I’ve been working as a Chief Information Security Officer at a global company for more than ten years. During those years I’ve probably been contacted by several thousand salespeople offering everything from the latest AI platform to the next magical security silver bullet.
Very few reach through and actually get a meeting scheduled. I thought it would only be fair to everyone, and a good way for me to link to this article as a simple answer, to list reasons you won’t get my attention.
First out – NO, I don’t have 15 minutes next week
One of the most common opening lines I receive is:
”Do you have 15 minutes next week?”
The honest answer is usually no.
All CISO’s I know, and I know quite a few, have extremely busy calendars. Mine is no exception. I rarely have a couple of minutes to spare on a cold sales call. Every minute I put in to anything has to be worth it.
Second – NO, I didn’t see your last message
Over the years I’ve seen more persons reaching out that ask me repeatedly if I didn’t see the last message. They might also be kind enough to bounce that message up in my inbox, by asking again.
Unfortunately, this means that I have even less time to check out the next message – or the one that actually caught my attention.
Following up once is perfectly reasonable.
Following up every few days with ”Just checking if you saw my previous message” doesn’t increase the chance of a reply. Quite the opposite. Eventually I’ll simply archive, delete or block the conversation.
Third – A CISO already know
Most CISOs are already well aware of the latest regulations, attack trends and buzzwords.
Opening with ”Have you heard about Agentic AI?” is unlikely to spark much interest. What catches my attention is when someone connects that trend to a concrete problem my organisation is likely struggling with.
How do you get the attention of a CISO?
It wouldn’t be fair to not include a couple of advices on how to get mine and every other CISO’s attention.
If you have something to offer of value, do the homework. Study the company that the CISO is working at. Look at the real challenges and find the ones that are difficult to solve.
As an example, AI is getting integrated into everything. The AI Act require that we do our risk analyses on the AI-solutions we utilize. Here’s a challenge you could offer a solution to – how do we find all our AI-systems out there?
Once you have a compelling case, write a elevator pitch for that case. Three sentences maximum. I’m not saying it will get you the attention of a CISO, but chances increase far more than if you repeatedly ask whether we saw the last message…
