You've nailed the demo and the POV, and then procurement asks why they'd bet on you instead of CrowdStrike, Palo Alto or Zscaler. Robbie Tyrie has been the buyer on the other side of that question at some very large organisations, and he said yes to the startup more than once. He walks through the math he ran, what he wanted back from the vendor in return, and the trial structure he says a buyer can't argue with. Now a fractional CISO for 50 to 200 person companies, he also explains why buyers stopped turning up at trade shows and what he responds to instead.
In this episode
- The two answers a big vendor gives when you ask for a feature (neither of them are that helpful)
- Robbie's math on the risk of a startup vendor: what you actually stand to lose is a couple of months
- Why smaller vendors treated him "more on a human level", reacted faster in 99% of cases, and gave a better deal than tools costing hundreds of thousands of dollars
- What "work with them" means in practice: quarterly meetings, and knowing the CEO, head of development and head of customer ops instead of an account manager juggling several accounts
- How he de-risked the bet: an agreed baseline, get-out clauses, and an open source tool running in parallel
- The FNZ story: a startup pen test vendor covering 100+ wealth management clients, and the six extra tests that earned everyone kudos
- The managed free trial: two weeks, a month maximum, run as a mini case study
- Why buyers aren't at RSA or InfoSec any more, and the Chamber of Commerce talk that landed him a CEO client
- What JP Morgan did to Fortify's roadmap, and how Robbie would stop your biggest customer doing it to you
About the guest
Robbie Tyrie has spent 26 years in IT and cyber security across the Scottish Government, NHS Scotland, Tesco Bank, J.P. Morgan, Clydesdale Bank, Aegon and FNZ Group, where he ran the Cyber Fusion Centre and application security, before joining pen testing startup OSec as CTO. In 2026 he founded Torridon Cyber, where he works as a fractional CISO for fintech scale-ups getting ready for SOC 2, ISO and enterprise buyers.
Notable quotes
- "So is the risk really there? At the end of the day, what are you going to lose? A couple of months' time putting some effort in at your side, for what?"
- "If it's a big vendor and you're asking for a feature, they'll probably turn around and say one of two things. First thing is no, or yes, that'll cost $100,000 and we'll have it delivered in 6 months."
- "You're just a bit-part player, no matter how big you are."
Chapters
00:00 Why a buyer would bet on a startup over CrowdStrike
04:02 Robbie's early days helping startups with pen testing
07:15 The 50 to 200 person company: the CTO is still running security
08:22 Security as a business enabler, not a cost centre
11:56 Big name or startup? How Robbie decided as a buyer
13:24 What "work with the vendor" actually means
14:21 Mitigating the risk: baseline, get-out clauses, open source in parallel
15:32 The FNZ story: a startup pen test vendor across 100+ clients
18:00 Coaching a founder to win mid-market early adopters
19:55 What's changed about getting in front of buyers
24:57 The managed free trial
25:53 Going around security to the COO
27:55 The Chamber of Commerce and the "knitting club"
31:12 Field CISOs: do they work?
33:01 The AI governance wave, and building your own LLM
40:02 Cyber Donut hot seat: what JP Morgan did to Fortify
The Cyber Go-To-Market Talk is the show for cybersecurity sales leaders, founders, CROs, and go-to-market operators looking to improve cyber sales performance and build more predictable revenue growth. Hosted by Andrew Monaghan, founder of Unstoppable.do, covering cyber sales leadership, revenue leadership, sales onboarding, forecasting, pipeline generation, and cybersecurity go-to-market execution.
Follow me on LinkedIn for regular posts about growing your cybersecurity startup
Want to grow your revenue faster? Check out my cybersecurity sales consulting and training
Need ideas about how to grow your pipeline? Sign up for my newsletter.

