AI Agents and the Truth Engine for Human Health with Matthew Matturro - Ep 230

Matthew MAtturo IMAGEMatthew Matturro is the CISO of TriNetX, a global health intelligence platform that describes itself as the truth engine for better human health. By connecting distributed clinical data nodes across more than five continents through partnerships with health systems, research institutions, and pharmaceutical organizations worldwide, TriNetX makes real patient data computable for clinical trials, research, and analytics without aggregating it in a single repository. Eleven years into his tenure and the organization's first IT and security hire, Matthew now leads an information security program built across three pillars: governance risk and compliance, security operations, and product security, while simultaneously building what he calls a headless security operations model powered by AI agents. 

 

apple
spotify
stitcher
google podcast
Deezer
iheartradio
tunein
partner-share-lg

Here’s a glimpse of what you’ll learn: 

 

  • What headless security operations means and how Matthew is restructuring his team around AI agents that handle foundational tasks so humans can operate at a higher order
  • Why Matthew is building a deputy CISO and chief of staff AI agent that runs locally on his identity and what governance has to be in place before it can be extended to the team
  • Why the best security teams are moving to an AI native capacity with an observability layer that blends human and AI judgment at each tier of the operation
  • Why Matthew has a descending opinion on security awareness training and what he is doing instead through a security ambassador program and center of excellence
  • Why garbage in, garbage out is not just a data quality problem but an access control and classification problem, and why that distinction matters in healthcare
  • How TriNetX uses the know your customer principle internally to make alert triage faster and more accurate across a globally distributed organization of 300 people
  • Why Matthew believes email security AI is currently in the teenage driver phase and what it will look like when it reaches the full self-driving equivalent



In this episode…

Matthew opens with a description of TriNetX that immediately distinguishes this episode from the usual enterprise security conversation. This is not a company that aggregates patient records into a central database. It connects distributed data nodes across health systems and research institutions globally, pulls them together for specific research or clinical trial purposes, and does it with real longitudinal data that has to meet the regulatory requirements of every country where it operates. Matthew has been the person responsible for securing that model for eleven years, which gives him one of the longer institutional memory spans of any guest this season. His framing of the current moment is equally grounded: he is building toward what he calls headless security operations, a model where AI agents handle the foundational and administrative work that used to consume his team's time, freeing humans to operate at a higher strategic tier. He presented this model to his full organization the same day he sat down for this conversation, and the energy with which he describes it makes clear this is not a roadmap slide. It is already underway.

The AI agent governance section of this episode is the most specific and operationally detailed account of what building an AI-augmented security team actually looks like in practice. Matthew runs a deputy CISO and chief of staff agent locally through what he describes as a Cowork-style offering, using his own identity as the access layer so the agent knows what he knows. The limitation he names is equally precise: extending that agent to his full team is a classification and access problem, because there are things he knows as an executive that his team should not have access to, and the information governance has to be right before the agent can be given broader reach. He is also developing a concept for an AI risk manager agent that could sit in the org chart, listen in on direct message threads, pull meeting transcripts, and surface risk signals across the organization's various headless security systems. His challenge to his team is explicit: automate yourself out of what you are doing today so you can do higher order work tomorrow.

The security awareness training debate in this episode is the most direct and productively contested exchange this podcast has featured. Matthew's hot take is sharp: security awareness training is a compliance checkbox that cannot reliably change human behavior, and the responsibility for keeping Jane in accounting safe from a phishing email should not be placed on Jane. It should be on the security team and the tools they deploy. His position is not that awareness is worthless but that the onus has shifted and AI-native email security is what makes that shift practical. Matthew pushes back with a different frame: a security ambassador program and center of excellence that treats awareness as a distributed, community-driven practice rather than an annual training requirement. His analogy lands well: finance gives employees a corporate card and trains them to use it responsibly, and they rely on users to flag suspicious charges. Security should operate the same way. The two positions are not as far apart as they first appear, and the conversation that results is more useful than either position alone.

 

 

Resources mentioned in this episode

 

Matthew Connor on LinkedIn
CyberLynx Website
Matthew Matturro on LinkedIn
TriNetX Website
Darktrace Website
Abnormal AI Website

 

Sponsor for this episode...

 

This episode is brought to you by CyberLynx.

CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.

We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.

Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

 

Check out previous episodes:

 

CMMC, M&A Integration, and AI Upstream Defense with Bobby Barts - Ep 228 

Physical Anchors and the Data Age: How Manufacturing Wins in AI with Chris Stierle - Ep 227

Fundamentals First: Why Data Governance Wins the AI Era with Kalen Howell Sr - Ep 226

 

Transcript: 

 

Matthew Matturro

CISO

TriNetX


Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Matthew Matturro, CISO at TriNetX. Matthew, welcome to the show.

Matthew Matturro: Thank you so much. I'm really excited to be here.

Matthew Connor: Excited to have you. Before we get too far in, a quick word from our sponsors. Hackers are getting smarter — is your security keeping up? Cyberlynx sells industry-leading, AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. And now back to our show.

Matthew, for those who aren't familiar, can you tell us about TriNetX and your role there as CISO?

Matthew Matturro: Absolutely. TriNetX is a global health research network. We connect life sciences companies, pharmaceutical companies, clinical research organizations, and healthcare organizations, and we facilitate clinical trial research. We make it possible for research sponsors to identify patient populations for clinical trials by connecting them to the real-world data held by our healthcare organization members. Our core mission is to accelerate clinical research, which ultimately means getting treatments to patients faster. For me personally, having come from the healthcare and life sciences space for most of my career, that mission resonates deeply.

As CISO, I oversee all aspects of information security — strategy, risk management, compliance, and operations. TriNetX holds a unique position in that we sit at the intersection of healthcare data, life sciences, and technology, so the security and privacy obligations are significant. We operate under HIPAA, SOC 2, and various international data privacy frameworks, and we work hard to make sure that trust is earned and maintained with every member of our network.

Matthew Connor: That's a fascinating environment to be operating in — the intersection of healthcare, pharma, and clinical research data is a genuinely high-value target from a threat actor perspective. Sensitive patient data, proprietary research, pharmaceutical pipelines — all of it attractive. And we're in a moment where the attack surface is evolving faster than it ever has. I get really excited about what AI is doing on the defensive side — particularly machine learning-based products like Darktrace that understand what normal looks like and stop what doesn't fit, rather than just bolting an LLM onto a traditional security gateway. That kind of intelligence is what you need when attacks are coming at machine speed. How are you thinking about AI in your security program?

Matthew Matturro: It's a topic I spend a lot of time on, and I'd frame it around three dimensions. The first is AI as a threat vector — understanding how adversaries are using AI to make attacks more sophisticated, more targeted, and faster. The phishing emails we see today are qualitatively different from what we saw three years ago. They're contextually aware, they're personalized, they're harder to spot. Social engineering attacks are more convincing. The attack surface from AI-generated synthetic media — deepfakes — is a real and growing concern, particularly in a world where we have remote-first work and video calls are how we do business.

The second is AI as a defensive capability. I'm aligned with what you described — the real value in security AI right now is in the machine learning layer: behavioral analytics, anomaly detection, threat hunting at scale. These are things that genuinely couldn't be done at the speed and volume required with human analysts alone. We're not at a point where I'd deploy a fully autonomous AI agent to make remediation decisions without human review, but the acceleration of detection and triage is real and significant.

The third is AI as a business tool — and this is where the governance challenge lives. Our researchers, our data scientists, our developers are all eager to use AI to accelerate their work. That's legitimate and I want to support it. But every AI tool that touches our data creates a potential data governance issue. Where does the data go? Who trains on it? What's the retention policy? When you're dealing with health data at any level of abstraction, those questions are not hypothetical — they have regulatory and contractual implications. So we've built a framework for evaluating AI tools before they go into use, and we're actively working on our AI acceptable use policy to give people guardrails without making it so restrictive that they go around us.

Matthew Connor: That three-part framing is really clean and I think it applies universally. The governance piece especially — the reality is that if IT and security are too restrictive, people will find workarounds and you lose visibility entirely. Shadow AI is a genuine risk, and it's compounded in an environment like yours where the data has real regulatory protection. You mentioned the AI acceptable use policy — what are the key principles you're landing on?

Matthew Matturro: A few things. First, classification-based access — the sensitivity of the data being processed should determine what AI tools are permitted to interact with it. We're not going to run de-identified, aggregated research data and PHI through the same AI governance framework. They have fundamentally different risk profiles.

Second, vendor evaluation. Before any AI tool goes into use at TriNetX, it goes through a security review — data handling practices, training data policies, whether the provider has appropriate certifications, whether there are business associate agreement implications under HIPAA. A lot of AI vendors haven't fully thought through their HIPAA obligations, and that's a conversation we have to have explicitly.

Third, human accountability. Whatever AI produces, a human is responsible for validating and owning. We're not in a place where AI output goes directly into a decision that affects a clinical trial or a patient population without a human in the loop. That's a principle we hold firmly, and I think it's the right one for the maturity of the technology right now.

And fourth, continuous monitoring. We're not just evaluating a tool at onboarding and then trusting it forever. We want to understand how it's actually being used over time — what data is being sent, what's coming back, whether the usage patterns match what we approved.

Matthew Connor: That human accountability piece is so important and I think it's exactly right for where we are. The self-driving car analogy is apt — the technology has made extraordinary progress, but the moment you take your eyes off the road is the moment something goes wrong. And in your world, the stakes if something goes wrong are not just operational — they're potentially patient safety. That raises the bar significantly. What does the threat landscape look like specifically for clinical research networks?

Matthew Matturro: Clinical research is a high-value target for several reasons. Pharmaceutical pipeline data is enormously valuable — knowing what a company is developing before it's public has obvious financial implications. Health data is valuable on its own — it's detailed, longitudinal, and difficult to change the way you can change a credit card number. And clinical research organizations are often seen as a softer target than the pharmaceutical companies themselves, so they become an attack vector into the supply chain.

We see credential-based attacks frequently — phishing attempts aimed at getting access to a valid user account that then gets used to move laterally. We see business email compromise attempts targeting our finance team. And increasingly, we see attempts to exploit third-party integrations — the connections between our platform and our healthcare organization members, or between our platform and research sponsors. Those integration points require particular attention.

The nation-state dimension is real in this space too. Health data and pharmaceutical research are intelligence priorities for several foreign governments. That means the sophistication level of some of the threats we need to prepare for is higher than what you'd encounter in most industries. We take threat intelligence seriously and we work to understand not just what's happening in the wild broadly, but what's specifically targeting the healthcare and life sciences sector.

Matthew Connor: Nation-state actors are a whole different tier of adversary — well-resourced, patient, and often operating with objectives that go beyond immediate financial gain. The dwell time on those intrusions can be extraordinary because they're not there to ransomware you and leave — they're there to collect intelligence over months or years. That makes behavioral detection even more critical, because the signature of a nation-state intrusion doesn't always look like a conventional attack. It looks like a slightly unusual pattern of normal-looking activity. Which brings me back to why machine learning is so powerful in this context — it's the only tool that can identify that kind of low-and-slow deviation from baseline. How mature is your behavioral detection capability today?

Matthew Matturro: We've invested significantly in that layer. We use an EDR platform with strong behavioral detection, we have network detection and response capabilities, and we have a SIEM that aggregates and correlates across sources. We work with an MSSP for extended SOC coverage — again, the breadth of expertise argument that applies to organizations of our size.

Where I'd say we're continuing to mature is in the integration and correlation layer — making sure that signals from different tools are being connected and analyzed together rather than in isolation. A behavioral anomaly on an endpoint that's also correlated with unusual outbound network traffic and a spike in data queries — those three signals together mean something very different than any one of them alone. Getting that correlation to happen in near real time, with meaningful context surfaced to an analyst, is the area where AI is going to have the most impact over the next couple of years.

Matthew Connor: That correlation piece is exactly what the next generation of AI-driven security is going to nail. The signals are already there — they've always been there. The problem has been that humans can't process all of them simultaneously and connect the dots fast enough. AI that can do that correlation across millions of events in real time and surface the three signals that actually matter together — that changes the game for detection and response. And it's already starting to happen in products from SentinelOne, CrowdStrike, and others that are using AI to do that multi-signal investigation automatically. What's your advice for CISOs who are earlier in the journey and trying to figure out where to start with AI in security?

Matthew Matturro: Start with the fundamentals. If your logging isn't comprehensive, if your asset inventory isn't accurate, if you don't have good visibility into what's on your network — AI won't fix that. AI is an amplifier. It amplifies the quality of your data and your processes. If those are weak, you get amplified noise, not amplified signal.

Assuming the fundamentals are in place — I'd prioritize email security and endpoint detection as the two highest-ROI areas for AI investment right now. Email is still the primary attack vector for most organizations, and machine learning-based email security that goes beyond signature matching is meaningfully better at catching what gets through. Endpoint behavioral detection is your last line of defense inside the perimeter — if something does get through, you want to know as fast as possible.

Beyond that, evaluate AI claims carefully. The market is full of products that claim AI capabilities — what you want to understand is whether the AI is actually doing the work or whether it's a label on a traditional product. Ask vendors specifically: what is the AI doing, what data does it train on, how does the model get updated, what happens when it's wrong? Those questions separate the real from the marketing.

And build the governance foundation in parallel with the tool selection. Your AI acceptable use policy, your vendor evaluation framework, your data classification scheme — those inform every AI decision you make. If you build them after the fact, you're retrofitting governance onto decisions that were already made, which is much harder.

Matthew Connor: That is excellent advice across the board — and applicable well beyond security. The governance before the tools principle is something I think every organization needs to hear right now, because the temptation is to deploy and govern later, and "later" never comes. Foundational thinking first, and then you move fast with confidence. Really well said.

Matthew, this has been a fantastic conversation. Before we go, can you tell everyone where they can find out more about you and TriNetX?

Matthew Matturro: Absolutely. TriNetX is at trinetx.com — you can learn about our network, our mission, and how we're working to accelerate clinical research. I'm on LinkedIn as Matthew Matturro — happy to connect and continue the conversation. Security, AI governance, healthcare data privacy — those are the things I think about every day and I'm always glad to engage with others working through the same challenges.

Matthew Connor: Fantastic. Matthew, thanks so much for coming on. Until next time.

Matthew Matturro: Thank you. Really enjoyed it.

 

Read On