SkarpSkarp

Chapter 3 of 8

Discover the Buyer's Security Priorities

A chief information security officer, procurement manager, and chief financial officer can hear the same pitch and evaluate three entirely different risks. Strong discovery uncovers those hidden priorities before the solution is positioned.

7 min readen

1. Start With the Buyer, Not the Product

Discovery Before Positioning

Do not begin with features. Begin by learning which risk the buyer is accountable for and what a negative outcome would mean for the organization.

One Control, Many Outcomes

The same control can matter for different reasons: MFA may reduce account takeover for a CISO, fraud exposure for a CFO, and audit findings for procurement.

Use a Shared Risk Language

NIST CSF 2.0 organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond, and Recover, helping teams connect technical controls to enterprise risk.

2. Map the Security Stakeholder Personas

The CISO Lens

A CISO often evaluates whether the solution reduces meaningful exposure without creating unmanageable operational burden, alert volume, or integration complexity.

The Financial and Procurement Lens

Finance asks whether the investment changes loss exposure and cost predictability. Procurement asks whether the supplier, contract, and evidence reduce third-party risk.

The Legal and Executive Lens

Legal focuses on obligations, defensibility, and sensitive data. Executives focus on resilience, trust, and whether cyber risk could disrupt strategic goals.

3. Stakeholder Lens Challenge

Stakeholder Lens Challenge

A company is considering a managed detection and response service after a phishing incident affected several employee accounts.

Match each statement to the most likely primary stakeholder:

  1. "Can this reduce the time between suspicious activity and containment?"
  2. "What will the three-year cost be, including onboarding and internal staffing?"
  3. "Can the provider complete our security questionnaire and accept our data-processing terms?"
  4. "If an incident becomes public, can leadership show that it had reasonable oversight?"

Suggested answers

  1. CISO or security operations leader
  2. CFO or finance leader
  3. Procurement, legal, or privacy leader
  4. Executive sponsor, board, or legal leader

Reflection: One stakeholder may care about more than one statement. Your job is to find the primary decision lens and the trade-offs between lenses.

4. Ask Risk-Based Questions Without Performing an Assessment

Discovery Is Not a Security Test

Discovery collects buyer context and priorities. It does not authorize scanning, testing, accessing systems, requesting credentials, or making compliance conclusions.

Follow the Question Ladder

Move from business process to risk scenario, current process, impact, and success metric. This produces useful context without probing technical weaknesses.

Create a Clear Boundary

If technical validation is needed, separate it from discovery: define scope, obtain authorization, document rules of engagement, and agree on expected outputs.

5. Identify the Current-State and Target-State Gap

Describe the Gap

A useful discovery finding states the current process, its consequence, the desired future process, and the evidence that would prove improvement.

Retailer Example

Manual reporting and business-hours monitoring create a delay. The target is continuous prioritization and escalation of high-risk identity activity.

Do Not Jump to a Product

The gap should first become a risk-informed requirement. Only then should the seller determine whether a specific product, service, or process can meet it.

6. Adjust Discovery for Industry and Data Sensitivity

Sensitivity Changes the Priority

Ask what data is sensitive, where it moves, which parties access it, and which operations cannot stop. These facts shape the buyer's risk tolerance.

Healthcare and Financial Services

Healthcare buyers may prioritize protection of electronic protected health information and care continuity. Financial entities may prioritize resilience, third-party risk, and incident reporting.

Use Current Regulatory Language

Do not describe proposals as final law. For example, HHS's HIPAA Security Rule update was proposed in December 2024; the existing Security Rule remains in effect.

7. Turn Interview Notes Into Priorities

Turn Interview Notes Into Priorities

Read these notes from a discovery call:

  • The CISO says analysts spend too much time investigating low-value alerts.
  • The CFO says a major outage during the holiday sales period would be costly.
  • Procurement says the company needs clear supplier assurance documentation before contract approval.
  • Legal says customer data is shared with multiple service providers.

Your task

Write three priority statements using this format:

`Because [risk or business consequence], the buyer needs [capability or outcome], demonstrated by [evidence or metric].`

Sample responses

  • Because analysts are overwhelmed by low-value alerts, the buyer needs prioritized detection workflows, demonstrated by lower false-positive investigation volume and faster triage of high-risk activity.
  • Because holiday disruption creates significant revenue exposure, the buyer needs resilient monitoring and response coverage, demonstrated by agreed response targets and tested escalation procedures.
  • Because third parties process customer data, the buyer needs supplier assurance evidence, demonstrated by completed due-diligence artifacts, contractual commitments, and documented data-handling practices.

8. Convert Needs Into Measurable Buying Criteria

Make Needs Testable

Replace "better security" with a requirement, priority level, proof standard, and accountable owner. This lets stakeholders compare options using the same decision logic.

Evidence Matters

Acceptable proof may include architecture documentation, service levels, reports, contract terms, a demonstration, references, or a formally scoped evaluation.

Protect the Must-Haves

A mandatory criterion is a decision gate. Do not let a long feature list distract the team from requirements tied to material risk, operations, or obligations.

9. Check Your Discovery Judgment

Choose the discovery question that best uncovers a measurable buying criterion without conducting an unauthorized security assessment.

Which question is the strongest choice?

  1. Can you provide administrator credentials so we can test your identity controls?
  2. Which response-time target would leadership consider acceptable for a confirmed high-risk account takeover alert, and how would you measure it?
  3. May we scan your external systems for vulnerabilities before the first meeting?
  4. Which security vendor has disappointed you the most?
Show Answer

Answer: B) Which response-time target would leadership consider acceptable for a confirmed high-risk account takeover alert, and how would you measure it?

This question connects a risk scenario to a measurable target and evidence method. It gathers discovery information without requesting access, scanning systems, or performing an assessment.

10. Review the Core Terms

Flip each card, then explain how the term would appear in a customer discovery conversation.

Stakeholder persona
A decision-maker or influencer defined by responsibilities, incentives, authority, and risk perspective rather than job title alone.
Current-state gap
The difference between how security work happens now and the outcome the buyer needs to achieve.
Target state
A defined future condition that describes the desired security outcome, process, or level of assurance.
Buying criterion
A verifiable requirement used to compare solutions, usually including priority, evidence, and an accountable stakeholder.
Risk-based discovery
Questioning that starts with business processes, threat scenarios, consequences, and desired outcomes instead of a feature checklist.
Unauthorized assessment
Security testing or system examination performed without explicit written authorization, agreed scope, and appropriate rules of engagement.

Key Terms

CISO
Chief information security officer; the executive commonly accountable for the organization's cybersecurity program.
Evidence
Documentation, metrics, demonstrations, contractual terms, or other proof used to verify that a requirement is met.
Target state
The desired future cybersecurity outcome that the buyer wants to reach.
Current state
The buyer's existing process, control environment, or operating condition as described during discovery.
Risk scenario
A plausible event that connects a threat, vulnerability or condition, affected asset or process, and business consequence.
Buying criterion
A requirement that can be evaluated using agreed evidence, priority, and ownership.
Data sensitivity
The potential harm, legal obligation, or business impact associated with unauthorized access, disclosure, alteration, or loss of data.
Third-party risk
Risk arising from suppliers, service providers, partners, or other external parties that access data or support business operations.
Stakeholder persona
A practical model of a participant's responsibilities, decision authority, incentives, and security concerns.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself