
Cyber Security Interviews · 2023-09-25 · 17 min
Key moments - from our scoring
Substance score
44 / 100
Five dimensions, 20 points each
Douglas Bruch, interviewed by Dan Ayala on his own podcast, explores how to effectively engage with CISOs by abandoning traditional sales tactics in favor of genuine relationship-building and problem-solving. Rather than elevator pitches or fear-based messaging, Bruch advocates understanding the CISO's day-to-day reality - dealing with spreadsheets, PowerPoint, and competing priorities - and offering a concrete three-to-six-month roadmap that addresses their core challenges: underfunded programs, staff shortages, and decision paralysis. He shares concrete examples of building trust through honesty (admitting when a product has failed), respecting organizational friction, and positioning himself as a business partner rather than a vendor. The episode also touches on his separate initiative, Hangar Shingle (available at smartlyremote.net), designed to help aspiring cybersecurity entrepreneurs navigate the business fundamentals of starting a firm. Bruch's philosophy emphasizes that CISOs don't actually use most security technology daily; they manage people, budgets, and strategic priorities - making human connection and clear sequencing far more valuable than technical features.
Talk with them, not at them, by researching their specific program, understanding their problems (underfunded, understaffed, analysis paralysis), and offering a clear sequenced roadmap rather than pushing your full product suite or using fear-based messaging like elevator pitches.
CISOs are overwhelmed by competing priorities and don't know where to start; solve it by giving them three specific, sequential steps over three to six months (e.g., inventory, logging, correlation rules) that build on each other rather than pointing them at the whole mountain.
Honesty about product or service shortcomings builds credibility and trust; when you admit failure and explain your improvements, CISOs see you as a true business partner rather than someone trying to extract value, making them more likely to stay or expand the relationship.
They want vendors that consolidate multiple tools, ensure team adoption after the sale, provide true partnership, have a strong vision and team, and help them reach strategic goals - not vendors pushing technology features they'll never use.
Going over the CISO's head to the CIO during a security incident triggers immediate damage control, destroys the relationship, and signals opportunism rather than partnership, often resulting in loss of the deal.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuinely practical CISO-selling insights buried in substantial rambling, but the episode is padded with meta-commentary about the podcast's return, entrepreneurship platitudes, and a meandering Pen & Teller anecdote that adds little substance for a B2B operator.
I talk to them. We talk to CISOs too, Doug. I was like, you talk at them. Do you talk with them? There's a big difference.
here the things that you need to do in this order These build on each other So they not three different steps There three steps in a row And in three to six months we going to get you here
The CISO-selling framework has some genuinely contrarian moments - admitting failure as a retention tool, rejecting the elevator pitch entirely, calling out ambulance-chasing after breaches - but the broader entrepreneurship content is generic and the CISO insights, while experiential, won't surprise anyone who has read challenger-sale or similar literature.
i was like yeah we fucked up we're sorry here's how we're going to do better oh that's refractory nobody ever says that
this dumb idea of if you were 30 seconds within an elevator with a c-stool how would you sell them i was like i fucking would it because that's the dumbest thing i've ever heard
Douglas Brush has real practitioner credentials - built The Digital Forensic Group, claims hundreds of CISO engagements, and is doing special master work - but this is a self-interview format where the host is effectively his own guest, which limits caliber assessment, and the credential claims are largely asserted rather than demonstrated with verifiable outcomes.
i've done 500 of these like i know i've seen every cyber security program that exists they're all the same they're underfunded understaffed
when i started the digital forensic group it was insane to me that when i launched the website within seconds i was seeing
A few concrete data points appear - AdWords keyword discovery ('pc forensics'), ad budgets of $5 - 10k in the mid-90s, a 3 - 6 month program timeline - but most claims are anecdotal and no named companies, dollar-value deals, or measurable outcomes are cited, leaving the advice illustrative rather than evidence-backed.
my advertising budget was limited it was pay up front and then wait newspapers radio yellow pages five ten thousand dollars
i found out there was a unused ad word that google suggested that was people had searched for but nobody else was bidding on in the marketplace pc forensics
Dan Ayala functions more as a prompt-giver than an interviewer - questions are broad and leading, there is no meaningful pushback, no data challenged, and the episode ends in a prolonged confused sign-off; the format is essentially an unguided monologue dressed as a conversation.
Do you want to talk about the two projects that you and I are working on together
Let's talk a little bit about CISOs and selling to CISOs.
Computed from the transcript - who did the talking, and the words that came up most.
This is the 5th part of the podcast's return after a brief hiatus. Daniel Ayala continues his interview of me. In this fifth part, we will discuss the start-up resources we provided in our Hang Out A Shingle presentation, what I am doing with Accel Consulting, selling to CISOs, tips to avoid when presenting cyber services, the selling to CISOs Master Class we are developing, and so much more!
Transcribed and scored by The B2B Podcast Index.
I'm Douglas Bruch, and you're listening to Cybersecurity Interviews. Cybersecurity Interviews is the weekly podcast dedicated to digging into the minds of the influencers, thought leaders, and individuals who shape the cybersecurity industry. I discover what motivates them, explore their journey in cybersecurity, and discuss where they think the industry is going. The show lets listeners learn from the expert stories and hear their opinions on what works and doesn't in cybersecurity.
Welcome to Cybersecurity Interviews. It's back. After a long hiatus and a lot going on in my life, I am bringing back the podcast. In order to do so, I brought my good friend and colleague and data privacy and cybersecurity person of interest, Dan Ayala, to interview me.
So over the next few episodes, we'll discuss where I've been in the past 18 months, what I'm doing now, and where I think this industry is going, and why I plan to leave it within the next seven years. Do you want to talk about the two projects that you and I are working on together, one that we've done together and one that we've got in the hopper? First around hanging out your shingle as a building out of your own business, and the other around selling to CISOs? yeah it's funny you know it's i i almost forgot about the hangout you're shingle and tell us thinking about things i needed as i'm setting up this business like holy crap dan i have a whole list of this we put it together and i found myself referencing it for myself and then as i've seen more and more people in the marketplace now trying to start businesses um it became a really valuable thing and this idea that kind of creating this this repository of resources for people that want to get into this because it there's it's not that you know again when i started computer house calls 94 95 my advertising budget was limited it was pay up front and then wait newspapers radio yellow pages five ten thousand dollars and stuff and i would have to wait six months to a year they said really it's year two you really see the results and we want you to expand them and get a bigger ad placement i'm like i feel like i'm being sold a timeshare what's going on and it's just like this really like where am i putting my money on and where's the results and it really it didn't it didn't pay out and then when i started the digital forensic group it was insane to me that when i launched the website within seconds i was seeing or seconds it's probably a little dramatic but and within hours days you know i can see what adwords were generating what was driving traffic to the site and i can track it to a sale and for me it was funny you know i was doing things like computer forensics i say computer forensics because that's the terminology that we use but i found out there was a unused ad word that google suggested that was people had searched for but nobody else was bidding on in the marketplace pc forensics landed a bunch of work once i put that in as a driver because that's what the lawyers are thinking about that hey uh you know they would yell down the hallway some partner they don't understand they're not gonna say i need a computer forensic expert witness on a rule twit it's like i need somebody knows pcs give me a pc expert and so they get pc forensics and that i think i know your audience know what they're thinking about and so there's a lot of this that that i think allowed me to shape and change this and even as i was doing some of the community stuff i built out a logo this this week for something i'm doing for the special masters community, I guess is the best way of putting it.
But it's around, you know, it's basically creating a safe place for special masters and stuff. And so there's going to be a website and it's called in Latin, Neutriums Spatium, which is basically a neutral territory. It a place to meet and confer but it going to be resources similar to kind of what we do with Hangar Show but a resource a slack channel where people can go and find other like people that are having the same problem long story short is yeah what you and i do and what we try to do is build these community things i think what is important is as people start entering this there's so many good things you can use now it was really hard back in the day it was actually more cross-through now actually it's still extensive in a bad way if you do the wrong thing it's all about order of operations choosing what you do when you do it how you do it and i take it for granted that i can go register a domain whatever i want edit the dms records point out the same again basically had a presence up on the internet with a logo for all of about 70 but again 23 years ago that would have been a 30 000 project over a year so we want to be able to show people that enablement but also show look it's very easy to get lost too because now there's almost too many options and so through through the hanger shingle work is to be able to say, look, do these things.
Here's your corporate structure. Here's what you need to worry about in the different, you know, whether it's a C corporation, S corporation, LLC, how are you going to structure your company? What's your exit? How to brand and market, how to do all these different things to get your business off the ground.
And I think a lot of people that are either going to be solo entrepreneurs or build into some kind of other practice, in particular, as we see the marketplace changing, where I think over the next six months as the economy recovers and all these people that lost jobs in the current marketplace because it's very important for stockholders, VCs, and investors to make the best capital gains this year while they take the tax write-offs for the losses this year so they can pay the least amount of taxes and make the most amount of money while everybody else uses their job in healthcare.
So as the economy makes this amazing recovery in six months, which it will, people are going to be, I think, more suspicious of going back to work for bigger companies and more companies are going to come out of this. And I want to be able to help these individuals that want to be entrepreneurs know what they're really getting into. Because I think a lot of people are kind of like have this e-myth or entrepreneurial myth that they can do it. And it's like, yeah, you can, but there's a lot of business structure behind it.
Here's some shortcuts. I hope they work for you. If they're not, get out, go work for them. But it's this idea where we have this community resource of things to help people get off the ground.
Yeah, you can go find it at smartlyremote.net. There's a video presentation as well as other collateral to take a look at, which is really a lot of fun to do. It's two years old, but I think it's actually it's four.
It's three, three years old now almost. But I think it's as fresh today as it was then. Let's talk a little bit about CISOs and selling to CISOs. Yeah, I think one of the challenges that I had, I've always had, is that whatever org I was representing said, you know, as you talk to these CISOs, I need you to really say or push this.
I'm like, cool, I'm not going to do that. Absolutely not. I'm going to talk to them because, again, one of the things that I kind of butted heads with focus, well, you know, you're not technical. It's like, yeah, but not my focus area right now.
I can do that. But really my area is the community, the collaboration, the friendships I've built in the CISO community. So I talk to them. We talk to CISOs too, Doug.
I was like, you talk at them. Do you talk with them? There's a big difference. They didn't get that.
Well, you're not, you know, you're not really spreading our message. It's not about us. It's about them. Understand what their problems are.
Understand the mentality of my CISOs. And how you sell to them is understanding their psyche, the problems, the things that they're going through. And that's how you really do it is connecting with them on a human level. And most of the times I would get on these calls with CISOs or go meet them.
you know hour-long prep meetings and i make sure we position this i was like no i'm not going to do any of that nope i already know what their problems are tell me what name of the company okay here's their problems after the call how did you know that i was like because i've done 500 of these like i know i've seen every cyber security program that exists they're all the same they're underfunded understaffed there's a lot that are good don't get me wrong but most people are not at the levels where they they can or should be and they're scared and i was like that that fear that I'm never going to get this done and it's overwhelming.
It's because there's, there's too many competing priorities. It's analysis paralysis. So what I go in and do and I say look here the here the things that you need to do in this order These build on each other So they not three different steps There three steps in a row And in three to six months we going to get you here And we only going to do these things And this is going to build out your program. And the salespeople are like, that's amazing.
And I was like, right. And did you see them actually add on to the products and services that we were selling? Like, yeah, but you didn't sell it. I got exactly.
I explained to them a path forward and how they should do it. Because I'm the expert. I've seen three other programs today. They want to know for me, what are my peers doing?
What would you do if you were in my sales? Here's what I would do. Cool. What are some of the technologies that can support that?
Ah, glad you asked. I have some of these. You shouldn't buy them all. I'll sell you one or two right now.
But when you're ready, we'll build into some of these things like AI, ML, SOAR, whatever it is. But right now you need to start with the basics about understanding your inventory, cleaning up your logging and aggregation, build out the right correlation rules. So you're detecting threats that matter most to your business. I don't want you to turn all the threat into a field.
I want you to pick a couple of use case scenarios that we're going to work on that are the highest risk of the business. Let's just focus on those. You can do that? Yep.
Our technology can do that. We can help you do it. Great. Then let's do that.
And then we're moving along already. And then as we go, we kind of expand on this. And then we get into the greater things. I think that's how you sell the CISOs is understanding where they're at.
Get them moving in the right direction. But don't like point to the top of the mountain and say, all right, go hike that. They're going to be like, fuck you, dude. I'm going to die on the way up.
And they probably will. get to the base camp one take them there sherpa them be there with them and be a true business partner and wear the logo of the jersey who you're playing for at the time and they're going to trust you build that trust they'll buy from you understand they have a lot of inertia in their lives and often it can be something as simple as understanding that you know some of the things that i've been able to help them out on is they were going to take out some products i was representing i was like i think you should we failed you we didn't do it the right job and the kind of look this did you just say what i think is and the sales people and product people did you just say that i'm like yeah we fucked up we're sorry here's how we're going to do better oh that's refractory nobody ever says that thank you well tell me more about that and then i got them interested and i was like yeah look and here's here's where we're making improvements here's how i was going to support you and talking in on their terms not about me not about whoever I'm representing what can be done better.
And it's like, you know, often I'll say, look, you know, if you give us some time to make this right, I know you're going to have to go through a procurement process. Oh my God. I've been on the phone with lawyers all day. They're taking me because I'm trying to go to this competitive product right now.
That sucks, man. I've been there. What if we did this instead? And we just give you more room in our product and we'll give you some more until you cut over to them.
Knowing that they're never going to do it because it's inertia. It's a business. I understand all their problems internally too. Again, understanding their friction points inside the organization of signing a new vendor making their job easier they're less likely to displace you so there's all these different things that you have to understand where they're coming from um instead of pitching them all the time this dumb idea of if you were 30 seconds within an elevator with a c-stool how would you sell them i was like i fucking would it because that's the dumbest thing i've ever heard um what i would do is talk to them about say hey how's your day going i've talked to them about anything else other than their job they're like oh cool thanks oh by the way yeah i know so and so and i might be in cyber you know just get them talking about anything other than they're already they deal with their job every day long they don't want to talk about it and this stupid idea when you go in and pitch a cso in your fucking cold email is uh as a cso are you worried about cyber security wow no no i'm not i'm so glad you asked or the fear and certainty and doubt of or even the worst the ambulance chasing uh that's disgusting i had somebody get fired over that i was so happy um because they went over the seesaw when the seesaw's in the middle of the house burning down oh this is our opportunity i was like no it's not this is our opportunity to shut up and listen to their problems and be there as a shoulder to crime.
Guy goes over the head of the CISO to the CIO who immediately gets an email, walks down the CISO's office and goes, what the fuck is this? Screams at the CISO, calls up the person and goes, what the fuck were you thinking? And then it's damage control for that. And I was like, just offensive acts like that.
And that's such a common thing in the industry. It's like, it's not that there's one guy, everybody does that It doesn work And this idea again why I done with this because we keep doing the same things over and over again that don work well we always done it this way yeah well what your uh is it working it working good enough could be working better could be working more efficiently you just fired a bunch of people you have less resources what if you did things that were more effective and efficient without pissing people off for once because really what ceas look for are just a few things what consolidates business problems into one tool that they have adoption after the sale there's somebody exists with a true partnership and somebody looking out for them as a person and as in their job function and also they buy from people that have a great vision a great team and basically help them get to that strategic goals even faster and that's that's it don't over complicate it and if you get to a cso it's like you know you've done your research you got to them you know you can recon them build with the relationship with them they're likely going to hand you off you don't have to keep bothering them after that they're going to hand you off to their hand to the king and King's Landing speak.
And you're good. Just keep that person happy. The best calls I've had are when the CISO says, I don't use your product. I haven't touched it in 10 years.
All I know is you keep my people happy. We'll keep buying it. I have other things to worry about. And this product, CISOs don't touch the technology.
I was like, no, they touch spreadsheets and they touch PowerPoint and they curse at them all day long. And then they go in their email box and the CEO says, again, just forwarding this from the New York times. We need to report on this. It's like, they're not, they're not sitting down in a sock doing this work.
That's this doesn't exist, you know? So you really have to understand what their day-to-day looks like. If you like these stories, if you like these stories, you're going to love the masterclass that Doug and I are putting together available soon. I had to stop Doug before he gives the whole class away.
oh no these are teasers like i have all the tools or do you or do you exactly so i'm really excited to do this i i'm sure you're you're a fan of of uh pen and teller because obviously of course yeah so when they did their their book their food food comedy book there was this awesome thing that they did around like and i thought it was brilliant it was like i I don't know, it was very early in the book. It was like, you want the most out of this book, skip to this page. And they put it right in the middle of the book.
And we skipped this page. And it was like, if you are at a restaurant, if you're going to pay with a credit card at a restaurant first, scrape off the barcode and then fill it in with a Sharpie. When you hand it over, they'll think it went through and they'll give it back. And then you go to the first page that says, how many idiots read that, then jumped ahead, thought they got what they needed out of this book.
and have just totally tanked their credit card. And that's the thing. It's like, go ahead. Use these couple of things I said.
I'll see what happens when you try to run that credit card. Exactly. Gotta read the whole book. Wonderful.
Well, Doug, thank you for joining me here on Cybersecurity Interviews. Doug Brosh of Excel Consulting. Thank you for joining me, joining you, for joining me. Yes, it's a little too meta.
Usual host will be back again soon until then. And I'll get a little peek on that. You got me talking. You can't get me stopped.
Like I said, people are like, hey, Doug, can we get you to talk at a conference? It's like, getting me talking is not the problem. It's shutting me up. No, it was that, you know, yeah, the next series of podcasts are going to be more episodic in that sense.
I'm going to break them up in a little bit of things. So stuff on the data privacy stuff, doing special master stuff, the CISO stuff, and how some of the things are changing in the industry. So I'm going to do more series of things over the next couple of months. Wonderful.
Well, I know I'm looking forward to hearing them, and I'm sure the community is as well. Well, thank you. Thank you for having me have you. Thank you for letting me have you, have me, have you, have me, have you.
Yes. Yes, this is a scene straight out of Airplane. Thanks to everybody for listening. Thank you so much for joining us today on Cybersecurity Interviews.
I hope that you enjoyed this interview as much as I did. Please go to cybersecurityinterviews.com where you can find every episode, including show notes, and links for each guest. There you can also find social media links and to sign up for new episode notifications.
Thanks. We'll talk soon.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.