First Principles

Every metric starts counting after someone decided it was safe to speak.

Avesta Hojjati, CTO of Netwrix, on the gap he’d most want to measure — the distance between the moment someone knows a problem exists and the moment the organization finally acts on it.

9 min watch


Avesta Hojjati

Chief Technology Officer, Netwrix

Leads a 300-person global engineering organization across identity and data security. Previously CTO at SecurityScorecard and eight years at DigiCert. PhD from Illinois, named inventor on more than 45 patents.


What this conversation is about

Avesta doesn’t measure impact by who solved the biggest problem. He measures it by who prevented one — the architect who caught a scalability wall years before it arrived, the support engineer who spotted a pattern in the ticket noise. And he wants a number almost nobody tracks: the distance between the moment someone first recognized a problem and the moment the organization started acting on it.

His early-warning signs for a struggling team are all verbal, and none of them live in a tool. Meetings shift from decisions to status. The same risk recurs for weeks with no clear owner. People start saying “we should” rather than “I will.” A team looks busy — tickets, meetings, activity — but can’t say what “done” means. Delivery, he says, is a lagging indicator; the breakdown happened much earlier, in the conversations.

On AI he refuses the tidy answer and says it does both — removes repetitive load and creates a new kind of cognitive load in its place, the work of validating, securing, and deciding where human judgment must remain. The mistake, he argues, is measuring adoption by activity: licenses bought, prompts submitted, percentage of code generated. Those aren’t outcomes. The real question is whether AI removes work from the system or just increases the volume the system has to process.


Three things to take from this

1.

Measure time to truth, not time to ticket.

Your dashboards start counting when a problem gets reported. The expensive delay is everything before that — how long someone sat on what they knew. That lag isn’t a routing problem, it’s a safety reading. If it’s long, your best people are deciding it isn’t safe to be the one who speaks first. In security that gap is how a small issue becomes a breach; everywhere else it’s how a fixable problem becomes an expensive one.

2.

Watch the pronouns before you watch the burndown.

“We should” instead of “I will” is the grammar of someone who doesn’t feel safe owning an outcome. A risk named three weeks running with no owner is three weeks of people quietly deciding it’s safer not to hold it. These read as process problems and get process fixes. They’re usually exposure management, and no amount of tightening the standup format changes what people are protecting themselves from.

3.

Trust the person who asks the best question, not the fastest answer.

The one Avesta turns to on a hard problem isn’t the one who claims to know. It’s the one who asks what’s reversible, what the cost of waiting is, what would change the decision — and who brings bad news early. Speed of answer is easy to hire for and often the wrong signal. Willingness to say “I don’t know yet, and here’s what worries me” is rarer, and it’s the thing that keeps a hard problem from getting worse.

“Hiding uncertainty is far more dangerous than admitting it.”

— Avesta Hojjati

Host’s note — Dharma Ramasamy

Avesta wants to measure time to truth: how fast accurate, uncomfortable information gets from the edge of an organization to the person who can act. It’s the sharpest thing anyone has said on this series about what a metric is actually made of, and I want to take it one layer down, because the reason the number is hard to move is not organizational. It’s biological.

The delay between knowing and reporting is a delay between two decisions, and the second one isn’t made in the part of the brain that reads an org chart. Telling someone with power over your standing that there’s a problem — especially one you might be blamed for, or one that’s still just a hunch — registers to the nervous system as a social threat. And a system under social threat doesn’t optimize for the organization’s information flow. It optimizes for the individual’s safety, which almost always means wait, soften, let someone else go first, gather more certainty before exposing yourself. Every one of those is a rational move for the person and a tax on the org. Time to truth is the sum of that tax.

Which is why you can’t shorten it with a candor policy or a memo about speaking up. The lag is the readout of a state, not the absence of a skill. People already know how to report problems; what they’re calculating is whether it’s safe to be early, uncertain, and possibly wrong. That calculation is set by exactly one thing: what they’ve watched happen to the last person who was. Make it survivable to raise a false alarm and the number drops on its own, because you’ve lowered the threat the body was responding to. That’s the same mechanism underneath every episode of this series — behavior that looks like a culture problem is a nervous system correctly protecting itself. Avesta just gave it the cleanest name it’s had yet.


Be on the series.

Five more of these this quarter. Twenty minutes, two cameras, nothing to prepare, and you see the edit before it publishes.

Get in touch →

The number Avesta wanted.

CultureGuard reads existing collaboration metadata to surface where human capacity is actually draining — and how long a problem sits before it surfaces — before delivery slips. No surveys, no AI, no content ever read.

How it works →