Ravi Soin has clear advice for anyone starting a security career today: don't be a risk manager, be a trust architect. In this episode, Steve Moore sits down with Ravi—CIO and CISO at Smartsheet—for a builder's-eye conversation on the modern CISO role, AI as an accelerant on old sins, and why the CISO who still says “no” is already obsolete.
Ravi traces his path through Sun Microsystems, RealNetworks, a decade at Microsoft, and 15 years at healthcare software leader Edifecs to his eight months at Smartsheet. He explains what it means to think about security the way builders do—understanding where corners get cut under sprint pressure—and why that inside-out perspective changes how you defend.
Steve and Ravi dig into how Smartsheet is deploying agentic AI across the enterprise: a centralized knowledge graph tied to every corporate system, Claude-powered threat models, DAST and SAST scans, SOC triage on the 80% phishing baseline, and MCP-connected asset and license management.
They name the old culture directly. It was an era of risk registers where lows and mediums were quietly punted, tens of thousands of known vulnerabilities were accepted as compensating- control fiction, and time-to-exploit was assumed to be forgiving. Both push back on the panicked reaction to the Mythos disclosures, arguing AI has simply closed the exploit window on the trash environments were already ignoring.
Ravi's core advice: build trust into the system, think about security through the customer's lens, and treat AI agents as first-class identities under the same IAM principles you apply to humans. He and Steve close on how incident response must be re-fit for the agentic era, why auditability is the non-negotiable foundation of AI governance, and why community remains the sharpest source of learning.
Key Topics
• Thinking about security like a builder, from the inside out
• Why the CISO who still says “no” is already obsolete
• Deploying agentic AI across engineering, SOC, and corporate systems
• MCP-connected asset and license management
• The old risk-register culture and how the industry was gambling
• Why the Mythos reaction missed the bigger story
• Advice to your 21-year-old self: be a trust architect
• Building security through the customer's lens
Guest Bio
Ravi Soin is the CIO and CISO at Smartsheet, where he leads global IT and security strategy for the AI-enhanced enterprise work management platform. He brings more than two decades of security and IT leadership, including 15 years as CIO and CISO at healthcare software leader Edifecs and product roles at Microsoft, RealNetworks, and Sun Microsystems. Ravi serves on the SeattleCIO advisory board and was named Seattle CIO of the Year.
GET A DEMO:
👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo
🔔 Subscribe for more product demos and cybersecurity insights!
ABOUT EXABEAM:
Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.
Exabeam: Stop Insider Threats. Human or AI.
CONNECT WITH US:
X: https://x.com/exabeam
LinkedIn: https://www.linkedin.com/company/exabeam/
Blog: https://www.exabeam.com/blog/