#1752438: Recommendations to Reboot the Security Vendor Pitch

Description: When vendors get a meeting with a CISO, what's the right engagement format? If there is a more attractive format, how can you promote it to get more meetings?

The ten-minute test
Vendors get judged fast, and most of their limited time should go to proof, not preamble. Joel Bork CISO at DoubleVerify, laid out his format for a 20 to 25 minute meeting. One to two slides, delivered in three to four minutes, then straight into the demo. "If I can't put a UI to your tool within ten minutes, my attention is pulled elsewhere," he said. Mor Asher of MAS Cyber Security agreed that brevity works when the substance is there. A vendor bringing a real solution, not just a product, can deliver the message in 15 minutes. He called it a "teaser" meeting, one that quickly shows the value and leaves him wanting more.

Relevance beats format
The clock might not be the real issue. Chris May of Advantage Technology argued that meeting length distracts from what matters. "The meeting format isn't the core issue; it's vendor relevance and credibility," he said. CISOs engage when the conversation centers on their environment, their risks, and their goals, not generic ROI slides or format tricks. Respect for his time, he said, is measured in preparation and substance, not minutes. He'd rather spend 90 minutes with a vendor who understands his environment than 15 with one optimizing for a follow-up rate. Angel F. of Saronic Technologies made a similar case for homework over hustle. A little research goes a long way, and understanding his space and regulatory needs earns a vendor consideration. But claiming to meet requirements without the certifications or controls to back it up suggests the vendor just "googled a few buzzwords."

Price the problem or lose the room
Some CISOs want the hard numbers up front, not a promise of a follow-up call. Tim Hampton of Hermeus said he always asks vendors "how many zeros do you think this problem is worth." Too often, the answer is that pricing is reserved for a follow-on call, built on the assumption that a first meeting guarantees a second. If there's no alignment on the value of the problem and no interest in how the vendor solves it, he said, there is no second call. Dr. Jason Gamage, PhD, CISA, CISSP of Metapilot Academy sets similar expectations before the meeting even starts. He tells vendors upfront that he doesn't want marketing slides. He wants to hear immediately how the tool solves one of his problems, followed by why the vendor is innovative. That's enough for an intro call, and if he extends it, that's a sign of real interest. As the budget holder, he always asks for rough pricing and doesn't want to hear "I'll get back to you."

Whose meeting is it, really
Not every "yes" to a meeting is a straightforward buying signal. Glenn Bravy of Wizer framed the obligation as mutual. "Teach them something even if they don't buy," he said. "It's gotta be as much for them as it is for you." Most discovery calls, in his view, are valueless to prospects and waste their time. Duncan Mills of Bitdefender raised a different question about who's actually in the room. He asked how the idea of short, high-signal meetings squares with the conventional wisdom that buyers are 75 percent into their journey before ever taking a meeting. Are CISOs really taking meetings blind, he wondered, or is someone on their team already doing the legwork and recommending the meeting on their behalf.
More info: https://www.linkedin.com/pulse/recommendations-reboot-security-vendor-pitch-cisoseries-lydvc

Date added Sept. 3, 2026, 11:09 p.m.
Source LinkedIn
Subjects
  • PodCasts / Webcast / Webinar / eSummit / Virtual Event etc.
  • Security Management/Strategic Security/ROI/ROSI - CISO and Higher Level