TTIC Leadership

Why TTIC Exists: Standards Adoption and Trust on The New CISO

On Exabeam’s The New CISO, Sherri Douville, Founder & Chair of the Trustworthy Technology & Innovation Consortium (TTIC), discusses why TTIC was created, how it is separate by design from Medigram, and what it takes to move a standard into adoption in high-reliability industries.

From The New CISO, an Exabeam podcast: Episode 150, “The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools” (September 18, 2026)

Question 1

Why was TTIC created?

Excerpts are quoted from Exabeam’s published transcript of the episode, with accuracy corrections limited to Sherri Douville’s own statements.

Discussing IEEE/UL 2933:

TTIC was stood up by myself and Mitch Parker, CISO at IU Health. IEEE is an incredible organization, and we built this standard for clinical IoT device and data interoperability. However, to get it adopted and maintained in an industry like healthcare, you need many stakeholders involved. TTIC was created to bring together CIOs, CISOs, physicians, engineers, and everyone necessary to do that work.

Sherri Douville
Question 2

What is IEEE/UL 2933, and why does its adoption matter?

I co-chair the Trust and Identity Subgroup of IEEE/UL 2933, the standard for clinical IoT data and device interoperability with TIPPSS: Trust, Identity, Privacy, Protection, Safety, and Security.

Sherri Douville

I want to see IEEE/UL 2933 implemented across infrastructure providers, because I believe it would lead to fewer outages. When outages happen in healthcare, it’s really hard on clinicians. They lose access to records, and this can persist for hours or days. People think it’s just a patient safety problem for that hour, but it’s actually a long tail of delays, challenges, and miscommunications for the next 14 to 20 days. It’s a huge problem for doctors and patients.

Sherri Douville
Question 3

How does the Indiana AI Security System Architecture Layers framework relate to IEEE/UL 2933?

Among its basic expectations, the Indiana Executive Council on Cybersecurity’s AI Security System Architecture Layers framework calls for data provenance using known standards, citing IEEE/UL 2933:2024.

The aspect of architecture upfront is important. We used the six layers of the Indiana Executive Council on Cybersecurity’s AI Security System Architecture Layers framework. … You need a framework to tell you where to put the controls, and you need a structure the executive team understands.

Sherri Douville
Question 4

How is TTIC separate from Medigram?

TTIC is an independent governance body. Medigram is the company I run, which is a commercial implementation of the governance work we do, and they are separate by design.

Sherri Douville
Question 5

What makes a standard hard to adopt in a high-reliability industry?

What has been the most difficult part of standing that up?

Steve Moore

The hardest part has probably been negotiating with other bodies in the market. The space of AI and IT in high-reliability industries is incredibly complex and political. There are a lot of turf wars. Negotiating those relationships and helping people feel comfortable that we aren’t stepping on anyone’s territory has been challenging. … Establishing that clearly took a lot of effort and personal time.

Sherri Douville
Question 6

What role can CISOs play as stewards of trust?

I’ve been coached and guided by a lot of CISOs in this journey. What I’ve been helping them with is getting them onto stages they wouldn’t have gotten on in the past—in front of physician health system leadership, getting them onto healthcare podcasts, getting them published in books, and giving them a broader leadership persona.

Sherri Douville

The reason it’s important, especially in healthcare, is that everything is about trust. The best CISOs are stewards of trust. In the tech industry, trust can sometimes be off to the side, but in healthcare, it’s the core of the business. It’s nice to see that the whole world, with AI and agents, is now moving towards trust. CISOs have the opportunity to be the stewards of that trust, and that’s how they can become the rock stars of the C-suite.

Sherri Douville
Question 7

How does the episode connect TTIC to Exabeam’s open-source security work?

Praxen and Observra are open-source tools from Exabeam, the publisher of The New CISO.

That connects back into an open-source project that Exabeam is leading and that you’re involved with.

Steve Moore

Steve Wilson from Exabeam is the chair of AI Security with us at TTIC.

Sherri Douville
Attribution
Host
Steve Moore, The New CISO (Exabeam)
Guest
Sherri Douville, Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC); CEO, Medigram

Published September 22, 2026 · Last updated September 22, 2026

Choose TTIC as a preferred source in eligible Google experiences. Prefer TTIC in Google

Published by
Trustworthy Technology & Innovation Consortium (TTIC)
Author
By Sherri Douville, Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC)
Originally published
Last updated

Cite this resource

Sherri Douville. “Why TTIC Exists: Standards Adoption and Trust on The New CISO.” Trustworthy Technology & Innovation Consortium (TTIC), 2026. https://trustworthytechnologyinnovation.com/the-new-ciso-exabeam-podcast/.