Cult Products podcast artwork for Inside the CISO Mind: Trust, Culture, AI, and the Sales Moves That Backfire

Inside the CISO Mind: Trust, Culture, AI, and the Sales Moves That Backfire

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya2 min read

With Ryan Lindley, Co-founder and CEO, Aegis Cyber

Key takeaways

  • Every security product either reduces a CISO’s load or quietly increases it.
  • The CISO role still carries real ambiguity, and reporting lines shape outcomes more than org charts suggest.
  • Influence and people skills matter as much as technical depth in the seat.
  • Much compliance evidence fails a basic reality test.
  • Certain sales behaviors do not just fail, they get a vendor blocked.

The load test#

The sharpest idea in this episode is also the simplest. From the buyer’s chair, every product either lightens the load or adds to it. Security friction, engineer context-switching and the operational tax of another console are all real costs that vendors routinely leave out of their business case.

For founders, this is a useful lens to apply to your own messaging. If your pitch cannot say plainly what it removes, the buyer will assume it only adds.

Why the CISO role is still ambiguous#

Ryan is candid about a role that has not settled. Reporting structures vary, authority does not always match accountability, and the personal risk carried by the person in the seat is higher than most vendors appreciate. He talks about reducing internal tension through culture, influence and security champions rather than through mandate.

What earns trust, and what gets you blocked#

Ryan describes what actually earns his trust as a buyer, and the sales moves that shut the door fast. This is the section worth playing to a sales team. The behaviors that backfire are familiar to anyone who has watched a founder get impatient: pressure, false urgency, and pretending to understand an environment you have not asked about.

The pattern matches what we hear repeatedly. It was the canned drip campaign that turned one buyer off, not the product.

AI adoption and downstream liability#

The conversation turns to how CISOs should approach AI adoption and governance, including the liability that flows downstream from decisions made quickly. Ryan also discusses what a control plane across governance, risk and compliance could bring together, and why so much compliance evidence does not survive contact with reality.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions