Business Tactics in a Broken Infosec Sales World

It’s a not-so-secret, secret, that cybersecurity $vendors are not paying their sales staff for renewals. This results in high-turnover of sales staff, ghosting, poor support, and aggressive sales.

The result within orgs takes the form of shadow IT, bad tech rationalization, half-assed deployments, overworked FTEs, and constant re-tooling.

What are some techniques you’ve found to be useful?

My number one go-to, is termination of convenience clause within contracts. You won’t find much luck with Microsoft and AWS, but you will with even largest cybersecurity organizations, even as a mid-enterprise. What this means, is despite an immaculate proof-of-value / RFC, they have a financial incentive (sales don’t get paid until the period has passed) to ensure a perfect post-sales deployment; you’ll get their A-team, training credits, and possibly PS hours.

There’s probably a heap of other things we do without thinking about it, like not allowing sales to divide your teams and always document every proof-of-value, to build resistance to organizational regime changes.

Depending on your role, much of this may be out of our control, such as software purchasing on P-cards, silo’d orgs, weak-willed peers with buying power, but I’m interested on how others handle this race-to-the-bottom, short-sighted sales world we have to operate in.

I treat buying software like building software. There is a scope, requirements, all that. I share that with vendors. If they aren’t willing to show me how their product meets our requirements, then the conversation is really really short.

This works in the renewal world too, but internally. If the C levels are renewing out of default, I show them the requirements document that the working stuff put together, and show that it doesn’t meet our needs any longer, if that’s the case.

Honestly doesn’t always work. But that’s OK. It’s like the security onion to the sales process - layers layers.