Rebuilding Trust at a Public Company: What Crisis Recovery Taught Me About Making Trust Demonstrable

What rebuilding stakeholder trust at a public company after a reputational crisis taught me about making trust demonstrable, six patterns for boards and executives who need to prove trust, not just claim it.

Tyson Martin

7/20/20268 min read

rebuilding trust public company crisis recovery
rebuilding trust public company crisis recovery

There is a particular silence in the room when you join a company after a reputational crisis.

It's not hostility. It's caution. Every stakeholder you meet — board members, auditors, vendors, employees, regulators — has been burned by believing the last set of assurances. So they don't argue with you. They just wait. They wait to see whether you're another person who will tell them things are fine, or the first person in a while who will show them what's actually true.

I walked into that silence in 2019, when I joined Lumber Liquidators as CISO and CTO. The company was several years past the crisis that had made it a household name for the wrong reasons, and deep into the harder, longer, less newsworthy phase: proving to auditors, regulators, investors, customers, and its own employees that it could be trusted again. My job was security and technology, but the real mandate was bigger than either. The mandate was to make trust demonstrable.

I want to write down what that experience taught me, at the level of pattern rather than war story, because I keep watching companies learn these lessons the expensive way. Pre-IPO companies discover them during S-1 diligence. AI companies are discovering them right now, in real time, in front of regulators who are still writing the rules. Every one of these patterns generalizes. A crisis just compresses the timeline enough that you can't avoid seeing them.

Trust is lost globally and rebuilt locally

Here is the asymmetry nobody prepares you for: when trust breaks, it breaks everywhere at once. One event, and simultaneously your auditors trust you less, your regulators trust you less, your customers trust you less, your vendors tighten terms, your insurers re-rate you, and your employees quietly update their resumes. The damage is global.

The rebuild is not. There is no press release, no rebrand, no town hall that restores trust across all of those groups at once. Each stakeholder group rebuilds trust on its own timeline, through its own evidence, in its own language.

Auditors rebuild trust through control testing that passes without drama, period after period. Regulators rebuild it through responsiveness, transparency, and the absence of surprises. Investors rebuild it through consistent disclosure and the sense that management knows where its own risks are. Vendors rebuild it through payment behavior, contract discipline, and how you handle the first dispute. Employees rebuild it through whether leadership does what it said it would do, at small scale, repeatedly.

The practical implication: you cannot run trust recovery as a communications program. You have to run it as a portfolio of evidence programs, one per stakeholder group, each with its own definition of "proven." The companies that stall in recovery are almost always running one generic effort and wondering why the auditors are still difficult and the employees still cynical.

The crisis never stays in its lane

Lumber Liquidators' crisis originated in product and supply chain. I ran security and technology. On paper, those are different domains.

In practice, a reputational crisis revokes the benefit of the doubt for the entire company, in every domain, at once. Once an organization has been publicly wrong about one thing, every external party reasonably asks what else it might be wrong about. The auditors who might once have sampled lightly now test deeply, everywhere. The regulators who might have accepted a summary now want the underlying data. Questions that were never asked before get asked, and "we've never had a problem there" is no longer an acceptable answer, because that's precisely what the company would have said about the original crisis the day before it broke.

So the technology and security programs I inherited weren't being measured against a normal bar. They were being measured against a post-crisis bar, where every control had to hold up under adversarial review by people who were professionally obligated not to extend trust. PCI, privacy, infrastructure, access, vendor management, all of it was in scope for scrutiny that the original crisis had triggered but that the original crisis had nothing to do with.

If you take one thing from this pattern, take this: your trust posture is only as strong as your weakest domain under hostile examination, because that is where examination goes after any failure. AI companies should sit with this one. The first serious AI incident at your company will not result in scrutiny of your AI. It will result in scrutiny of everything, conducted by people who no longer assume your other assurances are true either.

Evidence beats assurance and the difference is architectural

The deepest change in my thinking from those years is the distinction between a program designed to pass internal review and a program designed to withstand external scrutiny. They look similar on an org chart. They are not similar.

A program built for internal review optimizes for assertion: policies exist, attestations are signed, dashboards are green, the annual review found no material issues. It answers the question "are we doing the right things?" with "we say so, and here is our own paperwork."

A program built for external scrutiny optimizes for evidence: any claim we make about our controls can be independently verified by a skeptical third party, from records we did not prepare specially for them, in a reasonable amount of time. It answers the same question with "check for yourself, and here is where to look."

At a post-crisis public company, only the second kind survives. Every framework we aligned to PCI DSS, GDPR, NIST CSF, ISO 27001 was implemented with the explicit assumption that the checker would be external, unfriendly, and thorough. That assumption changes design decisions all the way down. You log differently. You document decisions, not just outcomes. You keep the evidence of the control operating, not just the policy saying it should. You make risk acceptances explicit and signed, because "someone decided informally" reads as "no one decided" under examination.

Here's what surprised me: building for evidence is not much more expensive than building for assertion. It's maybe fifteen percent more work at design time. What's expensive ,cripplingly expensive, is converting an assertion-based program into an evidence-based one after the scrutiny has already arrived. That's the conversion pre-IPO companies attempt during diligence, and it's why security remediation shows up so often as the thing that delays an offering. The window to build for evidence cheaply is before anyone demands it.

Trust recovers at the speed of visible cadence

Early in a recovery, there is enormous pressure to promise the destination: we will be best-in-class, we will be a leader in governance, this will never happen again. Resist all of it. A company that recently failed publicly has no credibility to spend on big promises, and every unkept or vague commitment resets the clock.

What works is cadence. Small commitments, made specifically, kept visibly, reported honestly, including the misses, on a rhythm that stakeholders can set their watch by. Board reporting on the same risk framework every quarter, so directors can see movement rather than a new format each time that conveniently obscures comparison. Audit findings tracked to closure in the open, with dates, not absorbed into a vague "in progress." Regulator communications that arrive before the deadline with the bad news included.

The mechanism here is simple and human: trust is a prediction. Stakeholders trust you when they can predict your behavior. Every kept commitment, however small, improves their model of you. Every surprise, even a pleasant one, reminds them their model is unreliable. In recovery, boring is the asset class. I have come to believe that the single best trust metric available to a board is not any security score. It's the ratio of things management said would happen to things that then happened, measured over eight consecutive quarters.

You don't get to pause the business and that's actually the opportunity

The tempting model of crisis recovery is sequential: first we stabilize, then we fix trust, then we resume moving forward. No real company gets to run that sequence. While we were rebuilding governance and control credibility, the business was simultaneously launching e-commerce capabilities and implementing a new ERP, the kind of major modernization that carries real risk even in calm conditions.

The conventional read is that this is a burden: transformation under scrutiny, the hardest version of both. I came to see it as the opposite. Modernization is where you demonstrate the new operating model instead of describing it.

Every major initiative became a proving ground. The e-commerce launch showed that security could be embedded in delivery without stalling it, that the answer to "can we move fast?" was yes, with controls designed in rather than bolted on. The ERP work showed that decision rights, vendor governance, and data protection could operate under pressure, not just in policy documents. Auditors and board members didn't have to take our word that the company had changed how it operated. They could watch it operate.

This is the pattern I now push hardest with growth-stage companies: don't build the trust program beside the roadmap. Build it into the roadmap's flagship initiatives, because that's where every stakeholder is already looking. Trust demonstrated inside real work is worth ten times trust described in a deck.

The inside rebuild is the one nobody budgets for

The least discussed stakeholder group in any trust recovery is your own people, and they are the load-bearing one.

Employees who live through a public crisis carry it differently than outsiders imagine. Some are exhausted from years of extra scrutiny. Some are defensive, because they did nothing wrong and have spent years being treated as suspects by association. Some have learned the most dangerous lesson an organization can teach: that surfacing problems is punished and quiet is safe. That lesson is precisely backwards for recovery, because an evidence-based trust program runs on people voluntarily telling the truth about what's broken.

Rebuilding internal trust followed the same rules as external: evidence over assurance, cadence over promises. When someone raised a risk, the response had to make raising it worth it, visible action or a visible, honest decision not to act, with reasons. When leadership committed to a fix, the fix had to happen, because the workforce was scoring our kept-commitment ratio just as precisely as the auditors were, and with better data.

I'll state this one plainly: no company can be more trustworthy externally than it is internally. The gap between what employees know and what the company claims is the size of your next crisis.

Trust is demonstrable — so demonstrate it before you have to

Put the patterns together and they compress into one sentence: trust is not a reputation you hold, it's a claim you can prove, and the proof has to exist before the demand for it arrives.

At a post-crisis public company, we had no choice — the demand had already arrived, from every direction at once, and we built the proof under examination. That's the expensive way. The reason I write about this now is that a growing share of companies are heading into the cheap-way-or-expensive-way decision without realizing it.

Pre-IPO companies will face S-1 diligence teams whose entire job is refusing to accept assurance. AI companies are operating in front of regulators, enterprise customers, and plaintiffs' attorneys who are all, in different ways, asking the same question my auditors asked: not "do you say this is under control?" but "show me." Financial services firms have lived under this standard for decades; everyone else is arriving at it now.

The companies that will navigate this well are the ones that internalize the crisis-recovery lessons without the crisis: evidence-based by design, one proof program per stakeholder, cadence over promises, trust demonstrated inside the real work, and an internal culture where the truth travels upward fast.

If a skeptical third party showed up tomorrow — an S-1 diligence team, a regulator, an enterprise customer's security office, a board of directors that just read a headline about your industry — could you prove your trust claims from evidence, or only assert them from policy?

That question has a knowable answer at every company. The only variable is whether you find it out on your schedule or someone else's.

Tyson Martin is a trust, security, and AI governance executive who has led through regulated launches, public-company crisis recovery, and complex ownership transitions. He advises boards and executive teams at companies where trust is priced — by investors, regulators, and enterprise buyers.

Tyson Martin is the executive public and pre-IPO companies in financial services, AI/data, SaaS, and cloud hire to make trust a measurable asset, one accountable answer to Is it secure? Is it resilient? Is the AI governed?

© 2026. All rights reserved.

Navigation

Free Resources

Contact

Stay ahead of your next board agenda

Sign up for Reports & Learnings From the Boardroom. Plain-English AI and cyber governance insights, biweekly. No pitch.