AI Agents and the Truth Engine for Human Health with Matthew Matturro - Ep 230
Guest Introduction Matthew Matturro is the CISO of TriNetX, a global health intelligence platform that describes itself as the truth engine for better human health. By connecting distributed clinical data nodes across more than five continents through partnerships with health systems, research institutions, and pharmaceutical organizations worldwide, TriNetX makes real patient data computable for clinical trials, research, and analytics without aggregating it in a single repository. Eleven years into his tenure and the organization's first IT and security hire, Matthew now leads an information security program built across three pillars: governance risk and compliance, security operations, and product security, while simultaneously building what he calls a headless security operations model powered by AI agents. Here's a Glimpse of What You'll Learn What headless security operations means and how Matthew is restructuring his team around AI agents that handle foundational tasks so humans can operate at a higher order Why Matthew is building a deputy CISO and chief of staff AI agent that runs locally on his identity and what governance has to be in place before it can be extended to the team Why the best security teams are moving to an AI native capacity with an observability layer that blends human and AI judgment at each tier of the operation Why Matthew has a descending opinion on security awareness training and what he is doing instead through a security ambassador program and center of excellence Why garbage in, garbage out is not just a data quality problem but an access control and classification problem, and why that distinction matters in healthcare How TriNetX uses the know your customer principle internally to make alert triage faster and more accurate across a globally distributed organization of 300 people Why Matthew believes email security AI is currently in the teenage driver phase and what it will look like when it reaches the full self-driving equivalent In This Episode Matthew opens with a description of TriNetX that immediately distinguishes this episode from the usual enterprise security conversation. This is not a company that aggregates patient records into a central database. It connects distributed data nodes across health systems and research institutions globally, pulls them together for specific research or clinical trial purposes, and does it with real longitudinal data that has to meet the regulatory requirements of every country where it operates. Matthew has been the person responsible for securing that model for eleven years, which gives him one of the longer institutional memory spans of any guest this season. His framing of the current moment is equally grounded: he is building toward what he calls headless security operations, a model where AI agents handle the foundational and administrative work that used to consume his team's time, freeing humans to operate at a higher strategic tier. He presented this model to his full organization the same day he sat down for this conversation, and the energy with which he describes it makes clear this is not a roadmap slide. It is already underway. The AI agent governance section of this episode is the most specific and operationally detailed account of what building an AI-augmented security team actually looks like in practice. Matthew runs a deputy CISO and chief of staff agent locally through what he describes as a Cowork-style offering, using his own identity as the access layer so the agent knows what he knows. The limitation he names is equally precise: extending that agent to his full team is a classification and access problem, because there are things he knows as an executive that his team should not have access to, and the information governance has to be right before the agent can be given broader reach. He is also developing a concept for an AI risk manager agent that could sit in the org chart, listen in on direct message threads, pull meeting transcripts, and surface risk signals across the organization's various headless security systems. His challenge to his team is explicit: automate yourself out of what you are doing today so you can do higher order work tomorrow. The security awareness training debate in this episode is the most direct and productively contested exchange this podcast has featured. Matthew's hot take is sharp: security awareness training is a compliance checkbox that cannot reliably change human behavior, and the responsibility for keeping Jane in accounting safe from a phishing email should not be placed on Jane. It should be on the security team and the tools they deploy. His position is not that awareness is worthless but that the onus has shifted and AI-native email security is what makes that shift practical. Matthew pushes back with a different frame: a security ambassador program and center of excellence that treats awareness as a distributed, community-driven practice rather than an annual training requirement. His analogy lands well: finance gives employees a corporate card and trains them to use it responsibly, and they rely on users to flag suspicious charges. Security should operate the same way. The two positions are not as far apart as they first appear, and the conversation that results is more useful than either position alone.





