“There’s Nothing More Important Than Having an Opinion”
Ian Hadwen has run a P&L, led product, owned commercial risk, and now drives revenue at Protecht. A conversation about seeing risk from every seat — and why the best risk decisions start as a quiet word at the board.
Ian Hadwen describes himself, cheerfully, as a contrarian. Over a career that has taken him from telecommunications through financial services and commercial risk at Equifax — where he ran a P&L spanning product management and sales — to leading revenue across APAC at Protecht, he has made a habit of picking holes in received wisdom and asking whether there’s a better way.
That instinct shapes how he thinks about risk. Having sat in the GM chair, the product chair, the commercial-risk chair, and now the revenue chair, Ian brings a vantage point most people in the industry never get. We talked about the upside of uncertainty, why culture beats compliance, and what actually separates organizations that take risk seriously from those that treat it as a box to tick.
You’ve held responsibility for parts of the business well outside sales. How has that shaped the way you see the world?
It tempers things. At Equifax I was running the P&L for the business, managing two major product streams, with product management and special solution sales all under me. You’re operating at 40,000 feet rather than 10,000 feet, looking at the whole picture — roadmap strategy, the cost of the business, headcount, what you can and can’t do for everyone.
At Protecht I’m much more in the trenches, in every deal. It’s a different way of thinking, and that’s the whole point — you take that maturity and recognize the scale and the activities are simply different. But the P&L lens never leaves you. I think about the cost of responding to a formal RFP, for instance, in a way a lot of people in sales never do. It’s a finite resource you have to balance.
You came into the risk world from the outside. What did that feel like?
Honestly? As a line manager at Equifax I was asked to complete risk assessments and get involved in audits, and I passionately disliked it. I was on the receiving end of it through a clunky legacy system, and it was a genuinely poor experience. So when someone later asked whether I’d be interested in non-financial risk, my first instinct was hesitation, because what I’d seen was terrible.
Then I thought — hang on, if you talk to the team at Protecht and see what good actually looks like, there’s your answer. That’s part of why we’ve grown. We have 350 customers in APAC since I’ve been here, and it’s because we have genuinely compelling product capability. It’s good stuff we’re selling, not just selling activity.
You have a board and executive lens as well. What’s the biggest misconception executives still have about risk?
It depends on the geography. In the US, compliance is such a huge driver — people are afraid of getting fined, the stick rather than the carrot.
Here in Australia, with the heritage of the ISO 31000 standards, enterprise risk is more in the DNA. There’s more acceptance of the principles. The parallel I draw is cultural — we’re an extraordinarily compliant society. More speed cameras and rules on the roads than anywhere I’ve been, and we follow them, we queue, we don’t argue. I’m a contrarian, so I sit there and want to ask: are you sure? Are you really sure? There are alternatives. You have to stretch yourself, and I don’t feel we always do.
I’m a contrarian. I sit there and ask — are you sure? Are you really sure? There are alternatives.
What separates companies that genuinely engage with risk from those that are superficial about it?
It’s tone from the top. If risk is a real thing at the board and CEO level, it becomes a priority — and more than that, it becomes a default part of the conversation. If an organization is about to launch a new product, the question is automatically there: has a risk assessment been done? What’s the downside, the upside, where does this lead us?
We did this ourselves entering the healthcare market. I acted as a bit of a brake on the thinking — are we aware of the privacy impact? It’s highly likely we’ll be capturing personally identifiable information, which as a GRC provider we don’t hold today. So what are the dimensions of change there? You have to think about it more deeply, ideate about it, ask where it could take us and what the potential risks are. If that becomes a normal part of the conversation rather than “let’s just go to healthcare,” you avoid unintended consequences — and you might tap into a whole new upside.
Because that’s the thing people forget: risk is the effect of uncertainty on objectives. That’s the ISO definition. Uncertainty doesn’t mean bad. It can be good. It’s about understanding the dimensions of the idea.
Risk is the effect of uncertainty on objectives. Uncertainty doesn’t mean bad — it can be good.
Protecht has been unusually effective at making that business-enabler message real. What’s the secret sauce?
Access to knowledge. Anyone can build a forms-based platform — that’s been proven many times over. The secret is making it tangible, with the support of people who actually make it work. We have qualified risk people from the very top of the organization — our thought leaders and boffins — all the way through advisory, implementation, and the customer journey. We can help you at every stage.
That’s what we have to protect, funnily enough. If we don’t do that well, customers fade away and churn goes through the roof. Our churn rate is 1.5%, and that’s not a coincidence — it’s a deliberate strategy. It’s an enterprise system, not Netflix. You don’t just download it. You need someone to help you build it, design it, and manage it over time. That’s what people miss.
Where’s the best entry point into a customer?
Our prime buying centers are CROs, or whoever owns risk. But honestly, one of the best entries is through the board. The G in GRC — governance — is a board responsibility. They’re there to observe whether the business is well run and compliant. So if the board says something, the CEO generally falls in line and acts on it. A quiet word from a board member can have a big impact on management decisions, and it doesn’t have to grind through a formal procurement process. I like the board dynamic because you can actually get change. And often a single board member sits across multiple organizations, so a champion in one place becomes a champion in several.
You’ve said you don’t want to be seen purely as a salesperson. Say more.
I’ve always felt I’m more of a solution person — I’m trying to fix a problem and help people, and revenue is an outcome of that. A guy I worked with at Equifax put it well: don’t even worry about the revenue, because it comes from the relationships you build. We get very mechanical about it — how many calls, how many of this and that. It doesn’t actually matter. What matters is whether you’ve built relationships with enough people that they come to you first. Then they’re buying from you rather than you selling to them. It’s a different dynamic entirely. Everyone wants to button it down to dollars and cents, but that’s playing for quantity. The difference is quality.
When you’ve built enough trust, they’re buying from you — not you selling to them. That’s a different dynamic entirely.
As you think about thought leadership in risk, what is important to you?
Less is more. What I do believe in is having a point of view. Put an opinion out there and back it up, because there’s nothing more important than having an opinion.
And away from work?
Most of my interests are sporting. I’m a keen snow skier, I enjoy sailing, and I still play soccer — in the very old division these days, where the main concern is holding my knees together. The articulation joints aren’t what they were, but I do what I can.
Ian Hadwen leads revenue across APAC at Protecht. This conversation has been lightly edited for length and clarity, and was produced by Eudai as part of Protecht’s executive personal-branding and thought-leadership program.