This website uses cookies

Read our Privacy policy and Terms of use for more information.

What you'll learn

  • Why most vendor conversations fail before they start: the buyer isn't a buyer yet, and Andy's "nine buyer truths" (which he condenses to three — location, problem, urgency) explain what a CISO has to actually believe before any product pitch lands.

  • How a field CISO earns credibility instead of burning it — by giving the "pre-pitch talk" about the problem and then getting out of the way, not by dragging their friends onto sales calls.

  • The split Andy sees coming for the CISO role: a junior "CISO/director of IT" title with no real authority, versus the chief-technologist path where you own AI adoption, cost, and safety — and what to do now to land on the right side of it. 

Description

Andy Ellis was Akamai's first CISO and ran security there for more than two decades while the platform grew to carry over 30% of global web traffic. He's a 2021 CISO Hall of Fame inductee, an investor and advisor, and the author of 1% Leadership and the free guide How to CISO. These days he spends his time telling security vendors why their go-to-market keeps burning bridges with the exact buyers they're chasing. This conversation is about that gap — and about what CISOs on both sides of the table, buyers and field-facing sellers, get wrong about how the sale actually works.

The through-line is simple: enterprise security sales pretends everyone in the room is already a buyer, when most of them don't yet believe the thing they'd need to believe to buy. Andy walks through his three gates — do they have a location with the problem, is it urgent, and are they the person who owns solving it — and shows why product marketing only matters after those are cleared. He's blunt about the incentives that push reps to "pick all the damn berries," about the field-CISO role that's easy to do badly, and about where the CISO job is heading as companies pivot to agentic systems and token-metered AI. It's for security leaders who buy, security leaders who've moved into GTM-adjacent seats, and anyone trying to figure out what "credible witness to the risk" means when the business is moving fast.

What we cover

  • "Pick all the damn berries" — why metrics like first-appointment counts drive reps to hammer every contact and destroy their company's reputation in the process.

  • "This is not a sales pitch. My first thought is... bovine excrement" — how the moment a CISO smells a pitch, their defenses go up and nothing lands.

  • "Do not abuse them... these are entry-level salespeople" — Andy's case for being charitable to the SDR, and his "vendor rebuff" email template.

  • "You're lending your gravitas to the problem" — the right way to run a field-CISO role, and why calling your friends to take vendor calls will cost you your network.

  • "Nobody's going to a seed stage company and buying a platform" — why seed, Series A, B, and C are different animals selling features, products, and repeatable motions.

  • "It's the reason why while I was a CISO, I had this email template" — how customer champions, not milked-for-freebies CISOs, should fill a steak dinner.

  • "Why am I the one in the line of this and not the product manager?" — the product-launch veto story that reshaped how Andy thinks about risk ownership.

  • "You've got 91 days" — the window a new CISO has to prove they're the change agent the executive team wanted.

     

Thank you to our Sponsors:

→ Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North.

→ Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending.

The conversation

The whole industry pitches as if you've already decided to buy.  

Andy's starting point is that go-to-market in security borrows a consumer model that doesn't apply. When you walk into an Apple store or onto a car lot, you're already a buyer — the only question is which one. Enterprise security treats every conversation the same way, as a deal that's obviously already there, and skips the part where the person hasn't decided a problem is worth solving at all. 

"If the person's not a buyer, like their defenses are all up and you can't convince them of anything the moment they think it's a sales pitch."

— Andy Ellis

He'd rather people think in terms of cultivation than closing. The berry metaphor does the heavy lifting: if you're measured on how many ripe berries you pick today, the way to win is to strip the whole field and sort the ripe ones out afterward — because nobody measured you on preserving berries for tomorrow. That's what first-appointment metrics reward. The cost isn't just wasted calls; it's that "they're learning the names of vendors as someone not to interact with." Stuart's addition is that the SDR making those calls is a product of their environment — told to win at all costs because the Series B might not come — and Andy is emphatic that the entry-level rep is the wrong target for a CISO's anger. Name and shame the company if you want. Be kind to the person.

The great reps are an independent channel the company mistakes for its own

One of the sharpest asides is about what a genuinely good sales rep actually is. They aren't a function of the company that employs them; they're a portable book of trust.

"Great sales reps are basically independent channel sales. They have a book of people that trust them. They'll go find a good product and they'll sell to that book and then they'll move on to another great company."

— Andy Elli 

Stuart runs the math out loud: a strong rep might have 100 to 200 real relationships, and their product is a fit for maybe 15% of them. Close fifteen enterprise deals a year and you're driving a very nice car. The trap for the company is believing this rep proves the sales motion is solved, when what they really had was one person who knows how to sell. Find the right product, sell to the fifteen people it fits, move on. It's a useful frame for CISOs too — the rep who keeps showing you things that don't fit isn't serving their book, they're spraying it.

The field-CISO job is easy to do wrong 

This is the section most relevant to the quiet migration Conor names — operators leaving institutional seats for field CISO, CISO-in-residence, and CISO-in-residence roles. Andy's warning is direct: a lot of companies will hire you to be a sales rep, and you'll fail, because you're not one. Worse, you'll spend down the trust that made you valuable when your CISO friends take calls as a courtesy to you and never intend to buy.

"What you're really saying is this is a problem that is so urgent that I think it should be fixed. And this is a way to fix it."

— Andy Ellis

The right move is to lend your gravitas to the problem, not the logo. Give the talk that gets people thinking about the problem — the pre-pitch talk — so their brain is primed before they ever hit a booth or a demo. Then, when there's a real sales motion, be the executive sponsor and the back channel: the person a CISO can call if the rep is being difficult. Andy insists a good field CISO should be able to out-pitch the rep, so the reps can steal the pitch — but should almost never be the one delivering it in the room.

Conor and Stuart both point back to what Conor built at RSA: a lounge of interesting rooms with topics that weren't "here's how Sysdig fixes cloud security," which let problems surface naturally with the brand attached but not shoved forward. Conor extends the logic to its endpoint — when the prospect finally asks about the product, the field CISO's job is to keep their mouth shut, let the professionals work, and reappear afterward as lived experience. "That works," Andy says of the shortcut, when a diligence team waves you through because they heard you speak. On one side of his brain, that's not how it's supposed to work. On the other, fantastic.

The three gates before anyone should talk about product

 The framework Conor wants to spend an hour on is Andy's nine buyer truths, condensed into three so it's easy to carry: a buyer needs a location with a problem, the problem has to be urgent, and the person in front of you has to be the one who owns solving it — with peers and stakeholders who agree.

"If you are selling AI security and you've got a company that is not using AI at all, they don't even have a location with a problem."

— Andy Ellis

He illustrates with an op-ed he wrote years ago arguing the CIO role would collapse into the CISO as everything went SaaS. It was one of his most-read pieces — and its real job was to get people to believe they were SaaS-native companies, because they had to believe that before they'd prioritize SaaS-security posture problems. That's the point of messaging: you set the belief that makes the problem urgent, long before you argue your product is better than the alternatives.

The organizational gate is where AppSec keeps dying. The CIO, the CISO, and the head of engineering disagree over who owns the problem, and underneath all of it, "the developers ultimately do not want this problem solved, especially not by the CISO." Only after those six earlier questions clear do you get to product marketing — is the solution viable, is it better, is there budget. Andy's blunt verdict: most companies start exactly there, and if you haven't cleared the earlier gates, "you're already screwed." He also ties this to stage — a seed company is selling a feature and calling it a product; a Series A has a bespoke, founder-dependent motion; you've reached Series C when a rep can be hired, trained, and set loose with no founder anywhere in the pipeline. Hiring a Series C CRO into a two-rep Series A just builds overhead on nobody 

Be a better buyer: say no fast, and take notes

The buyer-side advice is short and unglamorous: be honest, and say no quickly. The CISO who hems, equivocates, and says "come back next quarter" is wasting everyone's time, including their own. "I use one of your competitors and I love their product" is a gift — it's feedback the vendor can act on. Andy's also skeptical of the consortium-dinner economy, where a project manager sells access to a table of CISOs who show up for the freebies. If you're going to run a steak dinner, at least half the room should be existing customers, because those are retention conversations and your champions sell better than your reps. 

"The number of times I have seen vendors who are in a room with a group of CISOs who are talking and nobody is taking notes."

— Andy Ellis

He calls that criminal negligence, and it's the most actionable line for vendors in the episode. Run the table so each person answers a real question as part of their intro, let the side conversations become your best sales calls, and have someone capturing eight pages of notes so the rep can follow up on what each CISO actually said — instead of the generic "great catching up, let's talk tomorrow" that forces the prospect to rehash their whole problem from scratch. The pattern extends to the human stuff: pick a lane — football, running, fitness — and get good enough at it to talk to anyone. Curate your background so every object is a conversation piece. Andy's version of the CISO-whisperer move is the most counterintuitive: telling a prospect "we're not the right fit for you right now" buys instant credibility, especially if you point them at the IAM or SSO they should buy before they ever come back to you.

The CISO splits into two jobs, and only one has a future you'd want

Looking ahead, Andy sees the role bifurcating. One branch is a CISO-in-title-only — often paired with director of IT at privately held companies — where the executive label is dangled but the liability protection, the D&O coverage, and the seat aren't real. Take it to move somewhere else if you must, but see it for what it is. The other branch is the chief technologist: a CISO who also carries CIO and possibly chief-AI-officer responsibility, and who wants to solve problems rather than say no.

"We didn't show up and say what IT said. IT told them to stop and they said, screw you... We showed up and said, how can we help you do this better?"

— Andy Ellis

That, he argues, is the origin of the discipline, and AI is the chance to return to it. If you're not advising your company on how to use AI affordably, effectively, and safely — including the shift from all-you-can-eat to paying for token usage — you're not set up to be the technologist the business needs. The tactical advice is the one most people get wrong: don't bring this to the table. Executive authority is reputational, so you go to the CMO and the CRO privately, help each of them look smarter, and only convene the whole leadership team once you already have their confidence. "Never surprise the team with a conversation."

The frame that ties it together is Conor's borrowed line — the CISO's job is to be a credible witness to the risk. Andy sharpens it with the product-launch story: handed a veto over launches, he discovered that being the one in the line of fire made him the judge, not the witness. The fix was to make the product manager articulate the risks and own the decision, while security only judged how faithful that articulation was. The next red-flagged launch, the head of products killed it himself — and told the team no one should ever hear those words from Andy's mouth again. Witnessing the risk is one hat. Getting the most reward out of it is another. "Why would we think our job is to eliminate risk? No, it's to eliminate wasteful risk." And the clock on all of it is short: 91 days to convince the executive team you're the change agent they wanted, which is why Andy's first ebook — free at howtociso.com — is a first-91-day guide meant to be read before you ever take the seat.

Show notes

  • Guests — Andy Ellis, Akamai's first CISO (led security there 20+ years while the platform grew to carry 30%+ of global web traffic); 2021 CISO Hall of Fame inductee; investor and advisor; author of 1% Leadership and How to CISO; now advising security vendors on go-to-market.

  • Books mentioned — 1% Leadership (Andy Ellis); How to CISO (Andy Ellis, free at howtociso.com).

  • Frameworks / models / tools named — nine buyer truths / nine buyer beliefs (condensed to three: location, problem, urgency); the three organizational gates (owner, peers, stakeholders); seed/Series A/B/C sales-stage model; first-91-day CISO guide; "credible witness to the risk"; "vendor rebuff" email template; the four S's (speed, safety, stability, scalability); Duo; zero trust network access; SaaS security posture management; TPRM.

  • Other people / shows / resources referenced — Gary Hayslip (field-CISO guide); Apple (consumer sales model); RSA Conference / Sysdig Lounge; DerbyCon; Heartbleed; the New England Patriots and "deflate gate"; the Green Bay Packers; Vibram FiveFingers.

Hosted by Conor Sherman and Stuart Mitchell.

Keep Reading