How to Earn Attention from a Busy Enterprise CISO

562 views
•
May 15, 2019
by
RSAC Cybersecurity
YouTube video player
How to Earn Attention from a Busy Enterprise CISO

TL;DR

Approach the people who evaluate security products, such as managers, individual contributors, and security architects, instead of relying on a cold pitch to the CISO. A relevant subject line may earn a referral, but adoption still depends on technical review, strategic alignment, internal advocacy, and evidence that the product addresses a current organizational need.

Transcript

Uh, I'm Will Wilkinson. I'm the general manager of WSJ Pro, and it's an absolute pleasure to be here, even at short notice this morning. Uh, that snow turns out you can't-- There's nothing in cyber you can do to melt the snow. That's a real problem. Um, this is a forty-minute session, so I'm gonna get straight into business. Uh, we're gonna cover a... Read More

Key Insights

  • A CISO's primary responsibility is delivering promised outcomes while ensuring the security team has the people, resources, and organizational support needed to make progress. Vendor conversations must compete with operational priorities, project obstacles, security monitoring, customer commitments, and broader executive responsibilities.
  • Partner security is a significant concern for both large enterprises and cloud-native companies. Organizations may rely on providers for infrastructure, email, cloud platforms, human resources systems, applicant tracking, sales systems, data centers, and support at remote locations, creating many relationships that require security attention.
  • Vendor engagement can occupy a meaningful share of a CISO's schedule. Dan Glass estimated that he spent 10–15 percent of his time dealing with partners at American Airlines, including occasional two-day off-site sessions rather than a uniform block of time every day.
  • Cold vendor email is often ignored because a CISO's inbox already contains substantial internal traffic and many unsolicited approaches. Glass reported receiving about 300 internal emails each day, which left little time for messages from unfamiliar vendors without an immediately relevant subject or recognized relationship.
  • A compelling email subject can earn attention without securing a direct sales meeting. When an unfamiliar offering appeared relevant, Glass usually forwarded it to a security architect or responsible manager who could investigate the product and determine whether further evaluation was justified.
  • A promised 15-minute meeting is difficult for a CISO to accept because the actual duration is unpredictable. An irrelevant pitch may end in five minutes, while an interesting discussion can expand into a deep dive and disrupt the executive's next scheduled commitment.
  • Internal advocacy is often more effective than beginning with the CISO at a large organization. A vendor can engage a manager or individual contributor, build interest, and seek permission for a laboratory trial before requesting attention from the senior security executive.
  • Product selection is a collaborative process rather than a decision made by the CISO alone. Security architects question vendors, conduct whiteboard discussions, assess alternatives, and present candidates for strategic review, including possible replacements for current partners and products offering a genuinely different capability.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can a security vendor get a busy CISO's attention?

A security vendor should lead with a concise message tied to a recognizable organizational need, but should not assume that the CISO is the best first contact. In a large enterprise, managers, individual contributors, and security architects are more likely to evaluate the product. Their interest can create internal advocacy, support a laboratory trial, and eventually bring a credible recommendation to the CISO.

Q: Should a cybersecurity vendor contact the CISO first?

A cybersecurity vendor does not always need to begin with the CISO, particularly in a large organization where the executive may not make individual product decisions. Starting with a manager, individual contributor, or security architect can be more productive. Those employees can examine the offering, test it, challenge its claims, and determine whether it fits the organization's security strategy before involving the CISO.

Q: Why do CISOs ignore cold sales emails?

CISOs ignore many cold emails because vendor messages compete with urgent internal responsibilities and a large volume of correspondence. Dan Glass said he received about 300 internal emails each day at American Airlines, in addition to external approaches. Messages from unfamiliar senders were largely ignored unless a subject caught his interest, while established vendors and internal colleagues received more immediate attention.

Q: What should a vendor put in an email to a CISO?

A vendor email should make its relevance apparent quickly because the CISO is unlikely to spend much time interpreting a broad or generic pitch. The subject should connect the offering to a recognizable security concern, existing partner category, or strategic need. Even when the message succeeds, the likely outcome may be a referral to an architect or manager for investigation rather than a direct purchase discussion.

Q: Why is a 15-minute vendor meeting difficult for a CISO?

A 15-minute request creates uncertainty because a vendor discussion rarely fits that exact duration. Dan Glass said an irrelevant pitch could end after about five minutes, while a highly relevant offering could trigger an engaging deep dive that ran into the next meeting. The time request therefore represents not only a calendar slot, but also a risk of disrupting other executive commitments.

Q: How do security architects influence vendor selection?

Security architects provide the detailed evaluation that a senior security executive may not perform personally. Glass described architects asking structured questions, challenging ideas, conducting whiteboard sessions, and putting vendors through their paces. The architecture team could then present candidates during a weekly review, including vendors that might replace existing partners or introduce a capability that appeared strategically worthwhile.

Q: How much time can a CISO spend working with vendors?

The amount varies by organization, but Dan Glass estimated that partner engagement consumed 10–15 percent of his time at American Airlines. He clarified that this was an average rather than a daily calendar block. Some days contained little partner activity, while the estimate also included concentrated commitments such as spending two days off-site with a partner.

Q: Why are third-party vendors a major security concern?

Third-party vendors matter because organizations depend on them across many parts of their operations. The discussion cited managed service providers, data center services, remote desktop support, email, cloud platforms, human resources systems, applicant tracking, and sales systems. Security leaders must consider how these relationships affect risk and must invest appropriate resources in securing partner interactions alongside traditional infrastructure.

Summary & Key Takeaways

  • CISOs focus first on delivering promised outcomes, supporting their teams, resolving blocked projects, handling operational fires, and checking security conditions. Vendor engagement competes against these responsibilities, so a sales approach must quickly demonstrate relevance to an existing problem, required resource, strategic objective, or partner-related security concern within the organization.

  • Large enterprises can depend on many partners, ranging from managed service providers overseeing thousands of systems to remote vendors supporting only a few desktops. Dan Glass estimated that partner matters occupied 10–15 percent of his time at American Airlines, although this time was unevenly distributed and sometimes included multiday off-site sessions.

  • Cold email rarely reaches the top security executive directly because CISOs receive heavy internal and external message volumes. A more effective path is to interest managers, individual contributors, or security architects who can test the product, challenge its claims, compare it with existing partners, and recommend it when it supports the security strategy.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚