SBN

TrustCloud raises $15M to accelerate GRC Transformation for enterprise CISOs

When I speak to enterprise CISOs and GRC leaders, they often talk to me about 2 problems:

  1. “Every GRC product we have purchased makes us feel like servants to the product. We are stuck spending countless manual hours working for the product:”
    Solution: We want a product that works for us.
  2. “Enterprise GRC is complex. Nobody has created automation that solves this complexity, and as a result, we revert to manual work that is very ‘check-the-box’.  We don’t trust the results.”
    Solution: I need a solution that gives me automated assurance that I trust.

Today we unlocked a huge milestone for TrustCloud that will help us scale operations to solve these 2 problems for enterprise CISOs and GRC leaders.  We’ve raised $15M in strategic funding led by ServiceNow Ventures, with participation from Cisco Investments, Presidio Ventures, OpenView Venture Partners, Tola Capital, and other existing investors. (Read official press release)

The funding comes on the heels of a banner year of growth with new enterprise and mid-market customers, and will be used to further accelerate enterprise go-to-market and channel operations, while enhancing our AI capabilities to provide enterprise CISOs with a unified view of security risk across the IT landscape.

The enterprise challenge with legacy GRC vendors and Trust Management startups

Legacy GRC vendors, and new compliance automation and ‘Trust Management’ startups struggle to solve four areas of enterprise complexity – which are fundamental requirements to move enterprises from manual check-the-box to delivering ‘accurate assurance’ for CISOs and GRC leaders.

  1. Automation fails when enterprises have custom controls, risks, compliance standard requirements:  Automation is easy for simple controls, risks, and standards. Automation, especially accurate automation, is VERY difficult when every enterprise has built their own custom program. I have heard feedback from hundreds of enterprises and mid-market companies that their current vendor landscape fails when solutions are custom, forcing compliance automation back into manual mode due to complexity.
  2. Inability to handle inconsistent security maturity levels across BUs:  An enterprise is made up of many products, BUs (business units), and geographies. Every segment of the enterprise has a different security and privacy maturity level. A one-size-fits-all approach, that current GRC vendors take, doesn’t work. Most modern compliance automation and Trust management startups are very opinionated because they architected their products to meet the needs of cloud-native businesses that can all achieve a uniform and standardized security and compliance posture. This design strategy doesn’t work with complex enterprises because enterprises need a significant amount of flexibility to dictate different security postures and standards for different BUs. This results in a Trust Management startup vendor’s solution failing enterprise practitioners — forcing CISOs and GRC leaders to revert to using spreadsheets.
  3. Lack of support for fragmented and hybrid IT environments:  Legacy GRC vendors often can’t integrate and analyze data from IT, business, and security tools. Compliance automation and Trust Management startups can often only implement simple integrations and data collection from cloud-native tools. The moment an enterprise is hybrid and/or an enterprise has legacy security and IT tools with complex data and business rules that need to be extracted and analyzed, all bets are off. Enterprise practitioners are stuck with taking screen shots and performing risk assessments manually again.
  4. Can’t automate the work in complex security and GRC workflows:  Enterprises have built complex workflows over time.  Legacy GRC vendors are fantastic at creating and supporting these workflows manually.  But, they cannot automate the work in these workflows. What is an enterprise to do?

Security Assurance

Bye-bye Governance, Risk, and Check-the-Box (GRC).

Hello Security Assurance

We took a very different approach at TrustCloud.  We built and launched 3 key capabilities to solve enterprise complexity and deliver accurate assurance — we call it ‘Security Assurance’.

SECURITY ASSURANCE:  PURPOSE-BUILT AI FOR GRC TRANSFORMATION

TrustCloud’s security assurance platform is purpose-built to empower CISOs to work with chief risk officers (CROs) to take clear, informed action and implement better, data-driven decisions to protect their organization. The company’s AI- and API-driven automation transforms traditional GRC by slashing costs, increasing accuracy, and simultaneously turning GRC into an enabler of the business that reduces financial liability and accelerates revenue.

TrustCloud differentiators

To accurately automate first-party and third-party risk and compliance assessments for hybrid enterprises, TrustCloud’s Security Assurance platform delivers 3 unique pieces of functionality:

  • Hybrid Data Fabric:  Data lake that leverages 100+ data integrations to SaaS tools and an SDK to push data from on-premises environments to aggregate IT, business, security, and GRC data into a single source of truth.  Hybrid Data Fabric uniquely allows enterprises to support data collection from hybrid environments, aggregate structured, unstructured and document-based data, and store data in any schema or relationship format to automate the verification or any custom control, governance and risk requirements.
  • Continuous Control Monitoring (ConMon) on a Control Graph:  For enterprises that want accuracy and assurance, TrustCloud’s belief is that the only way to achieve both is to power risk, compliance and governance assessments using a foundational continuous control monitoring (ConMon) engine.
    • TrustCloud’s ConMon engine delivers continuous control assurance on top of proprietary AI-driven relationship models that intelligently graph and continuously test controls to multiple security, GRC, and business artifacts. This allows TrustCloud to analyze and test the impact of every IT, security and business change, and make recommendations to prioritize actions based on potential risk.
  • Assurance AI:  Purpose-built ML and NLP models enhanced by retrieval-augmented generation (RAG) techniques that see everything through the Control Graph and the Hybrid Data Fabric, resulting in a highly accurate security and GRC workflow automation without hallucinations.

In the last 2 years, we have enhanced and delivered 4 integrated AI-native user experiences that sit on top of the Hybrid Data Fabric, Control Graph, and Assurance AI, to accurately automate 1st-party and 3rd-party risk and compliance assessments for enterprise CISOs and GRC leaders. They are

TrustRegister icon

TrustRegister

Programmatic 1st-party application and infrastructure risk assessments, replacing check-the-box risk surveys sent to application, product, and IT owners.

TrustOps icon

TrustOps

AI and API based continuous compliance assessments to multiple industry standard and custom compliance frameworks, eradicating 1000s of hours of manual work

TrustLens icon

TrustLens

Programmatic inside-out and outside-in 3rd-party risk assessments, replacing security questionnaires (The security questionnaire is dead!)

TrustShare icon

TrustShare

AI that accurately creates a trust sharing customer security portal, and answers security questionnaires without hallucinations – so that you can prove how your security program accelerates revenue for your business

$15M to transform security and GRC into a profit center

This round, led by ServiceNow Ventures, with participation from Cisco Investments, Presidio Ventures, OpenView Venture Partners, Tola Capital, and other existing investors, is a strong endorsement of our vision to turn security into a strategic advantage for CISOs and GRC leaders, while simultaneously ensuring regulatory, contractual, and operational cyber resilience for their businesses.  

With our new funding, we will continue to scale our AI capabilities and deliver new  joyfully crafted products and experiences that our users continue to love. We will expand our go-to-market teams in the areas of marketing, sales, customer success, to facilitate our growth and ability to support our growing community  of the largest enterprise customers in the world.

Join the Security Assurance movement

Ok, what’s next?

Are you still using legacy GRC tools, or struggling with your inability to work with compliance automation or Trust Management startups, or even worse, still stuck in silos and manual GRC drudgery?  Do you want a better way? 

Let’s talk.

Setup a demo here to see how TrustCloud can upgrade your security and GRC program into a profit center

The post TrustCloud raises $15M to accelerate GRC Transformation for enterprise CISOs first appeared on TrustCloud.

*** This is a Security Bloggers Network syndicated blog from TrustCloud authored by Sravish Sridhar. Read the original post at: https://www.trustcloud.ai/trustcloud-news/trustcloud-raises-15m-to-accelerate-grc-transformation-for-enterprise-cisos/