When vendors get a meeting with a CISO, what’s the right engagement format? If there is a more attractive format, how can you promote it to get more meetings?
Check outthis postbyVal TsanevofCyberRisk Alliance, for the discussion that is the basis of our conversation on this week’s episode co-hosted byDavid Spark, the producer of CISO Series, andEdward Contreras, senior evp and CISO,FrostBank. Joining isJill Rhodes JD, LLM, CISM, svp, CISO,Option Care Health. Huge thanks to our sponsor,Teleskope.
The ten-minute test
Vendors get judged fast, and most of their limited time should go to proof, not preamble.Joel BorkCISO atDoubleVerify, laid out his format for a 20 to 25 minute meeting. One to two slides, delivered in three to four minutes, then straight into the demo. “If I can’t put a UI to your tool within ten minutes, my attention is pulled elsewhere,” he said.Mor Asherof MAS Cyber Security agreed that brevity works when the substance is there. A vendor bringing a real solution, not just a product, can deliver the message in 15 minutes. He called it a “teaser” meeting, one that quickly shows the value and leaves him wanting more.
Relevance beats format
The clock might not be the real issue.Chris MayofAdvantage Technologyargued that meeting length distracts from what matters. “The meeting format isn’t the core issue; it’s vendor relevance and credibility,” he said. CISOs engage when the conversation centers on their environment, their risks, and their goals, not generic ROI slides or format tricks. Respect for his time, he said, is measured in preparation and substance, not minutes. He’d rather spend 90 minutes with a vendor who understands his environment than 15 with one optimizing for a follow-up rate.Angel F.ofSaronic Technologiesmade a similar case for homework over hustle. A little research goes a long way, and understanding his space and regulatory needs earns a vendor consideration. But claiming to meet requirements without the certifications or controls to back it up suggests the vendor just “googled a few buzzwords.”
Price the problem or lose the room
Some CISOs want the hard numbers up front, not a promise of a follow-up call.Tim HamptonofHermeussaid he always asks vendors “how many zeros do you think this problem is worth.” Too often, the answer is that pricing is reserved for a follow-on call, built on the assumption that a first meeting guarantees a second. If there’s no alignment on the value of the problem and no interest in how the vendor solves it, he said, there is no second call.Dr. Jason Gamage, PhD, CISA, CISSPofMetapilot Academysets similar expectations before the meeting even starts. He tells vendors upfront that he doesn’t want marketing slides. He wants to hear immediately how the tool solves one of his problems, followed by why the vendor is innovative. That’s enough for an intro call, and if he extends it, that’s a sign of real interest. As the budget holder, he always asks for rough pricing and doesn’t want to hear “I’ll get back to you.”
Whose meeting is it, really
Not every “yes” to a meeting is a straightforward buying signal.Glenn Bravyof Wizer framed the obligation as mutual. “Teach them something even if they don’t buy,” he said. “It’s gotta be as much for them as it is for you.” Most discovery calls, in his view, are valueless to prospects and waste their time.Duncan MillsofBitdefenderraised a different question about who’s actually in the room. He asked how the idea of short, high-signal meetings squares with the conventional wisdom that buyers are 75 percent into their journey before ever taking a meeting. Are CISOs really taking meetings blind, he wondered, or is someone on their team already doing the legwork and recommending the meeting on their behalf.
Please listen to the full episode on your favorite podcast app, or over onour blog, where you can read the full transcript. If you’re not alreadysubscribed to theDefense in Depthpodcast, please go ahead and subscribe now. Listen to the full episodehere.
Huge thanks to our sponsor, Teleskope
Please subscribe viaApple Podcasts,Spotify,YouTube Music,Amazon Music,Pocket Casts,RSS, or just type “Defense in Depth” into your favorite podcast app.
Join us next week, Friday [09-11-26], for “Hacking Vendor Selection”
Join us Friday, September 11th, 2026, for “Hacking Vendor Selection: An hour of critical thinking about what happens in your environment that influences what you buy.”
It all begins at 1 PM ET/10 AM PT tomorrow, with guestsKarl Mattson, founder and managing director,Squared Circle Ventures, andHoward Holton, founder and principal analyst,Phronia Counsel LLC. We’ll have fun conversation and games, plus be sure to stick around until the end of the hour for our always-popular post-show meetup, hosted on Zoom.
Orregister oncefor every upcomingSuper Cyber Fridayevent. No need to sign up week to week.
PREVIEW: CISO Series Podcast LIVE in Houston, TX 9-15-26
CYBR.SEC.CON (CYBR.SEC.Events) is the best value show you can attend in cybersecurity.
CISO Series Podcastis heading back to Houston for our third year, and we’re recording a live episode on September 15 at 11:00 AM. JoiningDavid Sparkon stage will beJerich Beason, CISO,WM, andEdward Contreras, senior evp and CISO,FrostBank. Huge thanks to our sponsor,Dragos, Inc.
Find all of the information and the registration linkhere.
Huge thanks to our sponsor, Dragos
Why a Flat Network Is an Open Door for Attackers with Zero Networks
Most networks are flat by default. Every door left open, so an attacker who gets in walks straight into every house.
In this conversation withDavid SparkatBlack Hat2026, a longtimeZero Networkscustomer,Scott Ehrlichfrom wealth management firmBBR Partnersexplains how microsegmentation replaced a “Frankenstein” of RDP lockdowns and bolt-on MFA.
Read the article and watch the videohere.
Big thanks to our sponsor, Zero Networks
Cybersecurity Headlines – Department of Know
Our LIVE stream ofThe Department of Knowhappens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will featureJonathan Waldrop, CISO,Acoustic, andMontez Fitzpatrick, director, information security | global head of cybersecurity,Energizer Holdings.Join us on YouTubeand catch up on what shaped the week in security. Thanks to ourCybersecurity Headlinessponsor,KnowBe4.
Thanks to our sponsor, KnowBe4
Participate! Add our live shows to your calendar
Learn moreabout all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar,Outlook, or export an.ics file
Jump in on these conversations
“What logs have shown a surprisingly high value that you can’t live without now” (More here)
“I’m the only Application Security Engineer in my company and I have no clue what I’m doing” (More here)
“Frustrated with the Cybersecurity Job Market” (More here)
Cybersecurity Headlines – Daily News Shorts
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming.Learn moreabout all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What’s Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.