What Do CISOs Really Want? We Asked Them

Cybersecurity PR and marketers spend a lot of time trying to answer one question: how do you get a CISO’s attention?

You wouldn’t be shocked if we said CISOs are bombarded with vendor emails, sales calls, research reports, event invitations and promises of technology that will solve their latest security challenge. As Edward Tucker put it during our latest Eskenzi PR webinar, a CISO’s inbox can be “largely a war zone”.

So, rather than marketers and PR people continuing to guess what works, we decided to ask the people on the receiving end. 

For our recent webinar, ‘What Do CISOs Really Want?’, Eskenzi PR Co-Founder Yvonne Eskenzi was joined by Stephen Khan, CISO at Cognizant, Thom Langford, Strategic Adviser at AptaSentry, and Edward Tucker, Director, Cyber Security Practice at Telefonica Tech. The conversation covered everything from cold calls and content to case studies, conferences and the role relationships play in buying decisions.

One thing became clear pretty quickly: getting a CISO’s attention isn’t about shouting louder.

Relationships matter more than another sales pitch

Thousands of cybersecurity vendors compete for attention, but Thom argued that differences between technologies are often smaller than vendors might like us to believe. Products competing in the same category regularly leapfrog one another in terms of capabilities, which means the people and relationships behind the technology can become a major differentiator. 

As Thom explained: “Basically, it’s not the technology; it’s the relationships that surround the technology.”

Stephen agreed that relationships matter, but stressed that relevance and context are just as important. Technology still needs to solve a genuine problem for that particular organisation. 

Simply handing a CISO a glossy brochure, blinding them with technical language and expecting them to work out why the product matters to their business is unlikely to get very far. Vendors need to understand the organisation, the use case and whether what they are offering is genuinely applicable.

Edward also challenged one of the biggest assumptions in cybersecurity marketing: that everyone needs to target the CISO. In reality, the people working underneath the CISO are often those closest to the technology, the gaps and the problems that need solving. They can also become powerful internal advocates. By the time a recommendation reaches the CISO from somebody they already trust within their team, the conversation is very different from responding to an unsolicited sales email.

Give CISOs something worth reading

Content came up repeatedly throughout the discussion, and there was GOOD NEWS for cybersecurity PR and marketing teams: CISOs do read vendor content, as long as it’s actually useful.

Thom’s advice was to give CISOs something they didn’t already know. That might be original research, practical threat intelligence or an insight that helps them do their job better. Stephen agreed, arguing that CISOs simply don’t have the time or headspace to investigate every issue themselves, so genuinely insightful content can earn attention and start a relationship.

There was one warning for marketers, though: think carefully before putting your best content behind a registration form. Thom estimated that a registration wall could lose “99 out of 100 CISOs” who might otherwise have read the content. 

Stephen agreed, admitting that if he encounters a paywall while multitasking, he generally closes it and moves on. On the other hand, if a report is freely available, genuinely insightful and relevant, Thom said he is likely to share it on LinkedIn, giving the company far more visibility in the process.

Show what really happened 

Case studies were another area where the panel felt cybersecurity companies could do better. 

Edward argued that customer stories are often so heavily curated that they lose some of their usefulness. Every implementation has challenges, so rather than pretending everything went perfectly, he wants to see the “warts and all”: what hurdles appeared, how they were overcome, what resources were required and what the organisation actually achieved.

That focus on practical outcomes also applies to speaking opportunities and thought leadership. Edward wants to leave a conference session with something he can take back to his team the next morning, not sit through what amounts to a 40-minute product brochure. Thom summed it up neatly: “Sell a problem and a unique way of solving it.” The product can come later.

Perhaps most importantly, the panel reminded us that CISOs talk to each other. Edward described private groups where security leaders regularly ask peers about their experiences with particular vendors and technologies. Good experiences get shared, but so do bad ones, particularly when overly aggressive sales tactics are involved. Reputation therefore starts long before a vendor gets into a formal buying conversation.

Three tips for getting a CISO’s attention:

  1. Do your homework. It’s a simple and basic tip, but getting somebody’s name, company and current role right should be the bare minimum. Good research goes further – FACT. Understand their organisation, sector and likely challenges before making contact. As Stephen pointed out, he still receives approaches from people who think he works for previous employers. A quick check of LinkedIn could save everyone’s time.
  2. Be useful before you try to sell. Share original research, practical insight or information that genuinely helps someone do their job. Don’t jump on the latest cyberattack to suggest your product would have prevented it. Thom described this as “ambulance chasing” and warned that it reflects badly on the company doing it.
  3. Talk about outcomes, not fear. CISOs already know the risks they face. They don’t need another vendor telling them to be scared. Show how you have solved a real problem, what happened along the way and what changed as a result. And remember, the easiest route to the CISO may not be the CISO at all. Building credibility with their team, peers and wider security community could be far more powerful than another cold email.

We all want that five minutes of CISO time, and it comes down to something remarkably simple: know who you’re talking to, understand the problem you can help them solve and give them a reason to listen before asking for their time.

And whatever you do, don’t connect with them on LinkedIn and immediately try to sell them something. Edward was particularly clear about that one.

Why not watch the full webinar here: