Stage 1

Selling to a CISO

A CISO owns risk they can never fully remove and gets pitched constantly. Here's what they're measured on, which signals matter and how to open.

Kevin French
· 3 min read

A CISO is the most pitched buyer in the enterprise, and the most skeptical. They own risk they can never reduce to zero, they answer to a board that wants it at zero, and the vendors in their inbox all promise to get them there.

The way in is to sound like none of them.

What they own

Security strategy, the security team, incident response, and the controls that keep the company out of trouble with regulators and auditors. In many companies they own third-party risk too, which means they're the ones reviewing your firm's security questionnaire.

Where they sit matters. A CISO reporting to the CIO is often fighting for budget inside IT. One reporting to the CEO, the general counsel or the board has more independence and usually a bigger mandate.

What they're measured on

Not having a breach is the obvious one, and it's unfair. Nobody gets credit for an incident that didn't happen.

So they're measured on things they can show. Audit findings closed. Compliance frameworks met. Time to detect and respond. Coverage of critical systems. How clearly they can explain risk to the board in business terms.

That last one is underrated. A CISO who can't translate risk into money loses budget fights. Work that helps them make that case is work they'll fund.

What they ignore

Fear. Security vendors lead with threats and breach headlines. The CISO lives with those daily and stopped reacting years ago.

Tool pitches. They have too many tools already. Consolidation is more on their mind than addition.

Anything that adds work to a stretched team. Security teams are hard to staff, and a CISO will turn down a good idea if it means their people have to stand it up.

Signals that matter most

A new CISO leads. The first 90 days are when they assess the program, find the gaps and decide who they trust. They're often brought in after something went wrong, which means a mandate and a budget.

Business pressure is next, and for security it's often regulatory. A 10-K risk factor that grew since last year. A new rule in their industry with a compliance date. An acquisition that brings in systems they now have to secure.

Hiring for the problem is strong too. A cluster of security engineering or GRC posts says the team is building and probably behind.

And disclosure. A company that reported an incident in an 8-K is almost always about to spend on security. Be very careful how you approach that one. More below.

An opener that works

Say a regional health plan hires a new CISO, and its latest 10-K added language about third-party vendor risk.

Saw you joined as CISO a few weeks after the 10-K expanded its section on vendor risk. That usually means the board asked for a clearer view of third parties, and it lands on your desk early. My guess is the hard part isn't the policy, it's that nobody has a complete list of which vendors touch member data. Is that right, or is the bigger gap somewhere else?

No fear, no tool, no breach headline. A specific guess about their program and an easy way to correct it.

What to avoid

Don't reference an incident in a first message. If the company disclosed one, the CISO is living through it. A seller who opens with it looks like an ambulance chaser. Write about the program and the work ahead, not the event.

Don't oversell. "Eliminate risk" and "complete protection" are claims a CISO knows are false. Making them tells the reader you don't understand the job.

Don't ignore the rest of the committee. Security spend above a certain size usually needs the CFO, and often the CIO if the work touches infrastructure. A security architect or engineering lead is the technical voice. Write to each with a hypothesis about their part. The method covers how to split one account across three people.

And be ready for scrutiny. A CISO will look at your own security posture. Have your questionnaire answers, certifications and policies ready before you write. Selling security work from a firm that can't pass a vendor review ends the conversation.

CISOs answer sellers who understand the job is managing risk, not erasing it. Write like you know the difference.

See which of your accounts are moving.

Stage 1 reads your site, finds accounts that fit and checks their filings and news. Your first Board in about two minutes. Free for 14 days, no credit card.