David Gee is the former CIO and CISO at storied companies such as HSBC and Eli Lilly. Rather than quietly disappear in his retirement, he's been writing books. And not just any books, two of his published books are "A Day in the Life of a CISO" and "How to Sell to the CIO and CISO". And not just tiny little ebooks! Each of them is 500 days of details. Specifics. Stories. Advice. Explanations. Basically everything you need to raise your game selling to senior security and IT leaders.
In this episode
- Why the CISO's default rule is one in, one out, and what the CFO says that makes it so
- The exception: a new category the current stack doesn't cover, and why it's worth the extra procurement work and intensive POCs
- Security budgets are "one pot of money," and AI is now crowding it. Some boards are asking whether AI could replace whole packages
- Why the strategy that's already written down is too late for you, and the 12 to 15 month window before anything is budgeted
- The two-sentence intro that got a meeting with a large Australian company agreed within hours
- "AI alerts are 9 times more chatty": the one soundbite that made David stop a startup mid-pitch
- The three Cs of trust, and why swapping the A team for the B team after the contract is the mistake CISOs remember
- What David wishes CIOs understood about security, including the HSBC mobile banking story
About the guest
David Gee spent around twenty years as a CIO, including at Eli Lilly, before deliberately moving into the CISO chair at HSBC Asia Pacific. He now sits on boards, advises a small number of startups, and has written three books, the latest being How to Sell to the CIO and CISO.
Notable quotes
- "The CFO's telling you, hey, stop buying new crap from new vendors. Can you just use the vendors we have?"
- "The strategy that's been written down and being executed often is too late."
- "I can't just spam them because you asked me to. That would be going against my book."
Chapters
00:00 Why a CISO wrote a book for salespeople
10:39 Guarding the network, and getting in before the budget exists
13:05 What a CISO actually wants from a first meeting
17:29 Building trust: the three Cs
21:28 Selling change, and why procurement slows it down
23:10 How a CISO's career stage changes what they'll buy
26:50 The CIO and CISO tension, and the HSBC story
30:25 Turning the CFO into an ally
33:45 Startups, one in, one out, and AI
39:41 Where vendors fit after the sale
41:10 What to bring to the CISO meeting
46:39 Overrated or underrated
The Cyber Go-To-Market Talk is the show for cybersecurity sales leaders, founders, CROs, and go-to-market operators looking to improve cyber sales performance and build more predictable revenue growth. Hosted by Andrew Monaghan, founder of Unstoppable.do, covering cyber sales leadership, revenue leadership, sales onboarding, forecasting, pipeline generation, and cybersecurity go-to-market execution.
Follow me on LinkedIn for regular posts about growing your cybersecurity startup
Want to grow your revenue faster? Check out my cybersecurity sales consulting and training
Need ideas about how to grow your pipeline? Sign up for my newsletter.

