Episode 29 - Selling Cybersecurity Without Fear In The AI Era (w/ Guest: Dor Eisner)
32m 30s
In the conversation, Dor Eisner emphasizes the need to sell cybersecurity controls without instilling fear in prospects. He shares his extensive experience in cybersecurity, starting over two decades ago in the Israel Intelligence Force. Eisner stresses the importance of understanding customer pain points and engaging with them personally, recommending methods like lunch and learn sessions for effective marketing. Additionally, he mentions the value of providing valuable information during engagements, such as discussing cyber threats and SMB security. Eisner also mentions the free community package offered by Guards to MSPs, emphasizing the importance of delivering value to clients in the cybersecurity industry.
Transcription
5693 Words, 30731 Characters
How do you sell cybersecurity controls without having to rely on fear to make your prospect understand the urgency and value? Well, frankly, you start by listening to really smart people like today's guest. I spoke with Dor Eisner. He's a CEO and a founder from Guards. You've probably seen him around the channel before because he's been in cybersecurity for a really long time for most of my life. And he has some really fascinating perspectives on why cyber is difficult for prospects to understand, but some of the really tactical things we get into at the end of how to actually go about creating those conversations and some of his actual ideas that he's used to help MSP sell cybersecurity controls really, really valuable. So I will get out of the way. Let's get into it. Dor Eisner, so glad you're here, man. Thanks for joining me. Thank you, Brian. Thanks to you're coming from all the way from are you in Tel Aviv? No, I'm actually in Miami. Oh, Miami. Okay. So disregard. Okay. So you're closer to me than I thought you were, but listen, I'm so glad you're here. We connected a couple of months ago. Guards has been on my radar for a while. But the reason that I wanted to have you on the show is that there's not a ton of vendors who know how to talk about selling cyber without going very fun heavy. And there's not a ton of people out there that can seem to know how to sell cyber. But the more I've looked up you and the more we talked, the more I realized you got actually a pretty long pedigree of working in cyber and selling cyber. So what I'd love to do is I want to hear a little bit about how you got into sort of the cyber world, the IT world, because you've got quite a storied experience. Could you just tell us a little bit about that how you got into cyber and sort of how you got to what you're doing now? Sure. I started doing cyber security more than 20 years ago. I was a commander in the Israel Intelligence Force and we did cyber security way before it became a category. The pioneers of the first firewalls like checkpoint and I think that if you think about cyber security as a market, more than 50% of the cyber security that is being deployed worldwide is produced in Israel. And this is crazy to think about. It's such a small country and such a big, you know, a producer for the cyber security industry. And the reason is that, you know, there is a big foundations of the young generation coming into this amazing, you know, early days experience of doing hands-on cyber security and walking for the government for the army. And then it's like straight to the enterprise industry and through the event of a relationship and stuff like that. So I started to do it like more than 20 years ago. And then I moved after about a decade to the start-up world. So about a decade ago, I started my first company. It was IoT security. And then I started another company. It was a threat intelligence company, a monitor in the dark web and stuff like that. And then we sold it to WAPI-7 and then we started guards about a three years ago, a mission and a vision to help small businesses and MSPs secure their clients in a better way. So that was the journey of about 22 years now. And I'm very proud to help, you know, the small business community and the MSP community get better security for their clients and better protection. Yeah. And you've obviously been doing it, as you said, for a very long time. It's interesting to think about that that anybody who works in tech at all knows that like Tel Aviv is where all the security startups come from. They're all there. And it's interesting to think about the fact that that's 20, 30 years in the making. An entire generation committed, obviously like more of a militarized society, right? Yeah. And not just, and with that comes, has come sort of an investment into people and into the concept of cybersecurity and socializing cybersecurity more culturally. It's interesting to think about it that way. But what's unique about you, though, is that you don't just know the tech, but you've been selling the tech. So you have, are you, you have a technical background, though, correct? Yeah, I have a technical background, you know, in the first five years, you know, I was a technical, you know, like a leader and then I became, you know, like a director level, you know, for the government. And then I started my company and doing cyber security and, and you know, as a founder, you need to know everything about the business. You need to know the technology side and you need to know the business side equally. And then, and that's what leads me, you know, today to focus more on the business and the go to market side. But you know, with the strong foundations of, you know, knowing the technology and what we need to develop. And also attract the right talents, you know, to develop the product. Sure. And that's probably another, that's something we can pivot to a little bit is talking about attaching talent. But how did, how did you make that transition from being a technical person, the classic emith founder, right? Like you have the skills, the technical trade skills you went into business, but you've clearly been able to learn how to sell this. And we'll talk about your specific, how we sell without using fear. But how did you develop those skills? And what was that process like for you to figure out as you started talking to non technical people about these hyper technical things? What was it journey like for you? It's an interesting question. I realized very early in the first venture that talking with customers and trying to pitch the solution, it's equally important as developing the solution. Because if you develop the solution without talking to the right ICP to the right customers, then you're wasting your time. So I realized that, you know, that first, you need to build a massive, you know, go to market engine and build the product based on the demands from the market. So I liked it a lot. And that's why, you know, like I stayed in this founder mode for about a decade now. And I just like to build things and talk with customers and help customers achieve their goals. And with the technical background and cybersecurity, I think that this the right combination of building a successful venture. You might have already answered this earlier, but what would you say? What was the most crucial thing that you discovered or that you did or that you learned that actually helped you sell these cyber solutions? Understanding the pain. Okay, talk more about that. I think that sales, it's all about understanding pain. If you understand what is the pain of the one that you are trying to pitch or to attempt to sell the solution, talking about the pain, go deep on the pain points. That's the right way, you know, to position the solution in the best way. And that's also the best way, you know, to fine tune the offering or the product or the product market fleet or the valuable position, you name it in the right direction. It's all about the right pain and how deep you understand the pain of your prospects, but then check lines. I love that you just said that because so many times I see tools founders reach out to me all the time about wanting to talk to MSPs and how do you sell the MSPs and stuff. And oftentimes it's a some cyber vendor who wants to get in the stack. And you look at what they've built and they've usually they've engineered and engineered and over engineered this big complicated thing. And then you say like, what does it do? And they kind of can't even really answer the question. They explained how it works, but they didn't build backwards from product market fit. And so you seem to have maybe it's just the way your brain works or I don't know what your magic sauce is that you realize that you're using all of your cyber know how to reverse engineer an ideal outcome, a K an ideal product that's actually tethered to something that people need instead of saying, I'm going to take everything I know how to do and smash it into an application and then see if people buy it because I'm smart. Yeah, exactly. You know, like when we started to develop the product, we had a few dozens of design partners even before we we wrote the first line of code. And just on the concept, just on the direction, just on, you know, like the value proposition that we are going to bring to the game. And I think this is the right way to go when you're trying to build something. And from the other end, you know, we are talking about go-to-market and sales of MSPs, you know, for the small business clients, it's also about the pain points of the clients and the value proposition that you as an MSP can bring to the game. And understanding those pain points, it can be like regulation, compliance, insurance, you know, word of mouth, fear, I don't know, whatever, whatever is the pain, you need to deeply understand the pain in order to position your value proposition, your delivery hotel. Yeah. This is a good segue into the fear conversation, then, because how do you, I'll just ask it as plainly as I can think. How do you build a go-to-market motion for your cybersecurity offering around the pains that it solves without it just being fud, just fear-mongering? How do you do that? Because we are not selling around the fear of, you know, cybersecurity. We are selling to MSPs about the pain points of MSPs. For example, one of the pain points is operationalization. You know, if you want to deliver cybersecurity and you want to do it well, you need to understand that this has a lot of costs in your operations. So how you save costs and how you reduce your operational costs, cogs, whatever you call it, in terms of the delivery that is going to be profitable for your business and can scale. This is one pain point. The other pain point is how you, how you evolve your stack against the evolving threads because threat actors are not siloed at methods. They are actually augmenting and consolidating their methods. The cybersecurity landscape is more about the siloed stack that MSPs are using and if you have a siloed stack and the bad guys are not siloed at methods, so you are lost in this world. And what we are trying to say and what our vision is is that AI is a big component of the selling point these days because AI is obviously everyone talks about AI. Everyone uses, you know, chat GPT and those kind of generative AI. But also the bad guys are using those tools to accelerate and to evolve their ways that they are going after businesses. And what we saw in the last three to five years is a different, is a different black market. It's a different dark web phones. It's a different ways of doing cyber security or, you know, like cyber criminals operating around cyber security. And what we realized in the last two years that the way that they are implementing Gen AI into their attack methods is getting much better than everything that we see in the last decade or so. So the last two years accelerated, you know, more than a decade of cyber security tools in the back markets and the darkened forms. And this is what the main thing that MSPs should think about when they're going to their clients. Explain why AI is changing your life, why AI is changing your business, why AI is a big opportunity for your business, but also why AI is such a big change and a big acceleration for the bad guys going to democratizing tattoos. Right. And so your suggestion would be for the MSP listening, you've got these great tools in your cyber stack and all that's good. But you have the responsibility to get buy-in from the people who are ultimately paying for it. Because first of all, they need to pay for the tools. But second of all, they need to be compliant with the best practices. Then you actually, okay, you sell them MFA. Now they've got to use MFA and not turn it off. And you know, all that kind of basic stuff or privilege access management. Those things, their quality of life or their workflow, there's adaptations to interacting with technology when you're using best practices for cyber. So you need buy-in from them. So your suggestion is to use AI as the beginning talking point to talk about how and why threats are evolving and therefore how and why security must evolve and kind. Exactly. Exactly. I think this is the best way to position your MSP service delivery. Because AI, the customers knows that AI is here and AI is going to stay. And this is the biggest revolution of the tech industry in the last few decades. And the impact of AI on cyber crime is is going to be tremendous in the next in the coming years. Yeah. Because yeah, okay, I liked this idea because as you said, AI saw ubiquitous that I'm finding that the comment, the end user, the CEO, the president of the 40 user accounting firm, who the MSP is talking to. AI to them is one of a couple things. It's either they have this reductionist view of what it is. So they're like AI equals chat GPT and the background editor, like I can remove people from the background on my iPhone photos. Okay, now I'm using AI. So they think of it as something very small. Alternatively, they think of it as this vague confusing and scary black box. Like I don't know what it is. And they feel inferior. They feel unequipped. So they have sometimes oftentimes there's FOMO. We're seeing a business is going, I think everybody else is doing it in a thousand X's in their output. And we don't know what that means. How do I use it? So then they might be attempting to use it in ways that are not compliant. Or they just have no idea, you know. So if we can position ourselves, obviously as the AI expert, that's a whole other go-to-market conversation we could be having that AI is a service, AI governance, AI management, AI deployment, AI utilization as a whole is a great service that managers should be evolving into. But also using this as the talk track to explain to them. Actually, here's some of the things they are capable of. Imagine that the entire, that the US military or that your country's military every soldier has a jet pack now. Okay, well, what does that do to our military capability? Okay, now imagine that everybody, that the other guys have jet packs or the other guys have jet packs and now they can hold their breath underwater forever. Okay, well, what is that doing to the way that we need to position ourself for national security? Security is a concept that's not foreign. Cyber security is just this vague, confusing kind of, it's ethereal. You know, they don't know exactly what it means other than they think of their email and maybe pop-ups, maybe bad links or something, but that's their entire perspective of security. They don't know about all the other stuff. I like that analogy of that. I mean, you know, like the special power of, you know, Cybersolja, think about it the same with AI, helping any cyber-junior criminal in the world, become the one, the worst sophisticated cyber-criminal in the world, in mass market, spray-and-pray motion. And think about, you know, the power of, you know, like, attack a service, fishing to a service, fraud to a service, malware to a service, ransomware to, you name it. And the power is just, you know, it's very cost-effective for the cyber criminals. And when it's very, very cost-effective, it's becoming a mass market problem and it's becoming the SMB problem. And you know, like, research, so talk about, you know, that more than 50% of the cyber attacks are going after small businesses. I'm saying that more than 75% because most of the small businesses are not even aware, you know, of the cyber breach, the data loss until it's it, you know, the right time. And then even if they're aware, they are not going to the police or today, you know, to the newspaper and say, "Hey, my business was breached." It's kind of a silent breach. Yeah. Right. So much of it is unreported, right, that the data is probably only showing us the reflection of the work. Obviously, what we can report. And maybe there's some speculation, but they're not going to report on that, right? They're not going to, there's, it's not concrete. And the, the final maybe thought on that is if, because deploying these threats, like you're saying, ransomware as a service, malware as a service, phishing as a service, if you can deploy a threat or an attack for pennies, you can afford to target people who might only be able to pay you 3,000 USD in Bitcoin. And you don't have to go for the people who can give you 250,000 in Bitcoin who have a ransom negotiator and they have insurance, but you can go to uninsured people because they don't have to file a claim because it's a small enough thing because you could deploy it for it for small enough. We're costs you nothing to get that money. And it's all automated. That's exactly the point. You know, we are in a kind of AI inflection point that the bad guys are leveraging its scale and the democratization of the attack service tools are scaling and spraying promotion against the very small businesses. And I think that there is a huge opportunity for MSPs to capitalize on the demand and to know how to pitch the value proposition around cyber security and not talk about the fear, talk about the potential impact, talk about what's going on in the cyber criminal forms and then trying to expand the customer that they are the next victim potentially without getting into the specific, you know, details, you know, what's going to happen without like what I might call twisting the knife, which that's what a lot of people want to do is they want to twist the knife and say, wow, what could happen if they got your child's photo and then they did all of these horrible things with it and they stole your life savings and you get really into the details. Now the thing about fear is that fear works just like lying works. It doesn't mean you should do it. You know, you could tell people whatever they want to hear to buy your to buy your program that doesn't mean you should sell it that we shouldn't lie to do it. But let's get tactical for a minute because you're a guy who's as I said, you've you've had so much exposure, not only selling what you sell to man services, but passing through like there's a reason your your tool is used by so many MSPs because it's impacting MSPs ability to generate new revenue. So let's let's get tactical for a minute. What are some of the actual go-to-market motions or strategies that you are suggesting to an MSP? How do they get this sort of awareness out there? How do they get it in front of people? Are they doing lunch and learns? Are they just doing standard email campaigns? Like what are you seeing people do successfully to create that awareness? I think the more engagement around the personal engagement, I think that lunch and learn webbeen house. You know, this kind of digit, this kind of marketing works better than the spray and spray called email, you know, like a cold calling and stuff like that. I think it's much better these days because people are looking for this personal, you know, with all the digital world that we are living, people are looking for this kind of, you know, personal engagement. And so I think that these two motions should work perfectly for the right communities, for the right locations. And then come to this webbeen house with value. Talk about, you know, like what's going on in the black markets? What's going on in the world? What's going on in SMB security? I don't know, pick the topic and bring to this meeting the right information. And the right information, for example, at guards, if you are an MSP using the platform even for free, you know, even beyond our community package and we have a community package for free that any MSP in the world can join our community package and use guards for free, zero dollar, zero commitment. And we have like a tool that we call it a prospecting tool that you can just put the domain of the business and you get after a few minutes, a very detailed report about all the vulnerability, all the exposure, all the, you know, the dark web data that was leaked in the wild and all the, you know, open ports, vulnerable operations system, you know, stuff that is missing in the business. And when those prospects come to your webinar to talk about whatever is the topic, then you share with them, you know, in the end of the end of the this webinar, hey, just wanted to give you some, you know, information about your business. Boom, they go for something and then you are sharing something about their business. That's great. Then if they start to ask question, you can, as an MSP, you can say, hey, let me onboard you on my tools, free of charge, a week of, you know, valuation without any commitment. And after a week, you can generate from the guards platform a business review report, fully automated, fully branded. And then you can get this report and put it on in front of the MSP is one of the business owner and say, listen, this is what we discovered, you know, initially, this is what we discovered after doing like deep dive analysis on your business, connecting to your Microsoft 365, to your emails, to your devices. This is the situation. Now I can help you. If you want my help, you can get my help. If you want to talk with someone else and get the help, but I recommend, I highly recommend you to do something. I love that. So, so your suggestion is you, you do a webinar or lunch and learn something like this at the end of the 11 webinar, you say, hey, by the way, put your email or, you know, hey, I punched your domain into this free search, by the way, the entire dark web has access to this for $2 a month or for free. So this is something that I, every bad guy has. I'm not, I'm not creating any new attack surface, right? Like I'm not exposing anything that isn't literally out in the world for anybody who wants to find it. Now you are the, just you're added to the list of people who can see it. Here's all of your open ports. Here's all your cyber role and ability. So all your lap certificates, whatever it is. And you're suggesting then, hey, let me, let me put my stack in at seven days and let's run another report and see how much better position you're in and I won't charge you anything. Exactly. You schedule the meeting right then. Go ahead. Lead with value. That's what I'm saying. Lead with value. And in small pieces of values, don't bring all the value in one time. Bring a small piece of value and then another small piece of value and then your full value proposition. And if your, and your, your full value proposition resonate, then you can get a deal. And if it's not resonant, maybe someone else will get a deal. But at least exposure, your, your business exposure is there. Yeah. I mean, if you did what you just said, let's say you did a lunch and learn to get six business owners to come to a dinner with you. And you got two of them to take you up. You ran five reports. One of them opted out. Two of those reports said a week later, they went, wow, I went from all of these risks to no risks. And then they say, what happens if you pull all your tools out? You say, well, then you'd be in the same position you were before you met me. I'm happy to do that. But you pay me $2,500 a month. We manage you blah, blah, blah. By the way, since I already onboarded you, I'll weigh my onboarding fee, $0 onboarding fee. We start today. And 12 month commitment. If we're unhappy for any reason, you'd give it to me in writing. If I can't fix it in 90 days, you can break contract. If you do that for two people, one of them says, yes, guess what? You just turn a six person lunch and learn. You bought six people dinner, $70 promoting it. And you got a great $2,500 or more client. You just do that every four weeks. Do it every week. Do it every week. Whatever is the cadence that you can, that you feel comfortable about. But that's that's how you should, you know, attract new new business in this in this age. I really like that strategy. So that's okay. That's a great idea. If they wanted to do something like this, I agree with you that the more kind of hands-on approach, the relationship driven one, where you're actually talking to them is for sure the most effective move. But just so that we give everybody sort of a door number two. Is there any other way? Is there a more of a one to many approach? Could you do the same thing on a webinar with 50 people attending? Or do you think it loses efficacy when you go? I think webinar is the second option. Like I think lunch and learn, or dinner, community dinner, it's the best way to go. Small scale, but I value probably icon version rate. Webinars is the second way, digital webinars, and bring some, bring someone to talk about something besides the security or the or the topic, you know, talk about, I don't know, organic food, whatever, or how to make your employees, you know, happier, whatever. And I think the third one is more like, you know, events, you know, like you can go to different events that are not like MSP related events, like just business owner community, you know, chambers of commerce, stuff like that, and, you know, just position your stuff there, you know, like pay for the food, I don't know, few bucks, 300 bucks, and come well prepared, you know, like get the list of the audience before you come to this event, prepare some reports and prepare some, you know, like a pre-cooked, you know, like a stuff for the specific alliance and title to get them, you know, into your booth, with the right, with the right message. Yeah, I love that. So Webinars is a second good option. Frankly, if it were me, I would be calling vendors, cyber security vendors, I'd be calling people like guards and going, hey, do you have any, can you help me? Do you have any MDF? Do you have any giveaways? Do you have any promotional materials? Can you guys help me fill this room? Can you get me five people, help me get five people in the room? We are doing it for our, you know, certified partners anyway, you know, like because we have a big, you know, investment in digital marketing. So anyway, we are getting a lot of businesses, you know, small businesses to our funnel, and we are not able to sell to small businesses because our product and our platform build for MSPs. So it's too much complicated, you know, for small business to operate. So we are sending the leads, the small business leads into our certified network of MSPs, so feeding our certified MSPs with leads, you know, that are coming into the funnel. So that's one thing that we are doing, and the second thing is just MDF, you know, giving marketing dollar funds to our certified network, a, you need five thousand dollars to do this event, go do this event. If you believe it will, it will generate business because your business is our business and we are, we are in it together. Yeah, I mean, I love that so much. This isn't a perfect example MSPs of, you actually have, you can take responsibility, you can take power over your brand presence and other people are out there to help you because the MSP is the, MSP is the entry point into the small business that people like ours, you just said, you can't sell your product directly to the company because they need, they need an intermediary, your channel only, and not probably almost everybody in the MSP stack, frankly, you could call all of them and say, hey, do you want me to sell 50 more licenses? Great. Help me. I need to buy this booth. I bought the sponsorship thing or help me pay for the sponsorship fee for this golf tournament. I need this $400 booth for a backdrop. I need to buy a TV so that I can run assessments right there. I need to buy this. I need to buy some swag to give away. I need to do something and get some help. And even, hey, do you guys have any talk tracks? Do you have any scripts that I can use? Can you guys help me with any of that stuff? This is how you should be leveraging the army that is behind you that needs you to succeed. Door makes more money when you close a new deal. So he wants to help you, right? And I'm using you as a figurehead, right? Of course, but this is good stuff. Absolutely, man. Yeah. Okay. I mean, look, we've covered it. I think we got right to it. Is there anything else we need to address? Is there anything else you want to say to the MSP listening who, especially I would love that there's any other tactical stuff you can do to explain the difference between educating them on the threats versus twisting the knife and basically threatening, making them feel threatened or uneasy by the threats? It's all about, you know, like education and open conversation. And it's more about why you are better than the other MSP in the neighborhood. So keep keep this in mind. And I know that you know, obviously the cybersecurity market is highly fragmented and probably 95% or 100% of the MSPs probably using some point solutions in their stock in the arsenal. But keep in mind that if your cybersecurity is not up to date and your silo detections are not coming together, you are losing a lot of context. And even if you get the client and you won't provide the great product or the great service delivery, you will lose the client. And churn is is terrible, you know, like it's better not get the client, you know, from the early, from the moment you start. So keep in mind that it's about education. It's about getting the right customers and it's about deploying the right security tools into these customers. So we are happy to help with all of that and obviously support MSP community because that's what we do, you know, day in, day out. And please feel free to reach out to me directly. If you have any question, obviously you can get in guards, you know, guards.com and get, you know, get the exposure, get get everything ready and get just the platform, you know, to play with and, you know, operate, you know, get the report, everything is free of charge. We are not charging for any user, generate report, anything that is helping MSPs to drive business. If you get the business, we charge for the subscription because we are a rev show mode. Yeah, I love it, man. Okay, well, those links you just mentioned are super valuable. We'll put those in the show notes for this. Thor, thank you for joining me. I know you have a really tight schedule. I'm glad we're able to squeeze this in and I think this is going to be very helpful to a lot of listeners. So thank you very much. Thank you very much. Thank you very much and I hope it was
Podcast Summary
Key Points:
Dor Eisner, CEO of Guards, discusses the importance of selling cybersecurity controls without relying on fear.
Eisner shares his background in cybersecurity, starting over 20 years ago in the Israel Intelligence Force.
Understanding customer pain points and the value of personal engagement, such as lunch and learn sessions, are highlighted as effective go-to-market strategies for MSPs.
Summary:
In the conversation, Dor Eisner emphasizes the need to sell cybersecurity controls without instilling fear in prospects. He shares his extensive experience in cybersecurity, starting over two decades ago in the Israel Intelligence Force. Eisner stresses the importance of understanding customer pain points and engaging with them personally, recommending methods like lunch and learn sessions for effective marketing.
Additionally, he mentions the value of providing valuable information during engagements, such as discussing cyber threats and SMB security. Eisner also mentions the free community package offered by Guards to MSPs, emphasizing the importance of delivering value to clients in the cybersecurity industry.
FAQs
Start by listening to experts and focusing on the value and urgency of cybersecurity solutions.
Dor Eisner has over 20 years of experience in cybersecurity, starting in the Israel Intelligence Force.
Understanding customer pain is crucial in positioning cybersecurity solutions effectively.
AI can be leveraged to demonstrate the evolving nature of cyber threats and the need for advanced security measures.
Engaging in personal interactions like lunch and learns and webinars can be more effective than traditional marketing methods like cold calls.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.