- CISO Series Newsletter
- Posts
- Join us tomorrow for "Hacking the Analyst Firms"
Join us tomorrow for "Hacking the Analyst Firms"
Join us TOMORROW, Friday [06-12-26], for "Hacking the Analyst Firms"
Join us Friday, June 12, 2026, for “Hacking the Analyst Firms: An hour of critical thinking about how vendor rankings get made and who they're really for.”
It all begins at 1 PM ET/10 AM PT tomorrow, with guests Chris Ray, field CTO, GigaOm and, Fernando Montenegro, vice president and practice lead, cybersecurity, Futurum Group. We'll have fun conversation and games, plus at the end of the hour we'll do our meetup in breakout rooms.
Defense in Depth
CISOs Buy For Selfish and Politically Risk-Averse Reasons (Not Because Your Product is the Best)
Everyone says they want the best security tools for their organizations. But sometimes the best tools are the ones a CISO can defend buying. The phrase "no one ever got fired for buying IBM" still rings true even if the vendors have changed. Why aren't we more upfront about this kind of motivation?
Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Howard Holton, CEO, GigaOm. Joining is Tyler King, senior director - threat operations and response, Sinclair.
Listen to the full episode here.
Career insurance
Security purchases are personal before they are technical. "We aren't risk-averse. We're risk-aware. We know who carries the blame. And it's never the vendor," said Kunel Patel, CISO, With Intelligence. What kills deals, he added, is backchanneling. "Going around me because I said no or asked for more time. That's not sales. That's undermining trust. Every CISO remembers which vendors did that. And that list gets shared." Ty Nelson of Google has reached a similar conclusion after years on the buying side. "Every security purchase is a personal risk decision masquerading as a tech evaluation. The product is secondary to trust, proof, and survivability. I don't buy tools, I buy cover. Cover for my team, my board conversation, my reputation and my career." Features, he said, don't close deals. "Credibility does."
In the trenches together
The product has to work, but it's rarely what makes or breaks the relationship. "It's the personal and professional risk in making the decision that makes the difference," said Craig Garrod of ScienceLogic. "If the customer is in the trenches, will the vendor team be with you after you call them?" Jason Little of ThoughtSpot traced everything back to a line from a mentor: "People don't buy the best software, they buy software from people they trust." Trust in the software, trust in vendor viability, trust in ROI, and trust in the implementation plan.
Who are you actually selling to?
The instinct to reach for the highest-ranking person in the room may be the wrong one. "People are always trying to get to the highest person and ignoring the people at the coalface who are actually going to use the product," said Dwayne Rendell of Rapid7. His theory runs the other direction: "If you have a happy, enabled team, they keep the place running, which equals happy CxOs." Ed Mohr of Seceon raised a harder problem with the defensibility instinct. "When I hear that a product needs to be defensible, I think of companies that advertise on CNBC or the like, creating a perception that is carried on to the board." He has spoken with CISOs who are aware of known gaps in these products and "literally don't care because the name is defensible. Yet many of these companies have had substantial incidents, both self-inflicted and from bad actors, and they remain defensible."
Common sense, uncommon in sales
Buyers apply the same instincts to vendor decisions that they use everywhere else in their lives. "Checking product reviews before a purchase online, sticking with brand loyalty even though the competitor is running promotions, avoiding restaurants or brands because of that bad experience we had that one time," said Kraig Kraning of Flossy. Under quota pressure, that common sense tends to disappear on the seller side. "None of us would have friendships if we only ever talked about ourselves, never took an interest in anyone else, and simply pushed our agenda. And yet a lot of GTM motions feel exactly that way." The buyer experience, he argued, would look very different "if sellers showed up truly interested in the buyer, instead of simply attempting to make their product sound interesting enough to buy."
Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you’re not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now.
Huge thanks to our sponsor, Material Security
Subscribe to Defense in Depth podcast
Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "Defense in Depth" into your favorite podcast app.
Cybersecurity Headlines - Department of Know
Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will feature Brett Conlon, CISO, American Century Investments, and Jason Thomas, senior director, technology security, governance, and risk, Cystic Fibrosis Foundation. Join us on YouTube and catch up on what shaped the week in security.
Thanks to our Cybersecurity Headlines sponsor, Doppel
Participate! Add our live shows to your calendar
Learn more about all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar, Outlook, or export an .ics file
Cyber chatter from around the web...
Jump in on these conversations
"Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked" (More here)
"Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft's Disclosure Process" (More here)
"Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can't match" (More here
Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.
Cybersecurity Headlines - Daily News Shorts
Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.





