) Building a practical unified compliance framework

(42:25) Bringing governance into innovation decisions

(46:06) Patrick’s advice for leaders facing rapid AI change

Patrick

(0:00) It’s a scary time we live in for leaders. (0:02) Things are changing so quickly. (0:04) The technical competence of some of the people that are rolling out these tools, it’s almost like we’ve got a thousand Einsteins in every organization that are rolling out new tools that we have really no concept of what’s happening.

(0:18) So first of all, yes, it’s absolutely scary. (0:21) Second, the only one that can do anything about it in your organization is you. (0:26) So stop.

(0:27) Think about, again, what it is you really want to create. (0:31) That has to take a point of primacy in anything that you do from here on.

Melissa

(0:36) Everyone loves talking about what AI can do. (0:39) Fewer talk about what AI should do. (0:42) And today’s guest does exactly that because almost nobody is volunteering to write those rules.

(0:50) Patrick Sullivan has spent more than 25 years in IT security and compliance and now serves as the VP of strategy and innovation at A-Line. (1:01) He’s a TEDx speaker, a member of the ISO committee shaping international AI standards and an advocate for ethical, practical governance in a world moving at machine speed. (1:15) If you’ve ever wondered who’s quietly deciding how AI gets built, how it gets audited, how it earns trust, this conversation is for you.

(1:25) Welcome, Patrick.

Patrick

(1:28) Melissa, thank you so much for having me. (1:30) I really am honored to be here.

Melissa

(1:32) And I’m excited to start to chat with you today because we sure need somebody to start writing these AI standards. (1:39) And I know you spent 25 years in IT security and compliance. (1:43) A lot’s changed in 25 years.

(1:46) So what’s changed the most and what hasn’t changed?

Patrick

(1:52) Oh, my goodness. (1:53) I think first, what hasn’t changed? (1:55) There’s this saying, there’s nothing new under the sun.

(1:58) And Melissa, what I see, and I think it very likely is the same for you, thematically, we’re still dealing with all the same stuff. (2:05) New technologies hit the market. (2:07) Some of those technologies are distributed, some are not.

(2:11) But executives are left forced to make decisions about working new technologies, emerging technologies into their business strategies. (2:20) And so ultimately, we still, just like we did 50 years ago, just like 100 years ago, have a pool of decision makers who don’t necessarily feel like they have all the information at hand that they need to make good decisions. (2:34) I think, again, thematically, that’s the same today, very likely be the same in the next 100 years.

(2:41) What has changed, I would say, would be the speed with which we are identifying, creating, innovating, and adopting new technologies. (2:52) Melissa, we’re at a pace now unlike anything I’ve ever seen before, with all the booms, the bursts, the winters, the summers. (3:01) What we’re seeing with AI, specifically, agentic AI, before it, generative AI, is unlike anything I’ve experienced in my career.

Melissa

(3:12) Ready to lead smarter and invest wiser? (3:16) On the Executive Connect podcast, we unpack executive strategies for wealth and influence. (3:23) Hit the subscribe button now.

(3:25) Don’t just watch, act. (3:27) I agree. (3:28) I absolutely agree with everything you said.

(3:30) But the simple truth is so many organizations still struggle with basic security hygiene, large and small. (3:39) A lot of time, we say, oh, we’re a small company. (3:43) We don’t have the budget.

(3:45) Only the big companies have the budget. (3:47) We’ve recently seen with some very large billion-dollar, $25 billion companies that are getting hit. (3:55) Why are organizations still struggling with this basic security hygiene?

Patrick

(4:02) Blocking and tackling is what I would say, Melissa. (4:04) As humans, we all recognize this concept of hedonic adaptation. (4:08) We do something new, it’s fun for a while, the fun wears off and we move on.

(4:14) Unfortunately, though we systematize, though we proceduralize, what I find is that traditional cybersecurity controls, protecting confidentiality, integrity, availability, those are the things that tend to lose focus and therefore lose budget more quickly than anything else. (4:30) They are not, in fact, the shiny penny, the shiny nickel that boards and investors want organizations to chase. (4:39) In many ways, and I don’t know if this is your experience, but in many ways, even today, we find CISOs and other executives fighting for the budget they know they need in order to offer the protections that the organization needs to really mitigate the risk in the market.

Melissa

(4:55) Yeah. (4:55) I love that you said that. (4:57) It’s so true.

(4:58) I just came from a conference and several of the C-suite leaders had let me know that they were decreasing their cybersecurity budget by 30% because they either, A, needed to add on to a casino or they needed to put the money in other things strategically. (5:18) My jaw, as it always has for the last several years, dropped because as we, to your point, how fast we’re moving, cybersecurity is changing drastically because of the use of AI. (5:35) What lessons have you learned early from cybersecurity that are applying to AI today and where do leaders underestimate this risk today?

Patrick

(5:47) I think the first and biggest lesson I learned early in my career is that calmer heads always prevail. (5:53) It can be very, very easy to jump to conclusions, to panic, to execute strategies that might or might not actually create the outcomes that we intend for them to. (6:05) So for the leaders listening, stop and think.

(6:08) Calmer heads will always prevail. (6:10) I think secondary to that, what we do see with such rapid adoption is that it’s not only the good guys that are adopting these technologies. (6:21) We also see bad actors adopting these technologies and, in fact, making better use of them than the people that are using them for productive gain.

(6:30) Big example, Claude Code. (6:32) I think everyone’s probably familiar with this platform at this point. (6:36) There have been two significant incidents of bad actors.

(6:40) In one case, a nation state. (6:42) In one case, I think it’s yet to be determined. (6:44) Regardless, where bad actors use that Claude Code platform to scan systems, vulnerable companies, create exploits for those companies, distribute those exploits, exfiltrate data from those companies, and then use the tool set itself to document everything that they did so that they could turn around and sell that package to other bad actors, which is just unlike anything I’ve ever seen before.

(7:09) But it’s common procedure. (7:12) It is the new model that we accept as we do accept continued deployment of specific AI tools. (7:19) It’s just a whole new world, Melissa.

(7:21) And it’s really cool to be here. (7:22) As dramatic as I make it sound, it’s really, really cool to be here.

Melissa

(7:27) Yeah, and I agree with you. (7:28) And I think the one thing I hear you saying and the one thing I do see is a lot of these kind of bad actors working together, collaborating, sharing in strategies, sharing in tool sets. (7:45) And then maybe they pick a sector, they’ve been successful in that sector, and they just copy replicate throughout that sector.

(7:54) And so I’ve seen this in my sector, which is casino gaming and gambling. (7:58) I’ve seen casinos being hit. (8:01) We’ve seen this in commercial casinos.

(8:03) We’ve seen this in tribal casinos. (8:05) We’ve seen this with gaming suppliers. (8:07) They figure it out at one casino, drive up the highway or down the highway one direction, try it on one.

(8:14) Maybe they have a little tighter security controls. (8:17) And they say, okay, it’s not worth it. (8:19) Let’s go to the next one.

(8:21) They drive another, you know, half an hour down the street to someone else. (8:25) And they get in and they’re just copy, copy, copy. (8:28) And so I want to talk a little bit about, you know, you’re the VP of strategy and innovation at A-Line.

(8:34) I love strategy, love innovation, because you’re balancing a lot with that. (8:40) You’re balancing innovation with the regulatory rigor. (8:44) So how do you do that effectively in the landscape that we’re living in right now, and as you mentioned, in kind of AI and security?

Patrick

(8:53) Yeah, and first principles, really, Melissa. (8:56) So many people think that innovation is about going from zero to one, to pull a phrase from Peter Thiel’s book. (9:04) It’s really not.

(9:05) Ultimately, when we think of innovation, we need to think of incremental gains over time. (9:10) It’s not the going from zero to one that’s most important for businesses. (9:14) But we’re not necessarily focused on creating new categories, which can be cool, can be really exciting.

(9:20) But doing that isn’t what gets us where we want to be. (9:24) What we have to focus on to innovate is where we can make incremental gains that offer leverage. (9:29) That is, in this incremental gain, we now have a mechanism to offer a little bit less input for more output on the back end.

(9:38) And that really is where our heads have to be as we’re creating our strategies. (9:43) A strategy is really just a mechanism, a way for us to think about charting a path through the unknown, nothing more, nothing less. (9:51) And so that strategy will be different for every organization, depending on their intended outcomes.

(9:57) Once we know what it is we really want to create, the goal is not to make significant leaps. (10:02) That’s inherently risky. (10:04) And that’s where people traditionally fall down.

(10:08) The goal has to be, once we know where we’re going, to make incremental gains, even if we have to grope our way forward, but incremental gains over time to create the value that we’re actually seeking to create. (10:19) So I know that seems like a very simplistic view, but in reality, that simplistic view is what gets things done.

Melissa

(10:26) Yeah, it’s so true. (10:27) I think I had the whole analogy, eat an elephant one bite at a time. (10:30) We’re not going to eat, you know, we’re not going to eat it all at once.

(10:34) And cybersecurity technology, however you look at it, it is something that is one bite at a time. (10:40) And as soon as you go to the next bite, something’s changed, some strategies changed, or some regulations changed, or, you know, we’ve got to get sharper with our tool set. (10:52) And so how do you, like, typically, historically, regulations lag technology, right?

(11:00) Because there’s so much politics, there’s so much that goes into regulations, state level, federal level. (11:07) So what happens is we’re ahead in the world of technology and AI, and the regulations are behind. (11:15) So talk to me a little bit, how you stay ahead, and kind of what you were saying, one bite at a time, how do you eat, you know, eat that elephant one bite at a time, stay ahead as regulations are evolving?

Patrick

(11:30) Yeah, and so regulations are critically important, but they’re just one external pressure on any organization. (11:37) We also have market pressure, we also have a vertical pressure that is industry-specific pressure. (11:44) Ultimately, what organizations have to do for themselves is find their operating system.

(11:51) One of the things that I do love about ISO are the various ISO management systems, which allow us to think about security through the information security management system, privacy, AI. (12:03) ISO has created a management system 42001 for AI management. (12:09) Ultimately, we’re through this management system, we have a known good structure for evaluating our entire AI life cycle.

(12:16) The cool thing about all of these management systems is that they’re first meant to be customized. (12:22) That is, every organization thinks about themselves in their context, that is, who are we, how do we create value, what markets do we interact in, who are we really. (12:34) Based on that, they have an opportunity, they, the organizations, have an opportunity to implement this methodology, this operating system, again, that allows them to take a risk-based approach to create value.

(12:47) So, through AI, we think about creating value, we limit risk and harms that could befall stakeholders of this community, we continue to grow and change over time. (12:56) One of the functions of these management systems, again, is thinking about external influences such as regulatory pressure. (13:04) And so, what we have to do, what leaders have to do, is not be led by regulatory pressure, but simply communicate regulatory pressure through their own management system.

(13:17) So, we create our goals, we create our targets, we create our action plan, and we consider regulation as part of that, not regulation drives us and puts us in a box limiting possibilities for our interactions with the market.

Melissa

(13:31) Money Ripples is on a mission to help professionals like you get their money working harder. (13:38) Their clients free up an average of $35,000 their first year without having to work extra hours. (13:46) To show you how, they’ve put together a powerful training called Cashflow Secrets, and as a listener of the Executive Connect podcast, you can get it completely free.

(13:57) Just visit moneyripples.com forward slash secrets and enter the promo code E-X-E-C. (14:07) Yeah, and I love that because I think it really ties back to your vision and your strategy as a company, where are we going and how fast can we get there? (14:18) And so, regulation is every part of that step in many different industries, whether it’s banking or healthcare or gambling, there’s regulation in every industry.

(14:28) And so, if we’re going from Arizona to Nevada, we need to know where we’re going and those things are going to be tweaked and turned. (14:36) But if we don’t know where we’re going and we don’t know the regulation we’re building it against, we can’t really build it. (14:41) And in a lot of industries, like specifically to my industry, we could be looking at NIST, and we could be looking at PCI, we could be looking at GDPR, we could be looking at HIPAA standards.

(14:54) If you’re a native tribe, you also have all of that, plus healthcare. (14:57) And so, it’s really important to make sure that you have a strong compliance program and somebody is leading that charge and you’re looking at that. (15:08) I’ve had the opportunity to review an organization’s policies where they never changed anything in the policy.

(15:15) They just kept adding and adding and adding and adding to the policy. (15:19) And they had these mega, mega large policies, but nobody was following them. (15:25) Nobody even really understood them.

(15:27) Nobody even talked about them. (15:29) And so, a lot of times when situations happen, people aren’t doing anything nefarious. (15:35) They just don’t even know what their policies are or what they’re supposed to do.

(15:39) So, let’s get into a little bit about international AI standards policies and talk a little bit about what are these problems or what problems are these standards kind of trying to solve? (15:55) So, when I think about the AI, the international AI standards, what are they trying to solve?

Patrick

(16:03) Yeah. (16:03) And I think right now, the elephant in the room for the global community as it relates to international AI standards is the EU AI Act. (16:12) And so, what we see is it’s official, but what is changing are enforcement dates specifically for high risk and general purpose systems.

(16:21) But ultimately, the AI Act is not necessarily about how we stymie innovation, how we regulate the development of AI as much as it is a product safety regulation. (16:33) And so, the EU has taken the approach, look, AI is really cool. (16:37) It’s really fancy.

(16:38) It’s almost magical. (16:39) I mean, it’s like the man behind the curtain in many ways. (16:43) But if we take a step back and think about this objectively, it’s just another product we’re placing on the market.

(16:50) And so, the EU regulation has set about to create standards associated with AI placement on the market that parallel exactly what we see with other product safety standards. (17:02) No different than a toaster, no different than a car, no different than any other, again, technology that we would place in that market, which I think is fundamentally upside down from what the position in the US is, which is AI is a technology that we must innovate. (17:19) We’re racing to improve.

(17:21) And if people get hurt along the way, it’s just the cost of doing business. (17:26) So, with the AI Act, we have to evaluate high risk systems before they’re placed on the market. (17:32) We have to have mechanisms to evaluate them once they’ve been placed on the market.

(17:36) And should we see that something is going wrong, this toaster is shooting nails for some reason, I don’t know why it would. (17:42) But yeah, just as an example, the toaster is not working as we expect, there have to be mechanisms to pull that product off the market. (17:50) That sounds easy, and it sounds really reasonable and really logical.

(17:54) What we struggle with though, and Melissa, you hit on this earlier, we are developing tools so quickly, we don’t necessarily have defined mechanisms to pull together the data that we need to make good decisions about what’s really happening post-market deployment. (18:10) So, I can deploy an AI model to the market, and we know that model will change over time. (18:16) It will grow, learn, adapt.

(18:18) We don’t necessarily have the tools to see start to finish what’s happening there and know when it is time to pull something from the market. (18:25) It’s not as discreet as nails being fired out of a toaster, unfortunately. (18:30) So, that’s one take on AI regulation.

(18:33) And that really is the take that I think is causing the most consternation globally, because the regulation applies not just to organizations that are headquartered in the EU, but any organization that’s delivering a service to that market. (18:47) So, even if I have a small output that could be used by EU citizens, I still need to consider the EU AI Act as part of my regulatory burden to some degree. (18:58) They approach this in a risk-based approach.

(19:03) So, some risk carries much burden. (19:06) Some risk carries little burden. (19:08) Nonetheless, it has to be a consideration.

(19:11) In the U.S., we initially took a state-by-state legislative approach to think about AI governance and AI risk mitigation. (19:19) Largely, those are stalled, because we do have an expectation based on recent announcements that there will be coming federal regulation, ultimately, again, with the goal of ensuring that nothing burdensome is put in place to stymie innovation of U.S. companies that are developing AI systems. (19:37) So, it really is this polar opposites approach to thinking about deploying AI to the market.

(19:43) One is focused on safety and consumer safety. (19:46) One is focused on innovation at almost all costs.

Melissa

(19:50) Yeah. (19:51) And we are such a global – in business, we are working with global standards, however you look at it, all the time. (20:01) And so, how do these standards affect real-world AI systems?

Patrick

(20:08) Yeah. (20:09) And so, to say this plainly today, there have been no – there have been no cases where organizations have been penalized for failure to meet the obligations of the EUAI Act. (20:25) In the U.S., to my knowledge, there have been no cases of states that have existing legislation, those state attorneys general, using that legislation as a mechanism to enforce penalties on any company. (20:39) So, ultimately, where we hope to have some sort of accountability – accountability is completely absent today, Melissa. (20:48) And so, as I think about global regulations specific to AI, that really is the glaring weakness. (20:56) You open this up by saying lots of smart people are working on creating these standards, the standards in foreign regulation.

(21:03) Ultimately, the missing piece is accountability. (21:06) Leaders have to know that there is skin in the game, and today, there’s no mechanism to make that plain.

Melissa

(21:12) And I’m going to tie it back to cybersecurity, because it was the same with cybersecurity. (21:16) It was – we saw a lot of regulation around requirements for security, whether it be PCI, whether it be who’s liable when there is a breach. (21:29) Insurances were paying back to their policyholders, and now they’re questioning it.

(21:36) I’ve seen, in cybersecurity alone, the due diligence forms used to be a page when I got started in cybersecurity for cyber policies. (21:45) And now, there are many pages, and the insurance companies are checking up on these big corporations now. (21:51) And so, I think the lag is similar that it was in cybersecurity, that regulators weren’t finding, but they are now.

(22:00) They’re staffed up. (22:02) They’re aware. (22:02) They know what the regs are.

(22:04) They know what they need to be looking. (22:05) And so, I do see a world where we’re going to get there faster. (22:09) I would say faster than we did in the world of favors.

Patrick

(22:15) It’s so funny, the analogies you bring up to PCI. (22:18) I think you mentioned HIPAA. (22:19) Maybe not, but I think HIPAA and its enforcement through the Office of Civil Rights here in the U.S., prime example. (22:28) So, we have known for years that OCR did not staff enough auditors to actually audit organizations. (22:35) And so, largely, OCR has been driven by organizations that recognize that something went wrong and voluntarily reported. (22:43) That’s not true across the board.

(22:45) There have been specific instances where OCR has found what they consider to be willful neglect and certain breaches, certain disclosures. (22:54) But by and large, we have a regulation that requires on the community to self-police. (23:00) And in many ways, globally, that seems to be where we are today.

(23:04) But we have to openly acknowledge what we have today is not what we’ll have tomorrow. (23:10) And we have to really begin preparing for tomorrow.

Melissa

(23:13) Yeah. (23:13) And we need to take pride in the work, too. (23:17) I think we talk a lot about ethics, right?

(23:21) And I think we all have a certain responsibility to not just our staff as a company, but we have a responsibility to the people that buy our products and services to protect their information, to protect their data, to make sure we’re doing things ethically. (23:41) And I love, I think, and maybe this is just my opinion, but I feel like the word ethics has become a buzzword a lot. (23:51) We’re like, we’re ethical and we’re doing this in this capacity.

(23:55) But you’re actually known as an AI ethicist. (24:00) So, talk to me a little bit about that and ethics as a buzzword and what does it actually look like inside an organization to deploy AI ethically across all different businesses?

Patrick

(24:18) Yeah. (24:19) And what I would say is ethics as a study, traditionally, you’ll see being a derivative of philosophy. (24:26) So, you’ll see a lot of philosophers migrating toward AI ethics.

(24:31) Ultimately, the entire practice, the entire exercise is focused on ensuring that we are doing the right thing. (24:40) And the right thing is very subjective. (24:42) What’s the right thing for me might not be the right thing for you.

(24:46) But as a community, the goal is to determine what the right thing to do is with these emerging technologies, specifically AI. (24:54) Melissa, what I would say is doing the right thing is incredibly squishy. (24:59) It’s easy to say, we’re going to do this, we’re going to do this, we’re going to do this because it’s the right thing.

(25:05) But then when I ask you to do what any reasonable executive would ask you to do, which is measure and show me your progress against doing the right thing. (25:15) Suddenly, when we’re left with taking what’s squishy to something very empirical so that we can show progress and discrete improvement, suddenly we struggle. (25:25) And so right now, for the ethicist community, one of the biggest challenges is helping organizations understand how to actually take these lofty goals, these principles, and convert them into practice.

(25:38) Much like we saw with Kaplan and Norton’s balanced scorecard years ago, where we had these ideas, these ethical things that we wish to create, and we had to walk the process of converting them into metrics that we could measure against and take practical action on. (25:55) Today, the ethicist community that is, is very much in that mode. (26:01) How do we take this and make it something that organizations can actually be motivated to take action on in a meaningful way?

(26:10) But Melissa, again, it’s about how do we do the right thing with these tools so that we, almost like the Hippocratic Oath, first do no harm. (26:20) First, let’s make sure that we’re not harming the humans that are part of this process. (26:25) Then what else can we do so that we aren’t violating or impairing either liberty or fundamental human rights?

Melissa

(26:32) Yeah, and I love this word for ethics. (26:34) It’s one of my favorite words. (26:35) Transparency often helps with ethics.

(26:39) It sounds so elementary, but it’s so true. (26:44) I want to talk a little bit about where organizations get ethics wrong and how do you operationalize ethics? (26:58) Because a lot of times these discussions we’re having has historically sat with IT.

(27:05) It has often been hard sometimes because IT, not that they’re not transparent, they’re just in their own space, right?

Patrick

(27:19) Well, you’ve been there. (27:20) You know what this is.

Melissa

(27:21) Yes, I see it regularly. (27:23) How do we make this more of something that is part of every piece of an organization?

Patrick

(27:32) And it requires input from every piece of the organization, Melissa. (27:36) That would be where I would say to start. (27:38) And that would be where I see organizations that fail, failing first.

(27:43) We create these ethical guidelines, these ethical statements. (27:47) Again, this principle that when we actually begin digging under the hood and get input from people that need to implement it, we find out these things sound cool, but there’s absolutely no way to implement them practically. (28:01) Either the technologies don’t exist, the processes don’t exist, whatever the case may be.

(28:07) And so I think first and foremost, if we consider that AI is a (28:10) socio-technical system, which it is, a system made up of lots of technology that’s really cool, (28:16) but also lots of humans with lots of different perspectives, lots of different positions (28:20) in the hierarchies, we have to work with all of those, or as many as are practical, (28:27) all of those perspectives with the technology to create what would be principles, but then now (28:34) become practice.

(28:36) And so start there. (28:38) Start with ensuring that you have appropriate representation from everywhere inside your organization that makes sense, to be sure that your organization is actually creating ethical statements, ethical practices that can be implemented and serve the organization itself. (28:53) I mean, at the end of the day, businesses are amoral.

(28:55) They’re neither good nor bad. (28:57) Businesses exist to bring value into the world. (28:59) Hopefully you create more value than you consume, then everything is right.

(29:03) We have rainbows, we have unicorns, the whole nine yards. (29:07) In doing that, we just need to ensure that we are bringing value in a way that’s sustainable and harms no humans in the process.

Melissa

(29:16) Yeah. (29:16) And I’ve heard this line, I don’t know, I would go out on a limb and say hundreds, maybe even thousands of times in the last 10 to 15 years. (29:28) Oh, that’s the IT department.

(29:30) Oh, that’s the IT department’s responsibility. (29:33) Or, oh, my IT department handles that. (29:36) And so I think to your point is if you’re a CEO of a business or a board member or a leader, it’s imperative that we talk about this across HR and marketing and operations and IT and every piece of the organization.

(29:53) And I think the saying, see something, say something, I’ve had and heard of people seeing things happen and not doing anything about it for fear of bringing it up or getting in trouble. (30:06) And so when you have an organization that understands that it’s everyone’s responsibility to protect the organization, it’s everyone’s responsibility to be ethical, to follow the policies, I think it’s a cultural thing. (30:22) And so a lot of times, it starts at the very tippity top of the organization.

(30:27) And if the CEO truly believes that it’s an IT problem, so will everybody else in the organization.

Patrick

(30:35) It’s funny you say culture. (30:37) So I’ve seen a few different definitions of culture. (30:39) I’m sure there are textbook definitions that are absolutely perfect.

(30:42) I don’t have that. (30:43) But one definition I’ve seen is that culture is a group’s collective attitudes and behaviors, which is cool. (30:51) Another definition I’ve seen is that culture is the relationship between people and the organization.

(30:57) And so between those two elements, we’ve got this dynamic interconnect, like an invisible rubber band, wherein they pull on one another. (31:06) And so as an organization changes, so too must the people in the organization, else we see rifts in culture. (31:13) And ultimately, that has to be a consideration as we are deploying new tools, because again, it’s a socio-technical system.

(31:20) We can’t implement new technologies without implementing people or without changing people. (31:26) And as we change people, that relationship between the people in the organization changes, which means by default, our culture must change. (31:34) Our culture must adapt if our organization is to do so as well.

Melissa

(31:38) Yeah. (31:39) And not that I’ve ever been against culture or having a great culture, because I’m very much for it. (31:45) But I’ve seen some of the most well-working group of people.

(31:52) And why do they work so good together? (31:55) I have a very small team. (31:57) And the amount of millions of dollars that they run with a very small under-100-person team, I was blown away.

(32:06) I just had this recent experience where I was talking with a company that was a little under $100 million a year. (32:15) And they had under-100 employees generating that much revenue a year. (32:20) And it was like $80-something million a year.

(32:22) And talking to their CEO, he’s like, well, it’s really simple. (32:27) It’s culture. (32:29) Everybody is all in with the right attitude.

(32:33) And they understand what they’re supposed to be doing. (32:35) They’re in their zone of genius. (32:37) And when that happened, the machine works.

(32:41) And I’ve seen the same size revenue companies with seven times the amount of people. (32:48) And so I think culture is there’s so much to this culture thing from a business standpoint, a money standpoint, and a security standpoint. (32:58) And the companies that I was mentioning earlier that were skipped in this kind of highway of casinos that had cyber incidents, when I look and I open the hood of it, those organizations had their cyber culture right.

(33:16) And everybody knew what the rules were. (33:18) They were testing them. (33:19) They were practicing it.

(33:21) Everybody understood. (33:23) And so kind of tying this back to compliance frameworks, because this is also a compliance, a policy, a clarity piece. (33:34) So you’ve been recognized for unified compliance frameworks.

(33:38) Why is this approach becoming so essential?

Patrick

(33:43) And really and truly, as we think about harmonizing compliance frameworks via whatever mechanism, ultimately what we’re doing is removing noise from the signal, but we’re dialing in on real signal. (33:57) We’re mitigating the noise so that people within our organization can focus on what’s most important at the time. (34:05) And you know, Melissa, you talk about culture and speed.

(34:08) Stephen M. (34:09) R. (34:09) Covey, Stephen Covey’s son, wrote a book a few years ago called The Speed of Trust.

(34:14) I don’t know if you’ve read it. (34:15) For our listeners, I don’t know if you’ve read it. (34:17) You should.

(34:18) But in that, Covey outlines a simple formula. (34:21) On one side of the formula is trust. (34:23) And so trust sits in a position that when trust is present, speed inevitably goes up, speed to value creation, and cost inevitably goes down.

(34:39) And so there’s a direct relationship between trust and speed. (34:42) In low trust organizations, speed is low, cost is high. (34:46) In high trust organizations, speed is high, cost is low.

(34:50) And ultimately, that’s what we have to create. (34:52) And so in the presence of a group of humans, (34:54) a group of people that are working together, that trust one another, that have psychological safety, (34:59) that are prepared to be vulnerable in this creation process, what we want to do is remove (35:04) noise from what it is that they’re focused on, which is exactly where, to your point, (35:10) this harmonization, this crosswalk of compliance requirements and controls has to be dialed in for (35:17) the organization. (35:18) And that really is, though the leaders listening might not necessarily recognize (35:22) that you have an influence on this, that you have skin in this game, you have to ensure that your (35:28) posture from a compliance perspective is situated in such a way that you’re focused on only those (35:34) things you must focus on and excluding everything else for the benefit of your people so that that (35:40) speed to market, that speed to value creation continues to increase as your cost goes down.

(35:46) That is an absolute must.

Melissa

(35:48) And talk to me a little bit about what automation plays in compliance.

Patrick

(35:55) Oh my goodness. (35:56) So automation plays a role essentially everywhere today. (35:59) I mean, we’ve seen some really good examples of automation and pulling data from APIs and emailing users to ensure certain checklists are completed.

(36:12) So all those areas that we can think of automation being beneficial to our standard practices, yes, AI is providing that for us. (36:22) We’ve seen some really bad examples too. (36:24) I think for those that are kind of in this community, Delve, a GRC platform recently has been accused of some pretty nefarious things.

(36:35) We’re in under the guise of AI and automation. (36:39) They were simply rubber stamping, allegedly rubber stamping, sought to reports and one certifications. (36:48) And so automation can play a role in undermining the trust that our people have and that our markets have in us as an organization.

(36:57) So automation is a tool is something that we have to proceed with caution, proceed with, with caution, because ultimately we can automate benefit. (37:06) We can automate detriment. (37:08) It really will just be a matter of the effort that we put into planning and thinking before pulling those triggers.

Melissa

(37:14) This episode is sponsored by Texas Freedom Fund. (37:19) If you’re an accredited investor looking to protect your purchasing power, reduce taxes, and own real Texas energy assets, listen up. (37:29) The Texas Freedom Fund invest in proven oil and gas projects in the Eager Ford shale with no debt and strong tax advantages like intangible drilling costs applied against active income.

(37:42) Minimum investment is $25,000 and the sponsor invests right alongside every single deal. (37:49) Learn more at texasfreedomfund.executiveconnectpodcast.com. (37:55) Energy opportunity and Texas grit working for your portfolio.

(38:01) Yeah, I absolutely agree with that. (38:04) I think, you know, when I think about compliance or regulation, there’s so many frameworks like we talked about a little bit. (38:15) And so I often find, and I hear this a lot from CISOs or CIOs, that they’re frustrated sometimes about the requirement from, you know, the regulator, these kind of checkbox exercises, what they like to call them, versus operations, allowing them to get the budget to do the work, or their vendors who are not compliant.

(38:45) And doing their kind of due diligence, their security assessments, their, you know, PCI assessments, you know, whatever it may be. (38:55) And so I think there’s a lot of frustration a bit. (38:59) And so how should leaders approach building a unified framework?

Patrick

(39:06) So I would say, seek first to understand. (39:09) Melissa, I totally agree. (39:11) There is significant frustration in the market, particularly for organizations that are working in multiple verticals that might have multiple vertical specific requirements that are handling multiple data types.

(39:24) So now we’ve got considerations around EPHI and HIPAA requirements to your point cardholder data, PCI requirements. (39:32) Then you layer in the fact that most organizations today are global. (39:36) And so now we have regulatory requirements from regimes that we might or might not directly interact with, but we’re serving customers in those areas.

(39:46) So for leaders, seek first to understand what is it that these regulations are really asking you to do? (39:52) Not from a technical perspective, not from a controls perspective. (39:55) That’s how we get bogged down.

(39:57) That’s how we feel like we have to boil the ocean. (40:00) But from a conceptual perspective, what is it we’re really trying to accomplish? (40:05) With that in mind, what we have to do is map the requirements of those various obligations against what it is we actually do.

(40:14) So these requirements apply, but in our context, how do these requirements apply? (40:20) I think those have to be the first steps because regardless of our opinion on the matter, if there’s a regulation in place that we’re bound to, at some point we’re going to be held accountable to that regulation. (40:32) So let’s form a healthy relationship with that obligation rather than one of my kids when I tell them that we’re not going to turn the TV on tonight.

(40:40) I mean, there really is a better way to approach creating our compliance strategy more than just frustration or simply resolving ourselves to this as a checkbox exercise. (40:50) Because for those leaders that allow the checkbox exercise to be their compliance strategy, I promise you, you will be burned. (40:58) At some point, it could be small, could be big, something very bad will happen because you haven’t taken ownership of really understanding what your position here is and driving your organization forward.

(41:11) Everything starts from the top and works its way down. (41:15) That said, this even needs to start with you and your perspective on how you’ll maintain really compliance with your obligations in the global market.

Melissa

(41:25) Yeah, it’s so true. (41:26) And I think if we think with the end in mind, because AI is becoming more regulated, it’s not, you know, it’s not if it’s when, right? (41:36) It’s so getting organized and getting prepared for that end game.

(41:41) And what we need to get to that end game. (41:44) That’s, you know, maybe we can’t get it all done in a year because it’s not budget, we don’t have the time, but at least know where we’re going. (41:52) And so I think we really need to change that mindset a bit so leaders can innovate responsibly and build an ethics.

(42:02) But kind of what you were mentioning at the beginning, everything is so difficult when we’re, the speed is so fast. (42:10) So we have speed with responsibility. (42:14) Sometimes those two don’t work hand in hand, if there isn’t a plan and there isn’t a strategy and we really need to bring in the cultural side of it.

(42:25) And so how do you, you know, in thinking about that, like how, you know, what role does data come into this or governance play in this innovation? (42:37) So how do we bring governance into the innovation discussion?

Patrick

(42:41) Well, and I’m so glad you bring governance up because governance can be very confusing if we allow it to be, it doesn’t have to be. (42:49) So governance is essentially a value creation process. (42:53) What you’ll see across the board references to governance, be it through COBA, be it through traditional ISAC of LIT, even ISO takes the position that governance is a value creation process wherein we seek to create desired outcomes at optimized risk and cost.

(43:10) Not completely eliminate risk, not completely eliminate cost, but based on what it is we say we want to create, how can we optimize the risk and cost in doing so? (43:20) And so I think that simple framing for leaders has to be where it starts. (43:24) Really and truly, we’ve got three things to consider.

(43:27) The hardest part, and this sounds so crazy to say, Melissa, I don’t know if you see this as well, but the hardest part is getting leaders to clarify succinctly what it is they want to create. (43:38) Why are we doing this? (43:40) Well, it just makes sense, the work it’s asking.

(43:42) But really, why are we doing this? (43:45) What specifically are we hoping to create by deploying this tool, this process, this framework? (43:51) Next, with that stated, in our context, what risks do we have and how can we optimize them?

(43:58) And what costs, what financial burdens are we going to take on that we need to consider as part of this process? (44:04) I think simply working through that exercise mentally can position leaders to begin making really good decisions before anyone else gets involved. (44:14) I mean, ultimately, it’s up to the leaders listening to say, yes, this is something we want to pursue versus no, this is not.

(44:21) And every yes must be defended by a thousand no’s. (44:24) We know that. (44:24) That’s just what it is.

(44:26) So let’s say yes to the right things.

Melissa

(44:29) Yeah, it’s so true. (44:30) I think, you know, when I think of, you know, like you’re mentioning SOX2 or ISO, if we’re going to, you know, move our company in that direction, it’s not an overnight thing. (44:42) And if you have not had, you know, a strategy around governance and all of a sudden one day you wake up and you want to, you know, become, you know, PCI, ISO, GDPR, whatever the framework may be, it doesn’t happen overnight.

(45:00) And we need a strategy and we need a budget and we need leadership buy-in. (45:06) We need to know who’s going to be running with it. (45:09) There’s a lot of pieces.

(45:11) And, you know, the, this number changes all the time, but, you know, I have several friends that sit in, you know, important seats for billion dollar companies and their job is to, you know, move their company forward with AI transformation projects. (45:26) Yet the only reason they’re doing it is because their competitors is doing it and they’re telling their CEO, well, why are we doing it? (45:34) Well, you know, our other company is doing it.

(45:37) We should be doing it. (45:38) Well, that’s the wrong reason to be doing it. (45:40) So back to kind of what you were saying, why are we doing this?

(45:44) What is the reasoning behind doing this strategy? (45:49) Because it’s, it takes time. (45:51) It takes money.

(45:53) And could that money be put in other places? (45:55) I don’t know. (45:56) It’s a business decision.

(45:58) And so I want to, in closing, get kind of any, you know, final thoughts or anything you want to leave with our listeners before we close up.

Patrick

(46:06) Yeah, I would say, well, first of all, in open recognition, it’s a scary time we live in for leaders, Melissa. (46:12) There’s no way around it. (46:13) Things are changing so quickly.

(46:15) The technical competence of some of the people that are rolling out these tools, it’s almost like we’ve got a thousand Einsteins in every organization that are rolling out new tools that we have really no concept of what’s happening. (46:30) So first of all, yes, it’s absolutely scary. (46:34) Second, the only one that can do anything about it in your organization is you.

(46:38) So stop. (46:40) Think about, again, what it is you really want to create. (46:43) That has to take a point of primacy in anything that you do from here on.

(46:49) What do we really hope to create? (46:50) With that in hand, you can think about risks and costs associated with creating this and determine if there really is a business case. (46:57) Do we intend to commit to this?

(46:59) If we do intend to commit to this initiative, let’s put all the checks and balances in place that we would any other business case. (47:07) Let’s know when it’s time to exit. (47:08) Let’s know how we evaluate.

(47:10) Let’s know who’s involved in decision making. (47:13) All those things that are traditional parts of other new service or value creation in our organization apply to what we’re doing with AI. (47:21) We just have to step back and recognize that that’s true.

Melissa

(47:24) Yeah, I agree. (47:25) So AI doesn’t just need builders. (47:28) It needs architects of trust, right?

(47:30) People who understand not just what the technology does, but what it should do and how it should be governed. (47:37) And so thank you so much for being here and sharing your knowledge in time with our listeners. (47:44) If you enjoyed this episode of Executive Connect, make sure to follow and share it with your leaders who are navigating AI compliance and innovation.

(47:53) Connect with Patrick and for more conversations on technology, governance, and the future of leadership, subscribe to our YouTube channel and or your favorite podcast platform. (48:04) That’s the Executive Connect podcast.

Modern Maverick Test:

What Kind of Maverick Are You?

Break Free. Design Your Legacy. Discover your unique Maverick mindset.

Instructions: Read each statement below and rate how strongly you identify with it on a scale from 1 to 5:

Contact Us: Renaissance Workshop Interest Form

Preorder RENAISSANCE: Redefining Success for Modern Mavericks

Executive Connect Podcast Guest Release Form

This guest release is entered into between Stronger to the Executive Connect Podcast, “Podcaster” and “You”, “Guest” or individually “Party”.

As a Guest of the Executive Connect Podcast (“Podcast”), I consent to the audio and video recording of my voice, name, and image as part of my appearance on the Podcast. I further consent to the distribution and broadcast of my appearance, including any information and content I provide, by Teri Schmidt (“Podcaster”) in audio, video, or text form without restriction.

I further acknowledge and agree:

  1. I will receive no monetary compensation for my appearance. The consideration I receive for executing this release shall be the exposure I receive to the audience of the Podcast.
  2. I am granting the Podcaster a non-exclusive, royalty-free, perpetual, worldwide license to publish any copyrighted work I supply as part of my appearance on the Podcast.
  3. I am waiving any intellectual property claims including, but not limited to, trademark and copyright infringement claims, associated with personal or business interests discussed during my appearance on the Podcast.
  4. I am waiving any right to publicity and privacy claims, and agree my name, likeness, and business information may be used by Podcaster in the episode in which I appear and future reproductions as well as the marketing materials supporting the Podcast in general.
  5. That Podcaster is the sole owner of any and all rights to the Podcast, including the episode in which I appear. I further acknowledge and agree that Podcaster has the right to edit the content of my appearance and publish the same in any media now and in the future without first obtaining my approval.
  6. I am releasing and discharging Podcaster together along with all of the Podcaster’s principals, shareholders, officers, employees, agents, successors, and assigns from any and all liability arising out of or in connection with my appearance on the Podcast or the subsequent reproduction and distribution of the episode in which I appear in any medium.
  7. Execution of this Agreement does not obligate Stronger to Serve Coaching and Teambuilding, LLC to publish your presentation or other materials.

Podcaster grants Guest a royalty-free, worldwide, license and right to publish the Podcast episode in which Guest appears on Guest’s website or app and promote said episode in all of Guest’s social media accounts.

Bryan Hancock Headshot — Founder of Integrity Development

Bryan Hancock

Founder of Integrity Development

Integrity Development

Executive Biography

Bryan Hancock has been managing real estate investments—and overseeing development and construction projects—for nearly two decades. He has deep roots in Austin, Texas, and comprehensive knowledge of the opportunities and challenges in this fast-growing market.

Through his development and syndication companies, which he built from the ground up, Bryan has developed 50+ urban infill projects and managed $25M in real estate sales with approximately 35% return on investment at the project level. He also co-founded two private equity funds.

Bryan brings in-depth industry awareness, sharp business acumen, and extensive in-the-trenches experience to his work as co-founder and principal of Integrity Development. He partners with a team of professionals and industry experts (many have been involved in Austin real estate for 40+ years) to identify value-added and opportunistic investments that protect capital and reduce risk for lenders—while delivering outsized returns for investors.

Earlier, Bryan founded and directed Inner 10 Development, a residential development firm focused on Austin’s top zip codes and surrounding communities, and H2i, LLC, a real estate syndication company. He steered these organizations for 17+ years, overseeing the acquisition, buildout, and sale of single-family and multifamily properties, including a 350-unit urban infill joint-venture project.

Bryan was successful in delivering strong returns while minimizing risk for bankers and investors by taking a targeted, data-driven approach to opportunity analysis, due diligence, and strategic decision-making. He zeroed in on potential risks and developed proactive mitigation strategies to protect and grow investments.

Concurrent with his work at Inner 10 Development and H2i, Bryan established Gentry Lending Group, a private-equity debt fund. He also served on the board of Bullseye Capital Real Property Opportunity Fund. These experiences provided Bryan with a grasp of both investor and banker viewpoints, including an understanding of risk and liability on the lending side. This aspect of his background continues to shape his real estate decisions to this day.

There is another unique aspect to Bryan’s career—a corporate history that differentiates him from other investors and developers in this field. Bryan has built organizations, controlled multimillion-dollar projects, and supported billion-dollar programs for some of the world’s largest companies: Lockheed Martin, Microsoft, Dell, CACI, and Charles Schwab. He managed teams and vendors in the US, China, France, and India, and often balanced up to 10 projects at a time. He was trusted with a Top Secret Security Clearance from the United States government.

A business-savvy leader and lifelong learner, Bryan holds an MBA in Finance and Entrepreneurship from Texas Christian University and a Bachelor of Science in Electrical Engineering from the University of Texas at Austin.

Bryan founded the Wealth Investment Network, co-founded RealStarter (a crowdfunding platform for real estate investors), and was a member of the Urban Land Institute and Central Texas Angel Network. He has been a guest speaker at 20+ national events, including conferences and meetups through the Information Management Network (IMN), SXSW, Rice University, Bay Area Real Estate Summit, Soho Loft Conference, Texas Entrepreneur Network, and many others.

Featured In

Melissa Aarskaug Headshot — Founder of Executive Connect

Melissa Aarskaug

Founder of Executive Connect

Senior Executive, Board Member & Advisor

Vice President of Business Development
Bulletproof, a GLI company

Executive Biography

Melissa Aarskaug is a global executive and business leader at the forefront of the technology/cybersecurity industry. She shapes strategy, leads teams, and partners with Fortune 500 companies and other enterprise clients to protect their organizations from risk and noncompliance—while improving operations and accelerating growth.

For 15+ years, Melissa has taken the reins to propel organizations to the next level of performance. By combining business acumen and revenue optimization with the sharp mind of an engineer, she uncovers and seizes opportunities for profitable growth in the US and around the world.

Melissa has established a distinguished career with Gaming Laboratories International (GLI), where she is a key member of the senior executive team. Throughout her tenure, she has assembled teams, developed new markets, and influenced P&L impact, ultimately positioning GLI as the #1 provider of testing, certification, and cybersecurity services to the global gaming and lottery space.

After achieving this feat—a big win for GLI and game-changer for clients worldwide—Melissa steered both GLI and Bulletproof (acquired by GLI in 2016) into untapped verticals: finance, government, healthcare, higher education, hospitality, and retail. An enthusiastic, knowledgeable growth driver who cultivates partnerships and rallies teams, she led GLI/Bulletproof to dominate these markets as well.

Before joining GLI, Melissa shaped and executed strategy as Vice President of Business Operations for LV Investments, where she built and optimized a portfolio of commercial and industrial properties. Earlier, in a very different role as Project Engineering Manager for Fisher Industries, she directed and mobilized a team of 550 employees and contractors to develop the world’s largest concrete bridge. Previously, she headed a major engineering project for Pacific Mechanical Corporation.

A curious, lifelong learner, Melissa holds dual Bachelor of Science degrees in Civil and Environmental Engineering with minors including Business and Mathematics. She is a Karrass Master Negotiator and C4 Executive Coach who actively pursues ongoing education and inspiration as a member of Chief, Austin Technology Council, Austin Women in Technology, and Toastmasters International. In addition to her own personal and professional development, Melissa is committed to helping other people thrive both inside and outside of the workplace. She actively mentors and empowers team members at GLI/Bulletproof, and is an executive leader and coach for Global Gaming Women. She founded Young Nonprofit Professionals Network (YNPN) Austin and is a current or past board member of many organizations, including Emerging Leaders in Gaming, Ballet Austin, Texas School for the Blind & Visually Impaired, the Society of Women Engineers, and the American Society of Civil Engineers. She has been a Junior League volunteer in Austin, Las Vegas, and Reno for 15+ years.

Throughout her career, Melissa has inspired individuals, teams, and entire organizations to think differently about innovation, cybersecurity, leadership, and business development. She was honored as one of the “Emerging Leaders in Gaming: 40 Under 40” and she continues to share her ideas and expertise through publications, podcasts, webinars, and presentations.

Featured In

This is the Executive Connect

A show for the new generation of leaders. Join us as we discover unconventional leadership strategies not traditionally associated with executive roles. Our guests include upper-level C-Suite executives charting new ways to grow their organizations, successful entrepreneurs changing the way the world does business, and experts and thought leaders from fields outside of Corporate America that can bring new insights into leadership, prosperity, and personal growth – all while connecting on a human level. No one has all the answers – but by building a community of open-minded and engaged leaders we hope to give you the tools you need to help you find your own path to success.