Why TTIC Exists: Standards Adoption and Trust on The New CISO
On Exabeam’s The New CISO, Sherri Douville, Founder & Chair of the Trustworthy Technology & Innovation Consortium (TTIC), discusses why TTIC was created, how it is separate by design from Medigram, and what it takes to move a standard into adoption in high-reliability industries.
From The New CISO, an Exabeam podcast: Episode 150, “The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools” (September 18, 2026)
The New CISO is a podcast produced and published by Exabeam. This page presents selected highlights; the full episode and transcript are available on Exabeam’s site.
Episode art courtesy of Exabeam.
Why was TTIC created?
Excerpts are quoted from Exabeam’s published transcript of the episode, with accuracy corrections limited to Sherri Douville’s own statements.
TTIC was stood up by myself and Mitch Parker, CISO at IU Health. IEEE is an incredible organization, and we built this standard for clinical IoT device and data interoperability. However, to get it adopted and maintained in an industry like healthcare, you need many stakeholders involved. TTIC was created to bring together CIOs, CISOs, physicians, engineers, and everyone necessary to do that work.
Sherri Douville
What is IEEE/UL 2933, and why does its adoption matter?
I co-chair the Trust and Identity Subgroup of IEEE/UL 2933, the standard for clinical IoT data and device interoperability with TIPPSS: Trust, Identity, Privacy, Protection, Safety, and Security.
Sherri Douville
I want to see IEEE/UL 2933 implemented across infrastructure providers, because I believe it would lead to fewer outages. When outages happen in healthcare, it’s really hard on clinicians. They lose access to records, and this can persist for hours or days. People think it’s just a patient safety problem for that hour, but it’s actually a long tail of delays, challenges, and miscommunications for the next 14 to 20 days. It’s a huge problem for doctors and patients.
Sherri Douville
How does the Indiana AI Security System Architecture Layers framework relate to IEEE/UL 2933?
The aspect of architecture upfront is important. We used the six layers of the Indiana Executive Council on Cybersecurity’s AI Security System Architecture Layers framework. … You need a framework to tell you where to put the controls, and you need a structure the executive team understands.
Sherri Douville
How is TTIC separate from Medigram?
TTIC is an independent governance body. Medigram is the company I run, which is a commercial implementation of the governance work we do, and they are separate by design.
Sherri Douville
What makes a standard hard to adopt in a high-reliability industry?
What has been the most difficult part of standing that up?
Steve Moore
The hardest part has probably been negotiating with other bodies in the market. The space of AI and IT in high-reliability industries is incredibly complex and political. There are a lot of turf wars. Negotiating those relationships and helping people feel comfortable that we aren’t stepping on anyone’s territory has been challenging. … Establishing that clearly took a lot of effort and personal time.
Sherri Douville
What role can CISOs play as stewards of trust?
I’ve been coached and guided by a lot of CISOs in this journey. What I’ve been helping them with is getting them onto stages they wouldn’t have gotten on in the past—in front of physician health system leadership, getting them onto healthcare podcasts, getting them published in books, and giving them a broader leadership persona.
Sherri Douville
The reason it’s important, especially in healthcare, is that everything is about trust. The best CISOs are stewards of trust. In the tech industry, trust can sometimes be off to the side, but in healthcare, it’s the core of the business. It’s nice to see that the whole world, with AI and agents, is now moving towards trust. CISOs have the opportunity to be the stewards of that trust, and that’s how they can become the rock stars of the C-suite.
Sherri Douville
How does the episode connect TTIC to Exabeam’s open-source security work?
That connects back into an open-source project that Exabeam is leading and that you’re involved with.
Steve Moore
Steve Wilson from Exabeam is the chair of AI Security with us at TTIC.
Sherri Douville
Published September 22, 2026 · Last updated September 22, 2026
Choose TTIC as a preferred source in eligible Google experiences. Prefer TTIC in Google
- Published by
- Trustworthy Technology & Innovation Consortium (TTIC)
- Author
- By Sherri Douville, Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC)
- Originally published
- Last updated
Cite this resource
Sherri Douville. “Why TTIC Exists: Standards Adoption and Trust on The New CISO.” Trustworthy Technology & Innovation Consortium (TTIC), 2026. https://trustworthytechnologyinnovation.com/the-new-ciso-exabeam-podcast/.