What makes CISOs buy and what turns them off? This is a question that the SASIG community has been addressing for many years now. Product and services are vital to an effective security regime so vendors and users need to find a way to work in partnership and harmony, as equals. But how do CISOs find the right solutions, from the right suppliers?
The Security Awareness Special Interest Group (www.thesasig.com) was founded in 2004 as a safe, trusted environment for those interested in or responsible for the cyber resilience of their organisation to meet, share knowledge and expertise, and exchange experiences without fear of a hidden agenda or sales pitch. Membership is drawn from government, the public and private sectors, law enforcement and academia. Our 11,000+ membership representing some 4,500 organisations of every size and sector are never shy in expressing their views, and regularly give us positive suggestions about helping resolve this enduring dilemma:
- CISOs are overwhelmed by a constant tsunami of cold calls and clumsy pitches; many refuse to answer their phones to anyone, and their inboxes become clogged up with unsolicited emails. They are reluctant to attend conferences, trade fairs and exhibitions for fear of being mobbed, both there and afterwards with even more unsolicited approaches.
- CISOs focus on threats, not solutions. They identify their needs and then look for appropriate solutions – not the other way round! Too often, they say, the vendors come with their proprietary solutions without understanding the problem – as my old mum would say, “finding a button and having a coat made to match.”
- Personal relationships (and thus a level of established trust) are vital; “People buy from people that they know, like, and trust” (Bob Burg). CISOs are no different, they prefer to buy from vendors they know and trust.
Our members have offered a host of helpful suggestions about how suppliers old and new might gain that trust, and better court them now and into the future:
- Cold calling/cold emails just won’t work. Indeed, this is counter-productive.
- Stay real. Don’t promise the world. Vendors who claim they have all the solutions to all the CISO’s problems is an instant turn-off.
- Research the prospect’s needs and resources, and propose appropriate solutions that the client can afford.
- Build on a small initial assignment to prove your worth, show reliability and build trust. Case studies are gold dust. Reference sites are vital.
- Help CISOs show success. The focus should not always be on preventing loss, but on enabling business growth and success – this will help the CISO to justify spend.
- CISOs will speak to their peers and ask for recommendations about who they’ve used to resolve a challenge. They will also keep an eye on the changing threat landscape to try to anticipate problems/solutions.
- CISOs keep an eye on private investors, they look for where the new money is being invested, this is a great indicator of good products/innovations/start-ups.
- It’s not just about a product/solution’s cost and performance, it’s also a matter of the supplier’s resilience and stability. How good a partner will a vendor become over time is an important element in the choices to be made?
- Return on Investment (RoI) is essential, but also tough to measure and prove. This is where strategy comes up against point solutions, and where short and longer-term benefits collide. Inevitably, purchasing judgements become subjective and “soft ROI” (benefits seen in less tangible ways) should come into play (e.g. financial vs reputational costs).
SASIG is privileged to work with our small cohort of Supporters and Contributors – vendors that have been selected for their integrity and maturity as well as the effectiveness and innovation of their propositions. They use their place within the SASIG family to foster contacts with existing clients and prospects, to contribute to the debate, and to develop over time those direct and trusted relationships with user organisations that will inevitably lead to business. They are within the SASIG “circle of trust”, a position highly valued and respected by each of them. They interact regularly with the membership, gently dissolving the barriers between vendor and user. This is, I believe, how it should be done. It takes longer, but the results are worth the wait. It’s about growing oak trees, not pine trees. It’s about less haste, more speed.
And finally – can we all try to be nice to each other? Vendors are not the CISO’s enemy, even though some may occasionally behave so. Similarly, I see that some CISOs become understandably defensive and discourteous as they react to the onslaught of approaches. We are all part of the same continuum. We all contribute to the protection and resilience of the corporate community whichever side of the so-called “divide” we sit. Most of us, in whatever role we occupy, are highly professional and talented in our own rights and we all deserve respect. So, as a special plea, can we all try to be nicer to each other, including those who reach out to us for whatever reason? Let’s try and show compassion and tenderness towards all our fellow professionals. It costs nothing.

