This Series:
Part 1 (Intro) | Part 2 (Hire Strange Renegades) | Part 3 (Build Craftsmen) | Part 4 (Create Artisan Products) | Part 5 (Earn Raving Fans) | Part 6 (Forge an Inimitable Brand)
In my mind's eye I have always imagined risk3sixty to be on those companies that people talk about like their favorite local restaurant. You know the place. It's one of those hidden gems that only the locals know about. You only speak about it in a whisper because it must be preserved.
The owners still work in the kitchen preparing finely honed recipes that make the food uniquely excellent. It's off the beaten path, always busy, and always excellent. It's your place and you tell your closest friends and family about it anytime someone asks for a recommendation.
The key to a restaurant like that staying in business is that their food is so darned good that customers become "regulars" who spread the word to their friends. And in many ways I think that has been our secret to success here at risk3sixty. We don't want to be the big chain restaurant, we want to be an elite boutique.
We strive to earn raving fans.
Raving fans are different. They trust you. Advocate for you. They choose you again and again, and they tell others why. And like every other stage of the Flywheel, raving fans don’t happen by accident. They are earned through intentional experience, consistency, and relentless listening.
Designing the Customer Experience to Earn Raving Fans
One of the most important ways we try to earn raving fans is by carefully curating an excellent customer experience. And this ambition is true whether someone is receiving consulting services or using one of our products. We think how a customer feels about receiving the service is nearly (but not quite) as important as the result itself.
And one thing I have learned over the years is that great customer experience doesn’t come from heroic effort or individual brilliance.
It comes from systems.
For example, one thing we realized that was important to our customers is the ability to get answers to questions fast. No one wants to sit around feeling helpless or with too much ambiguity. So, we have taken steps to solve that problem during every step of the engagement process.
During kick-off we discuss the full project plan and provide orientation sessions. During the project we exchange contact information, connect a slack account, and provide weekly status updates. We even invested in building AI into fullCircle, our GRC platform, so customers can get context specific information about their program anytime they need it. When we provide deliverables we always provide drafts and do read out sessions to answer questions in advance. Even between engagements we have touch points.
These are little steps are subtly designed into our systems without our customers even noticing. But the result is that our customers always have the information they need, always feel confident, informed, and supported.
Reviewing Customer Feedback as a Team Every Week
Designing a great customer experience is only part of the equation. Earning raving fans requires listening and striving to continuously integrate the feedback we hear into our systems and products. One way we do that is by asking customers for formal feedback at the conclusion of each project in the form of an NPS score as well as written and verbal feedback. We review every feedback submission as a management team and as a team during our weekly all hands meeting.
For example, each week, Phil Brudney, our director of quality assurance presents the NPS scores and customer feedback from the previous week during our all-hands meeting. This isn’t a leadership-only review or a private report — it’s a shared moment for the entire organization.
We review the feedback openly - the good and the bad (though it’s usually good) - because we want to make it clear that that our company makes customer feedback a priority. It is healthy accountability when you know that your customer's feedback will be front an center to the whole company.
We celebrate promoters, give shout-outs to team members who went above and beyond, and discuss lessons learned when something didn’t land as intended. Our weekly rhythm shapes our behavior, reinforces what great looks like, and keeps us grounded in the experiences of the people we serve.
How Customer Feedback Shapes Behavior
Customer feedback isn’t something we collect and file away. It actively shapes what we build and how we operate.
A great example of this is how we developed our AI Agent for Evidence Lifecycle Management which is part of our Agentic AI "xLM" suite. During lessons learned sessions and post-engagement conversations, customers consistently told us the same thing: managing evidence was one of the most painful, time-consuming parts of maintaining a compliance program. Gathering it, validating it, updating it, and keeping it audit-ready created constant friction for their teams.
You can only get this kind of feedback so many times before you decide you have to do something about it.
So we did.
The result was agentic AI tooling designed specifically to reduce the burden of evidence management, automate repetitive tasks, and give compliance teams back time and clarity.
This is how feedback becomes behavior (or even products) at risk3sixty. We listen, we learn, and we build. Over time, those small, customer-driven improvements compound to strength our delivery, improve our products, and earning deeper trust with every turn of the Flywheel.
Why Raving Fans Matter to the Flywheel
At risk3sixty, we have to keep our customers happy because it is essential to our business model. Unlike many of our competitors, we are bootstrapped and grow our business from the profits of the business rather than outside funding. The result is, we value every customer and believe the deserve to be treated with care. We simply can't (and don't want to) throw money at marketing budgets or big sales teams to try to replace lost customers with new ones.
That's just not our model.
And just like visiting your favorite local restaurant over some big chain - you will notice the different. We will know your name, we will remember your preferences, we'll get to know you, and most importantly the "food" will taste great.
This momentum feeds the final stage of the Flywheel - Inimitable Brand. A reputation built on authentic advocacy can’t be copied, bought, or rushed.
What’s Next
In the final post of this series, we’ll explore the last stage of the Strategy Flywheel: Inimitable Brand.
When raving fans accumulate over years of consistent execution, something powerful happens. Your brand becomes a reflection of trust, craftsmanship, and experience — something no competitor can replicate.
Check out part 6 --> INIMITABLE BRAND
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)