How to Sell to the CISO: David Gee, who is a ... CISO
The Cybersecurity Go-To-Market PodcastSeptember 29, 202600:45:5631.59 MB

How to Sell to the CISO: David Gee, who is a ... CISO

David Gee is the former CIO and CISO at storied companies such as HSBC and Eli Lilly. Rather than quietly disappear in his retirement, he's been writing books. And not just any books, two of his published books are "A Day in the Life of a CISO" and "How to Sell to the CIO and CISO". And not just tiny little ebooks! Each of them is 500 days of details. Specifics. Stories. Advice. Explanations. Basically everything you need to raise your game selling to senior security and IT leaders.

In this episode 

  • Why the CISO's default rule is one in, one out, and what the CFO says that makes it so
  • The exception: a new category the current stack doesn't cover, and why it's worth the extra procurement work and intensive POCs
  • Security budgets are "one pot of money," and AI is now crowding it. Some boards are asking whether AI could replace whole packages
  • Why the strategy that's already written down is too late for you, and the 12 to 15 month window before anything is budgeted
  • The two-sentence intro that got a meeting with a large Australian company agreed within hours
  • "AI alerts are 9 times more chatty": the one soundbite that made David stop a startup mid-pitch
  • The three Cs of trust, and why swapping the A team for the B team after the contract is the mistake CISOs remember
  • What David wishes CIOs understood about security, including the HSBC mobile banking story

About the guest 

David Gee spent around twenty years as a CIO, including at Eli Lilly, before deliberately moving into the CISO chair at HSBC Asia Pacific. He now sits on boards, advises a small number of startups, and has written three books, the latest being How to Sell to the CIO and CISO.

Notable quotes

  • "The CFO's telling you, hey, stop buying new crap from new vendors. Can you just use the vendors we have?"
  • "The strategy that's been written down and being executed often is too late."
  • "I can't just spam them because you asked me to. That would be going against my book."

Chapters

00:00 Why a CISO wrote a book for salespeople 

10:39 Guarding the network, and getting in before the budget exists 

13:05 What a CISO actually wants from a first meeting 

17:29 Building trust: the three Cs 

21:28 Selling change, and why procurement slows it down 

23:10 How a CISO's career stage changes what they'll buy 

26:50 The CIO and CISO tension, and the HSBC story 

30:25 Turning the CFO into an ally 

33:45 Startups, one in, one out, and AI 

39:41 Where vendors fit after the sale 

41:10 What to bring to the CISO meeting 

46:39 Overrated or underrated 



Support the show

The Cyber Go-To-Market Talk is the show for cybersecurity sales leaders, founders, CROs, and go-to-market operators looking to improve cyber sales performance and build more predictable revenue growth. Hosted by Andrew Monaghan, founder of Unstoppable.do, covering cyber sales leadership, revenue leadership, sales onboarding, forecasting, pipeline generation, and cybersecurity go-to-market execution.

Follow me on LinkedIn for regular posts about growing your cybersecurity startup
Want to grow your revenue faster? Check out my cybersecurity sales consulting and training
Need ideas about how to grow your pipeline? Sign up for my newsletter.