In this customer spotlight, Matt Sharp, CISO at Xactly, discusses how AI is reshaping the threat landscape, why Continuous Penetration Testing has become essential for modern security programs, the importance of human-in-the-loop validation, and how Evolve Security helps prioritize the exposures that matter most to reduce business risk.

Matt Sharp, CISO, Xactly Corp

Xactly, a Vista Equity Partners portfolio company and leader in incentive compensation and sales performance management software, partnered with Evolve Security to strengthen its offensive security program.

In this customer spotlight, Matt Sharp, CISO at Xactly, discusses how AI is reshaping the threat landscape, why Continuous Penetration Testing has become essential for modern security programs, the importance of human-in-the-loop validation, and how Evolve Security helps prioritize the exposures that matter most to reduce business risk.

Transcript

Mark Carney:

Hi, I'm Mark Carney with Evolve Security — I'm the CEO here. Today I've got Matt Sharp with Xactly with me. Matt, tell us a little about your role and about Xactly.

Matt Sharp:

I'm the Chief Information Security Officer at Xactly. I own most of the cyber disciplines you'd expect in a traditional CISO role, and I also serve as the chair of the AI Governance and Guidance Committee. Xactly is a recently recognized leader in the sales performance management space, so we're really excited about achieving that recognition. The bona fides really help us and reinforce the investments we've been making on a multi-year transformation over the last three years.

Mark Carney:

We've both been in this space for a long time, and AI is now a big part of it — new threats and a new way of thinking. How has that changed your role, and vulnerability operations? How has that transformation from an old way of thinking about vulnerability management to a new way of thinking impacted you?

Matt Sharp:

The mental framework I like to use when I think about AI in general is that there are things within our control as a business, and then there are things happening in the environment around us — and both impact us in a pretty important way when it comes to making sure we've adequately mitigated vulnerabilities in the environment.

For example, Mythos is the poster child for a changing, evolving landscape. And then separately, internal to the org, we're aggressively releasing an agentic builder experience, and we have a number of assistants and data exploration built on large language models. So making sure we can evaluate non-deterministic workloads in an appropriate way, and making sure our architecture is sound on this brand-new technology — where, frankly, there's no proven path on how to build AI — is critical. There's a lot of experimentation, and having the ability to leverage folks who understand that technology, along with some of the traditional security disciplines around threat modeling and penetration testing, is pretty crucial for the successful release of software in our business. We're certainly living in a different time.

Mark Carney:

When you think specifically about continuous pen testing versus an episodic, point-in-time approach — transforming into more visibility and trying to prioritize, which I think has been amplified by some of the attacks and the tools now in the hands of our adversaries — what specific things are you trying to accomplish?

Matt Sharp:

As you know, I tend to root all of my activities in the ongoings of the business. The aggressive innovation curve — the time horizon of innovation and adoption of new technology — has shrunk from maybe one to five years down to three months. Our business has accordingly adjusted the way we plan and execute our roadmap to make sure we're aggressively adopting and staying ahead of the curve. Naturally, that means the InfoSec team has to think about how to prioritize and be congruent. We have to facilitate the business doing what it's going to do either way, so honoring the cadence of innovation in the business is the first piece.

When you think about how that gets done, there are a couple of things. We have to go from a priority concept all the way to code release in a relatively short time, so having fixed harnesses and defined happy paths that avoid meaningful deviations is one thing, and then doing appropriate risk analysis to understand the level of diligence that needs to be done. Those are two of the big programmatic things we've done. And then, obviously, having the vendors in place who understand how the evolving technology is impacting companies and — frankly, from a pen test perspective — who are able to hack this stuff.

Mark Carney:

When you think about continuous pen testing, what are the business outcomes that come out of it?

Matt Sharp:

From a business perspective, what we're trying to do is get from priority concept to delivering value to customers, and we have to do that in the most efficient way. The truth is, we're a company with 20 years of history, and for us to move fast, the stakes are different than for an AI-native company with three employees, no technical data infrastructure, and no existing customers. We see a lot of innovative companies coming in and offering really interesting value propositions, and we have to understand and react to some of that in the evolution of our product. But we also have to stand tall on the fact that we have a platform, a robust data architecture, and a security program that far exceeds any of our competitors' capabilities.

So collectively, we're matching the pace — because security isn't the only thing customers are buying. We're more of a gate on the front end of the sales cycle, when we ask, "Should we work with these guys?" And then at the tail end, when we're trying to close deals, it's about, "Is this the right partner for us?" — not just, "Did they make the shortlist?" The ability to both be secure and keep pace with the innovation cycle is really the name of the game in the SaaS industry at this point.

Mark Carney:

There are a lot of pen testing providers out there. Why did you select us to partner and come along the journey with you?

Matt Sharp:

That's a good question. We surveyed the landscape. We'd had some internal friction with commodity pen test providers — they struggled to understand the complexity of our enterprise application. That was the first thing: even the access methodologies and models, being able to run tests, and understanding, when you find something, whether it's a feature or a bug.

Beyond the sophistication of offering an enterprise SaaS application, it was important for us to know we had somebody who wasn't just on a large bench of random testers — part of a big pool that maybe spent more time running infrastructure-type scans and doing Metasploit-type exploitation. We wanted somebody who could come in and speak the language of data science to our data scientists, understand some of the core configurations, and grasp the implications of things like a code interpreter behind a large language model — and help us think through what we should or shouldn't be concerned with in terms of embedding guardrails into our RAG, and things like that. So the sophistication of our business and software was one piece, and the sophistication of the folks conducting the test and understanding the emerging technology was the other — both were very important in our selection.

Mark Carney:

We certainly appreciate the trust you have in us and the partnership with you and Xactly. Thank you for that, and thanks for spending time with me today. We appreciate the great work you're doing.