Menu

Operational Trust vs. Technical Trust — The Foundation of Confidential Computing

In this short video take, my colleague Daniel Newman and I discuss the differences between operational trust and technical trust. These two things form the basis of what Confidential Computing is really about.

Watch the clip:

To hear the entire conversation, check out the episode here.

Disclaimer: The Futurum Tech Podcast is for information and entertainment purposes only. Over the course of this podcast, we may talk about companies that are publicly traded and we may even reference that fact and their equity share price, but please do not take anything that we say as a recommendation about what you should do with your investment dollars. We are not investment advisors and we do not ask that you treat us as such.

Transcript:

Daniel Newman: So let’s revisit this, operational trust and technical trust, Shelly. I talked about it at the end. This is really, in my eyes, what confidential computing is all about.

Shelly Kramer: Yeah. And I think sometimes most of us don’t break these down in our heads, but operational trust is the thought that better and regular training, and stricter rules, and compliance and certification, all of those things, those things are important. We’ve worked with many clients in the space of providing training and compliance and all that sort of thing. Those things are important. But today, operational trust alone is not enough. And so then we’ll shift and talk about technical trust, and that’s really where we need to head.

Technical trust is the focus on removing people from the security equation and deploying technology solutions rather than the training, and the processes, and the compliance, and the certification. And the industry as a whole needs the ability to make it possible to run applications on somebody else’s computer, but where the owner of the computer can’t influence or observe what’s happening. It sounds kind of weird, I know, but this can be achieved through the deployment of technology that has no reliance on human intervention. And that’s really what we’re talking about when we’re talking about confidential computing, and what we’re talking about when we look at what’s the next gen of security protection for organizations.

Daniel Newman: Yeah, absolutely. And the genesis of all this is, as we’ve moved to Cloud, companies have had to rethink who can access the data, and how they’re able to access the data, and why they need to access the data. If you think about some of the biggest threat surfaces inside of an organization, it’s often people.

Shelly Kramer: Right.

Daniel Newman: And you talked about that with operational assurance, Shelly, but oftentimes the people have the capacity, because they’re administrators of the systems, to also be able to view or extract or take a snapshot of an application and the data, and that data can get migrated. It’s like anytime you have a PC that’s company owned and data has been sent around, oftentimes it’s sent around in an application.

But we often say, let’s download the CSV, we want to manipulate this data, play with this data. Well, all of a sudden this data is no longer in the secured environment, it’s now on someone’s machine.

Shelly Kramer: Right.

Daniel Newman: And administrators often have no reason to need to look at data, especially if you think about it in some highly regulated type spaces where you have things like credit card and financial data, you have HIPAA type data, and so we’ve had to build more hardened systems. But confidential computing as a whole, I guess we’ve talked around it a lot, but it really comes down to the ability to protect data in kind of all three states, right? We’ve got data at rest, you got data in transit, and we’ve gotten pretty good at that in terms of protecting it. But what about when data is being used in an application, and being able to manage it in all three states? That’s a pretty big problem.

Author Information

Shelly Kramer is a serial entrepreneur with a technology-centric focus. She has worked alongside some of the world’s largest brands to embrace disruption and spur innovation, understand and address the realities of the connected customer, and help navigate the process of digital transformation.

Related Insights
CrowdStrike Deepens Agentic SOC Strategy Across Partners, Services, and Devices
April 1, 2026

CrowdStrike Deepens Agentic SOC Strategy Across Partners, Services, and Devices

Fernando Montenegro, VP & Practice Lead for Cybersecurity & Resilience at Futurum, examines CrowdStrike’s agentic SOC expansion across partners, IBM, and Intel, and what it means for security execution and...
LevelBlue–SentinelOne Partnership: Does Unified Security Improve Outcomes?
April 1, 2026

LevelBlue–SentinelOne Partnership: Does Unified Security Improve Outcomes?

Fernando Montenegro, VP & Practice Lead for Cybersecurity & Resilience at Futurum, analyzes the LevelBlue SentinelOne partnership and its focus on integrating threat intelligence, AI detection, and response to improve...
Palo Alto Bets on Agentic Endpoints Before Anyone Else Does
April 1, 2026

Palo Alto Bets on Agentic Endpoints Before Anyone Else Does

Palo Alto Networks bets big on AI agent security through Koi acquisition, with CEO Nikesh Arora backing it with a $10M stock purchase, positioning the company as first to formally...
Can Prisma SASE Actually Secure Agents It Cannot See?
March 29, 2026

Can Prisma SASE Actually Secure Agents It Cannot See?

Palo Alto Networks extended Prisma SASE to govern agentic AI workloads, but structural mismatches between SASE design and dynamic agent behavior raise critical enforcement questions....
Prisma AIRS 3.0: Does Palo Alto Own the Agentic AI Security Stack?
March 29, 2026

Prisma AIRS 3.0: Does Palo Alto Own the Agentic AI Security Stack?

Palo Alto Networks unveiled Prisma AIRS 3.0, a purpose-built security platform for autonomous AI agents. As enterprises deploy agentic systems across cloud and SaaS, control of the agentic security stack...
Does the NetApp-Commvault Partnership Signal a Paradigm Shift for Backup?
March 27, 2026

Does the NetApp-Commvault Partnership Signal a Paradigm Shift for Backup?

Fernando Montenegro at Futurum examines NetApp and Commvault’s alliance linking storage-layer ransomware detection to automated recovery workflows across hybrid environments....

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.