How to Talk So That They Will Listen: Selling Cybersecurity
May Brooks (CISO)
BSides NYC 2024 · Day 1 · Entrepreneur
Overview
In "How to Talk So That They Will Listen: Selling Cybersecurity," May Brooks, a seasoned CISO turned entrepreneur and advisor, delivers a compelling exploration into the art and science of effectively selling cybersecurity solutions. Drawing from her extensive experience on both sides of the fence – as a CISO responsible for making critical purchasing decisions and as an entrepreneur navigating the vendor landscape – Brooks dissects the common pitfalls and successful strategies for engaging with cybersecurity leaders. The talk emphasizes that successful sales in this highly specialized and often skeptical field are less about the product's technical specifications alone, and more about building genuine trust and demonstrating profound understanding of the client's unique challenges.

Key moments
- 0:00 Speaker's background and CISO's inherent distrust
- 2:08 Selling cybersecurity is about nurturing relationships and trust
- 3:20 Trust as the foundation of long-term CISO-vendor relationships
- 4:40 Focus on understanding problems and delivering real value
- 5:20 CISOs are bombarded; do your homework before pitching
- 7:00 Pitching to the right technical expert, not just the CISO
- 8:00 Tailor pitches to industry, regulations, and current needs
How to Talk So That They Will Listen: Selling Cybersecurity
Speakers: May Brooks, CISO
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=JBz23S7zIFM
Overview
In "How to Talk So That They Will Listen: Selling Cybersecurity," May Brooks, a seasoned CISO turned entrepreneur and advisor, delivers a compelling exploration into the art and science of effectively selling cybersecurity solutions. Drawing from her extensive experience on both sides of the fence – as a CISO responsible for making critical purchasing decisions and as an entrepreneur navigating the vendor landscape – Brooks dissects the common pitfalls and successful strategies for engaging with cybersecurity leaders. The talk emphasizes that successful sales in this highly specialized and often skeptical field are less about the product's technical specifications alone, and more about building genuine trust and demonstrating profound understanding of the client's unique challenges.
Brooks' unique perspective is particularly valuable because she articulates the CISO's mindset, revealing why traditional sales tactics often fail and how vendors can pivot to truly resonate with their audience. She highlights the constant bombardment CISOs face from unsolicited pitches and the resulting inherent mistrust, underscoring the critical need for personalized, value-driven communication. This talk is essential for anyone involved in selling cybersecurity products or services, as it provides a practical roadmap for fostering long-term relationships and securing meaningful engagements within a competitive and discerning market.
Ultimately, this presentation transcends mere sales advice, offering deep insights into effective professional communication and relationship building within the cybersecurity ecosystem. It's a call to move beyond transactional interactions towards a model of partnership, where vendors act as informed advisors rather than mere product pushers. By focusing on the buyer's needs, understanding their context, and consistently delivering value, Brooks argues that cybersecurity sales can transform from a struggle into a mutually beneficial collaboration.
Background
▶ Watch: Speaker's background and CISO's inherent distrust (0:00)
The cybersecurity landscape presents a unique and formidable challenge for sales professionals. Unlike many other industries, the decision-makers – primarily Chief Information Security Officers (CISOs) – operate from a position of inherent skepticism. As May Brooks aptly puts it, their job is "not to trust anyone." This professional mandate, coupled with the sheer volume of unsolicited pitches they receive daily, creates a significant barrier for vendors attempting to introduce new products or services. CISOs are constantly bombarded with LinkedIn messages, emails, and calls, many of which are irrelevant or poorly researched, leading to what Brooks describes as "a lot of junk" and a profound sense of mistrust.
Historically, the cybersecurity industry has often been characterized by a "silver bullet" mentality, where vendors promise a single solution to solve all security woes. Brooks debunks this myth, emphasizing that no such panacea exists, and CISOs are acutely aware of this. This contributes to their skepticism towards any product claiming to be the ultimate fix. Furthermore, CISOs typically operate under tight budgets and limited resources, necessitating stringent prioritization. They cannot afford "nice-to-haves" when fundamental security issues remain unaddressed, especially in less mature organizations (e.g., a five-year-old company).
Prior sales approaches often neglected the crucial step of research and audience understanding. Many salespeople would pitch generic solutions without investigating the target company's industry, regulatory environment, or specific security posture. Brooks recounts instances of being pitched GDPR solutions while working for an Israeli company with no European ties, or OT security as a CISO in a fintech firm. Such misaligned pitches not only waste the CISO's time but actively erode trust and result in blocked communications. The problem stems from a transactional mindset, where the goal is a quick sale rather than building a lasting relationship based on mutual understanding and value. This talk aims to reframe this approach, advocating for a more strategic, empathetic, and relationship-centric model for selling cybersecurity.
Key Findings
▶ Watch: Trust as the foundation of long-term CISO-vendor relationships (3:20)
May Brooks' talk distills several critical findings for anyone looking to successfully sell cybersecurity solutions:
- Trust is the Foundation of Sales: The most paramount finding is that sales in cybersecurity, like any significant relationship, hinges entirely on trust. It is not built in a day but through a consistent process of sincerity, reliability, and demonstrating that the vendor has the CISO's best interests at heart. Brooks emphasizes that even if salespeople switch companies, she continues to work with those she trusts, highlighting the relationship's longevity over specific product affiliations.
- Understanding the Problem is Paramount: Effective selling begins not with pitching a product, but with a deep understanding of the client's pain points and the specific problems they are trying to solve. Generic pitches that fail to acknowledge the CISO's unique context, industry, regulatory landscape, and organizational maturity are doomed to fail. Vendors must demonstrate they know "where I'm going, where I'm coming from" to offer truly impactful solutions.
- Research is Non-Negotiable: A lack of due diligence is the quickest way to alienate a CISO. Salespeople must conduct thorough research to understand the target company's industry, relevant regulations (e.g., avoiding pitching GDPR to a non-European-focused company), and even the specific roles within the security team. Knowing who the actual user of the product will be (e.g., an application security engineer versus the CISO) allows for tailored communication and ensures the right stakeholders are engaged.
- Communication Must Be Tailored and Consistent: The way information is conveyed is as important as the information itself. Brooks stresses the need to adapt communication styles for different audiences – using technical terms for engineers and business-centric language for the board. Beyond tailoring, consistency in communication, particularly through platforms like LinkedIn, is crucial for nurturing relationships and staying top-of-mind, even if a sale doesn't materialize immediately.
- Focus on Value, Not Just Features: CISOs have limited budgets and must prioritize. They need to understand "why I would pay money for it." Pitches should clearly articulate the value a product provides, demonstrating how it addresses a critical pain point or fills a genuine gap, rather than being a "nice-to-have" or a redundant solution.
- Embrace "Ripple Effects" and Long-Term Engagement: Sales often involve a long cycle. Brooks introduces the concept of "ripple effects," where an interaction today might not lead to an immediate sale but can resonate years down the line. This reinforces the idea that every piece of content, every conversation, and every act of mentorship contributes to a long-term brand and relationship building, rather than just immediate transactional outcomes.
Technical Deep Dive
▶ Watch: Focus on understanding problems and delivering real value (4:40)
While May Brooks' talk doesn't delve into the intricacies of cybersecurity exploits or network protocols, it provides a "technical deep dive" into the psychology, strategy, and mechanics of effective communication and relationship building specifically within the cybersecurity sales context. This involves understanding the operational environment of a CISO and applying structured communication techniques to overcome inherent barriers.
The core of this technical deep dive begins with dissecting the CISO's mindset. A CISO's primary directive is to manage risk and protect assets, often by questioning and verifying. This translates into a professional skepticism that views most unsolicited sales pitches as potential distractions or even threats to their time and focus. Brooks highlights the fallacy of the "silver bullet" – the notion that a single product can solve all cybersecurity problems. CISOs, through experience, understand that security is a complex, multi-layered endeavor. Therefore, any sales pitch that promises an all-encompassing, effortless solution immediately triggers distrust. The technical challenge for a salesperson is to bypass this inherent skepticism by demonstrating a nuanced understanding of cybersecurity realities.
A critical component is pre-sales research and audience segmentation. Brooks emphasizes that a "technical" approach to sales means understanding the target organization's specific context as thoroughly as a security analyst would understand a system architecture. This includes:
- Industry and Sector: Is it fintech, healthcare, manufacturing? Each has unique risk profiles and regulatory burdens. Pitching OT (Operational Technology) security to a fintech company, as Brooks experienced, is a fundamental research failure.
- Regulatory Landscape: Is the company subject to GDPR, HIPAA, PCI DSS, or other specific compliance frameworks? A pitch for GDPR solutions to a company with no European ties is not only irrelevant but demonstrates a profound lack of homework.
- Organizational Maturity: Is it a young startup or a mature enterprise? A "five-year-old company" likely prioritizes fundamental security over "nice-to-haves" due to budget and resource constraints.
- Specific Role and Persona: This is a crucial technical distinction. Brooks explains that a CISO, especially in a larger organization, often delegates technical assessment. For an application security product, the primary technical audience might be the application security engineer, not the CISO. The sales strategy must involve engaging the technical expert first, allowing them to assess the product's capabilities and then "pitch" it internally to the CISO, who then makes the strategic decision. This multi-stage engagement acknowledges the division of technical labor within a security team.
The "technical deep dive" also extends to the mechanisms of communication. Brooks advises tailoring language based on the audience. Just as a CISO communicates differently with technical teams versus the board (using terms like "MTTD," "CVEs" vs. "business risk," "financial impact"), salespeople must adapt their lexicon. For technical teams, discussions might involve specific APIs, integration capabilities, performance metrics, and vulnerability types. For the CISO or CFO, the conversation shifts to Return on Investment (ROI), risk reduction percentages, compliance adherence, and operational efficiency gains.
Furthermore, Brooks champions consistent engagement through platforms like LinkedIn as a strategic technical tool for market research and relationship nurturing. She highlights that LinkedIn, while an algorithm, rewards consistency. Regularly sharing knowledge, insights, and ideas – even if it's only once a week – acts as a continuous, low-overhead marketing and brand-building mechanism. This isn't just about posting; it's about observing who engages with the content, providing implicit market research on what resonates with potential customers. The use of Generative AI is mentioned as a tool to facilitate content creation, allowing individuals to maintain consistency even without large marketing teams.
Finally, the talk implicitly details a "protocol" for building trust: sincerity, reliability, and consistency. Sincerity means genuinely understanding the client's needs. Reliability means following through on promises and being a dependable resource. Consistency, as discussed, ensures continuous engagement and reinforces the brand's presence. These elements, when combined, form a robust framework for overcoming the inherent skepticism in cybersecurity sales and fostering long-term, valuable partnerships.
Demo / Proof of Concept
▶ Watch: Pitching to the right technical expert, not just the CISO (7:00)
May Brooks' talk, "How to Talk So That They Will Listen: Selling Cybersecurity," does not feature a traditional technical demonstration or a proof of concept in the sense of showcasing a cybersecurity product's functionality or an exploit. Instead, the entire presentation serves as a meta-demonstration of her core thesis: that effective communication, built on trust and understanding, is the most powerful tool in sales. Her "proof of concept" is delivered through her personal anecdotes, practical advice, and real-world experiences, illustrating the principles she advocates.
Brooks effectively "demos" her approach by sharing relatable scenarios from her career as a CISO and an entrepreneur. For example, her frustration with being pitched OT security as a fintech CISO, or GDPR solutions when her company had no European presence, vividly illustrates the consequences of poor research and misaligned communication. These examples serve as a concrete "proof" of what not to do, making her subsequent advice on audience understanding and tailored communication all the more impactful.
She also provides a "proof of concept" for successful engagement by detailing her own strategies:
- Leveraging LinkedIn: Brooks explains how she, as an individual, maintains a consistent presence on LinkedIn, creating content once a week based on a quarterly plan. This demonstrates how a free and accessible tool can be used intentionally for brand building, market research, and nurturing long-term relationships. She even shares a specific "hack" for CISOs to filter irrelevant messages by adding an icon to their name, proving her practical understanding of the CISO's daily struggles.
- The Power of Brand Ambassadors: Her story of becoming an "evangelist" for a startup with a technically brilliant but communication-challenged team illustrates the value of external advocates. This is a practical example of how companies can overcome internal communication gaps by leveraging trusted relationships.
- Intentional Content Creation: Brooks discusses her challenge to post daily on Instagram during Security Awareness Month, demonstrating the discipline and strategic thinking behind consistent communication. This isn't just theory; it's a living example of executing a communication plan with a clear objective.
- "Ripple Effects" in Action: Perhaps the most compelling "proof of concept" is her anecdote from Vegas, where a mentee from a year prior approached her, profoundly moved by a brief mentoring session Brooks had nearly forgotten. This story powerfully demonstrates that even small acts of value-driven interaction can have significant, long-lasting "ripple effects," reinforcing the idea that not every interaction needs to lead to an immediate sale to be valuable. It underscores the long-game approach to relationship building.
In essence, Brooks uses her own journey, her successes, and her frustrations to validate her methodology. The "demo" is not a product, but a framework for human interaction within a highly technical and trust-averse industry, proven through her firsthand experience and observable outcomes.
Defensive Implications
▶ Watch: Tailor pitches to industry, regulations, and current needs (8:00)
While primarily aimed at those selling cybersecurity, May Brooks' insights offer profound defensive implications for CISOs and security teams. By understanding the principles she outlines, defenders can become more effective in their roles, both in procuring solutions and in communicating their own security posture.
Firstly, understanding how to "sell cybersecurity" to a CISO empowers the CISO themselves to better filter and evaluate vendor pitches. Knowing that effective sales require research, an understanding of pain points, and a focus on trust, CISOs can quickly identify vendors who have not done their homework. They can dismiss generic pitches that promise "silver bullets" or offer solutions irrelevant to their specific industry, regulatory environment, or organizational maturity. This saves valuable time and allows CISOs to focus on engaging with vendors who genuinely understand their challenges and can offer tailored, valuable solutions. It also provides a framework for CISOs to proactively ask critical questions that expose a vendor's depth of understanding, rather than just their product features.
Secondly, the talk provides a blueprint for CISOs and security leaders to improve their internal communication. Just as a salesperson must tailor their message to different audiences, a CISO must do the same when communicating with technical teams, executive leadership, or the board. Brooks' distinction between discussing technical details with an application security engineer versus business risk with the CFO or CCO is directly applicable. Security teams can leverage these principles to:
- Translate technical risks into business impact: Instead of presenting raw vulnerability counts or threat intelligence feeds, CISOs can frame security issues in terms of financial loss, reputational damage, or regulatory non-compliance, resonating with the board's priorities.
- Justify budget requests: By clearly articulating the pain points solved and the value delivered by security investments, CISOs can build a stronger case for resources, much like a successful salesperson would for their product.
- Build internal trust: Consistent, sincere communication about security initiatives, challenges, and successes can foster greater trust and collaboration across departments, transforming security from a perceived bottleneck into a strategic enabler.
Thirdly, the concept of "ripple effects" and long-term relationship building is crucial for CISOs in their interactions with service providers. Brooks explicitly states her preference for working with service providers she knows personally or through trusted contacts, highlighting the importance of relationships beyond mere technical expertise. This implies that CISOs should actively cultivate a network of trusted advisors and vendors. Engaging with the community, attending conferences, and participating in forums allows CISOs to build these relationships organically, creating a pool of trusted partners for future needs, rather than scrambling to find new vendors during a crisis.
Finally, the talk implicitly encourages CISOs to foster an environment where their teams are empowered to engage with vendors and provide technical assessments. By understanding that a CISO doesn't always have the time or the specialized skills to assess every product, they can delegate technical evaluations to the appropriate experts, like the application security engineer in Brooks' example. This ensures that the most qualified individuals are assessing the technical fit of solutions, leading to better procurement decisions and more effective defensive postures.
In summary, May Brooks' talk equips defenders with a powerful lens through which to evaluate vendor relationships, optimize their internal communication strategies, and ultimately strengthen their organization's overall security posture by making more informed, trust-based decisions.
Key Takeaways
- Trust is Paramount: Successful cybersecurity sales are built on sincerity, reliability, and consistent trust, not just product features. CISOs prefer to work with trusted individuals, often over specific company affiliations.
- Research is Foundational: Always conduct thorough research into the client's industry, regulations, organizational maturity, and specific pain points. Generic pitches (e.g., OT security for fintech, GDPR for non-European companies) are ineffective and erode trust.
- Know Your Audience: Tailor your communication to the specific individual and their role. A CISO needs to hear about business impact and risk, while an application security engineer requires technical details and integration specifics.
- Focus on Solving Problems: Articulate how your product addresses a genuine, critical pain point for the client. CISOs have limited budgets and prioritize solutions that solve core problems over "nice-to-haves."
- Leverage Consistent Communication: Platforms like LinkedIn offer a free and powerful tool for consistent knowledge sharing, relationship building, and market research. Regular, intentional engagement fosters long-term connections and brand recognition.
- Embrace "Ripple Effects": Not every interaction leads to an immediate sale. Focus on delivering value and building relationships, as small acts of mentorship or shared insights can have significant, long-lasting impacts years down the line.
About the Speaker(s)
May Brooks is a distinguished cybersecurity leader with a rich and varied career spanning both the corporate and entrepreneurial worlds. She has served as a Chief Information Security Officer (CISO) for a digital bank, gaining firsthand experience in the intricate challenges of cybersecurity leadership and procurement. After her initial CISO role, Brooks transitioned into entrepreneurship, a period she humorously refers to as "getting my senses back." However, her passion for cybersecurity eventually led her to take on another CISO position in the UAE, showcasing her deep commitment to the field.
Currently, May Brooks works extensively with Venture Capitalists (VCs) and a diverse range of startup companies, providing guidance and insights at various stages of their development. This role allows her to leverage her dual perspective as both a CISO buyer and a startup entrepreneur. She is also an author, having recently published "Sales Hacking and Cybersecurity," which she describes as her way of "giving back to community and talking about security awareness to anyone who's listening," with a strong focus on communicating cybersecurity effectively. Brooks is an active participant and volunteer in the ICT community, involved with boards and events, and is known for her dedication to mentoring and fostering talent within the industry.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
May Brooks brings genuine dual-perspective credibility — CISO buyer and startup advisor — to a perennial pain point in the industry. The content is practical and honest, but it's a soft-skills talk at a technical conference, and nothing here will surprise anyone who's been in the room for these conversations before.
Heather Calloway (CISO) — SOLID
May Brooks delivers practical, earned advice on vendor communication from a credible dual vantage point — CISO and founder. The content is useful, honest, and grounded in real experience, but it stays squarely in sales enablement territory and never reaches the governance, procurement accountability, or institutional risk dimensions that would make it essential for senior security leaders.