Skip to content
AppSec PodcastThe Application Security Podcast — home
47 minSeason 12, episode 11

Sean Varga -- OWASP Top 10 for AppSec Sales

with Sean Varga

on OWASP Top 10, Security Culture and Conferences and Community

Audio hosted by Buzzsprout. Nothing loads until you press play.

We’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga. Sean shares the unique challenges and best practices in AppSec sales, like the importance of empathy, understanding customer needs, and community participation. Learn about the OWASP top 10 for AppSec Sales and discover how to achieve success by aligning with customer goals, maintaining detailed living documents, and fostering strong partnerships.

Mentioned in this episode

Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.

Transcript

7,895 words · assemblyai

0:00Chris RomeoAppSec meets sales strategy. This is not your typical security podcast, but a glimpse into how sales work in AppSec. As security practitioners, we must practice empathy. This is our chance. We're unpacking the OWASP Top 10, not for vulnerabilities, but for what drives successful AppSec sales. From knowing your customer's go-live date to understanding their SLOs, MBOs, and the full stakeholder map, we'll explore how empathy, execution, and community participation make or break success. We'll talk about living documents, trusted partners, and why your current deployments are the blueprint for future wins. Today's episode is brought to you by Security Journey. Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10. Learn more at securityjourney.com. Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I am a VP now at Security Compass after selling DaVinci and co-host of, I don't know, the best application security podcast on the planet, which has no research behind it, by the way. That's just completely my statement I'm making here. Joined as always by my co-host, Robert. Robert, how's it going?

1:27Robert HurlbutGood, Chris. Yeah, Robert Hurlbut, Principal Product Security Architect and Threat Modeling Trainer at Torion. And congrats on the new role, Chris, and the sale and everything that's going on right now.

1:39Chris RomeoYeah, thank you. It's been a busy time, but that's a story for a whole other podcast. When I start my How to Sell a Company podcast, we'll get into that. So, joined by Sean Varga, and Sean has had, I'm aware of a number of different roles in sales across different application security companies. And I like the opportunity to talk about something sales-related because sales often gets a bad rap in our space. And having founded 2 companies, I've built sales teams and know kind of how the sales process works. But before we get into that, Sean, you know, we always ask people their security origin story. So walk us through where you're coming from.

2:25Sean VargaYeah, no, thank you. It's an honor and a pleasure to be here. It's so good to see you both. And again, congrats, Chris, on the acquisition. Um, yeah, the, the origin story is pretty simple, I guess, from the sense that, uh, I graduated from college in 2009, you know, right after the crash. And around 2007, I always knew I wanted to be in sales, and I'll talk more about that in a second. But, um, I have to give kudos to my dad. In 2007, when I was trying to figure out what type of, uh, profession I would have or what specific domain I would, I'd work in, he said, cybersecurity really seems to be a huge problem. And this is 2007. He's like, everything that I'm hearing, my dad's always been in, in the IT world, particularly CRM sales. He's like, something's going on in security. He's like, I think you'd really enjoy it. It's very technical. It's very interesting. And his recommendation was to start at RSA Security. You know, at the time they were the biggest name in the world. They had just been acquired or around that time been acquired by EMC. And so he said, hey, that's a place I would go. I lived in Massachusetts. They were in Massachusetts. It was a no-brainer. And lucky enough, Through a bunch of hard work and grit, went through an interview process and started there. And I did get a little bit into application or virtualization capacity planning and monitoring, uh, early in my career after RSA, but not too long after that, I got into application security at Veracode, um, during just wonderful days with wonderful people. This would be about 10 years ago that I started. And I just caught the AppSec bug. It's a really hard, challenging, fun thing to dive into every day and been in it ever since. So happy to provide other context, but that's kind of how I got into AppSec, if you will.

4:22Chris RomeoCool. So we're going to get into talking about some of the things that you're thinking about as far as the best, we'll call them best practices in AppSec sales. Something did, and I'll let Robert kick that off in a second, but something that you, that you shared with us, uh, kind of in our pre, pre-show process was about your first and only customer return at Veracode. So I'm curious just to get some perspective on this story.

4:51Sean VargaYeah, no, thank you for asking about that. So in like the, the top 10 best practices for application security sales, one of them we'll talk about is a living document. And so particularly when I was at Veracode, I was working with an organization, um, where they were looking for static and SCA for, I think it was like 10 applications. And we had all the application languages correct. We had their infrastructure correct, but we did not have their operating system correct. And we did not know it. And we did not support, I think it was like 7 of the applications. Um, and application security is just so complex. You might have support for the language, you might have support for the frameworks, but maybe you don't have support. This is particular to Veracode and particularly, you know, a long time ago, 9 years ago, they didn't support that OS at the time. And after the purchase and they started to deploy, they've determined, oh, this doesn't work on majority of applications we need to scan. And they end up doing a return. My only return in life, and obviously I wanted to, you know, die when it happened. It was, for me, really crushing. And when I went to our finance team, you know, Veracode was a very big operation then. Went to my finance team and said, hey, this is the situation. They're like, oh, no big deal. You know, we live in a complex world. These things are going to happen. Not the end of the world. This is how we do it. And that's something I just will never forget. It's really important to be very detail-oriented when you're talking to your customers in application security, because there's just so many things you have to get right so that the application security solution can work throughout the enterprise, if you will.

6:36Robert HurlbutVery cool. Very cool. Well, like we said, we're going to dive into this topic today. Oh, you're calling it OWASP Top 10. But essentially, it's a top 10 of AppSec sales and really, as Chris mentioned, characteristics or attributes of really good approaches or thoughts about AppSec sales. Let's start with number 1 and go down the list. But the first one you note is empathy. Tell us about that.

7:10Sean VargaYeah, so I've been very fortunate from my time at Veracode and at other, at RSA Security, is to learn how difficult, not just application security is, but application development as a whole. Um, Chris Weisopel, from one of the co-founders of Veracode, always said, Sean, application development is an art and a science. And to write just performant and quality code, um, alone is very hard, let alone secure code. And as I talked about earlier with that return of error code, it just, their job is very hard. And when you get, dive into your first role at an AppSec vendor, and you're talking to customers, and you're talking to an AppSec leader, you can just see the pain on their face, right? They're trying to help developers secure their applications. And that's always at odds with application development, trying to release new features, and it's— the job of developers is trying to write performant and quality code. It's just very hard, and trying to teach them about all of the security implications is just even harder. So, you have to have empathy, not just for the AppSec leaders, or who have this very hard job, but you have to have empathy for the developers that are trying to write performant code and get it out the door as soon as possible. and empathy for the app dev leaders and DevOps and just everybody in that scenario. It's just, it's not easy. It's why, for anyone working at a software vendor, you're always wanting more features faster, and we need to deliver them secure too. So, hopefully that is a helpful answer.

9:00Chris RomeoI guess I want to ask kind of another question on this single point, because I'm curious, I mentioned kind of in my preamble that often salespeople in general are seen from a negative perspective. I'm just gonna throw the cards on the table, right? There's no reason to be anything but transparent, right? Like people tend to think of salespeople, ugh, salespeople coming my direction, or they're messaging me on LinkedIn or whatever. Like, How do you maintain empathy when we have folks in our industry who are not pro-salespeople? How do you keep that? How do you keep that same attitude?

9:49Sean VargaYeah, no, I appreciate that question. It's been my observation in the 15 years I've been doing this, 16, whatever it might have been, is that No matter if it's an AppSec leader or a CISO or a CIO, I've actually observed that most people are getting nicer. And I think the world is, you know, if you go back to when we could actually print words and we could start to read and get the word out there on different information, just the transparency we're seeing and everyone is listening to podcasts like this and really improving upon themselves. And those that brought a negative tone, an angry tone out of the blue and just decided to have their first interaction in just with a negative light and assume, you know, judge a book by its cover. I just don't really see those that much. Yeah, of course you run into somebody that might've had a bad day. You never know what somebody's dealing with, right? They could have a really bad personal situation happened to him recently. But for the most part, I mean, I find most people are really nice and I enjoy when somebody's, you know, rude, right? It's just, it's when you're doing something very hard, if someone's not trying to partner with you and be open and honest and transparent, I can't help them. We'll never be successful. So it's an easy way to kind of disqualify the situation is, you know, they say you don't want to bring on a bad customer. And so most people are nice and somebody's cranky, kind of disqualifies them out, if you will.

11:24Robert HurlbutYeah.

11:26Chris RomeoAnd I think some of the way people buy now has drastically changed in the last 10 years. People are doing so much research in advance. By the time, I feel like by the time they get to the sales process, they kind of have their mind partially made up. At least that they need to do something. Maybe it's not, maybe they haven't chosen their vendor. Maybe they've got a couple of different vendors that they're looking at, but they're to the, they don't, it's not like people are, it's not like you're catching people very early where they're like, I didn't even, I don't even know if I have this problem. Like people are like, hey, I know I have this problem. I need a solution in this space. So now I'm going to go talk to a couple different vendors about what they could offer me. And in that, they've already, so they're already coming at this from a more positive perspective than maybe they were 10, 15 years ago where it was more of a, you had to kind of convince them that they had the problem and then get them to the way, you know, that they needed a solution to that problem.

12:31Sean VargaCompletely agree. No, I think you're pulling at a really important theme is a lot of buyers or practitioners have already done their research. They're coming with a positive light, like they chose, they've chosen us. Or if it's through cold means, if I'm able to reach out to an AppSec practitioner and my messaging resonates with them, they typically, the messaging I sent them is good and they'll go into our website or they'll go into different, you know, chats they have with other AppSec practitioners and They'll do their research and they'll come and they'll say, yes, I definitely want to talk to you. So I agree.

13:07Chris RomeoOkay.

13:10Robert HurlbutWell, let's take a look at the second point. Success lives and dies with your customers. Yeah. Let's dive into that one a little bit.

13:18Sean VargaYeah, no, it's an important one. And that's why I put it at number 2 is, as we talked about AppSec being so complex and so hard, And really has been looked at as a blocker to accelerating new features. If you have an hypothesis that you've created a solution that can solve people's needs and you have customers purchase, you have to then have them succeed and deploy the solution how you think it should be deployed and hit those metrics, those success metrics that you use to measure if this is reducing risk, better managing risk. And so one of the things I learned earlier in my career is that you have to treat the AppSec community with utmost respect, because if you don't treat them well and do right by them, The word will get out very quickly that you're not a vendor to work with, you're not a person to work with. And so you have to get these few customers that you first land, get them successful, listen to them intently, deal with them on a day-to-day basis, get them successful. And then that will prove your hypothesis, which then you can take to new companies and say, hey, we helped XYZ company do this. This is what we're good at. Can we help you here? Do you have the same problem? And have those proof points. If an AppSec company just goes out and churns through all their customers, and everybody hates it and never hits their goals and just continues to move on, you'll, first of all, you'll run out of customers, and everybody will hear, hey, I don't think anybody's deployed this successfully. So that's, it's really important to focus on your customers.

15:13Chris RomeoYeah, I was smiling when you were sharing that because you're 100% spot on. Like, AppSec practitioners, we all, we have backchannel communications, we have, we get together at different, in different forums, and you mentioned communities and things like that. But yeah, we do talk behind the scenes about what we experience with particular vendors. And I've seen people get, you know, people definitely will share, hey, this is somebody who's not, this is, this is not a vendor you want to work with. And that's going to be a really tough hurdle to clear in the future when the practitioner space is hearing that, oh, this is a solution that has a lot of risk for you. Because face it, people are, when they buy something, they're often putting their name, they're attaching their name to the project, which means their future career trajectory is tied to the success of what you're describing, you know, the success of the customer. And so, yeah, I see that as something that I've seen very often. So curious about this next one. Show me who deployed your solution successfully and I'll show you your future customers.

16:18Sean VargaExactly. So every company I've been to, to be successful, obviously I'm in sales, I have to be successful. I have to drive successful new customers for the company is I don't guess, right? I don't read marketing literature or anything like that. I just look at Okay, who's bought us? Who likes us? Who's hit their goals? Who's renewed? Who's expanded their usage? And it's important. AppSec, there are so many disciplines. There's manual intervention, bug bounties, MPT. There's scanning, there's training, there's threat modeling. Everyone tends to have their particular space. And so, you need to look at, okay, who purchased? What vertical are they in? Is it financial services? Is it telecom? Is it software companies selling to big banks? Um, what size companies are there? Do you typically sign on 1,000 employee software companies? Are you just signing on the JPMCs of the world? You will see that ideal customer profile, who buys you, succeeds with you, and expands with you. And that's where you should spend your time. If big financials are buying you, you should go talk to other big financials. If it's, you know, mid-market manufacturing and retail companies, that's who you should go talk to. And that's what I think is really important, really selling anything, but in particularly with AppSec, because it is so particular, you need to know where you're having success and then focus on the dupli— you know, the other vendors that do the same thing, if that's helpful.

17:59Chris RomeoYeah, I have a kind of a different perspective on this that fits in the same words that you shared, though. Show me who deployed your solution, I'll show you your future customers. Had the experience, and maybe, Sean, you've seen this as well, where have a new customer come in, buys the product, and then in AppSec, people tend to move around a lot. And so then they go to the next company, and then they call up and say, Hey, I just moved over to Acme Corporation. Let's chat. Like, those are some of the best relationships from a sales perspective because they bought into the product enough to say, not only did I buy it at the first company where you met me, but I'm gonna, I'm bringing it. So you become part of their suite of products as they move around. And so I've had that happen a couple of times and it's just, it's a really powerful thing for, to have that type of reputation for the product. that people are willing to, to take it with them and bring it into their next ventures along the way?

19:01Sean VargaOh, big time. Yeah. I think it's the, probably the nicest kind of compliment you can, you can have is when someone in a new organization, they don't know the politics, they don't really know much. And when they can say, nope, I can depend on Chris, it, it's huge. And we had that recently at Psycho where somebody moved to a new company and same thing. It was, it was like, that's, that is a great signal. So, Yeah, no, I'm passionate about ideal customer profile and focusing your time properly because that's how I think being a good salesperson is, is as I get older, my title grows and I get more exposure, I'm starting to get a lot of sales emails, which is interesting for all types, different types of services. And the one thing that really bothers me that, and I work very hard on this in my outreach, is when someone contacts me that has nothing to do with my role. Like, it's clearly RevOps or the ultimate sales leader here. And that's what I work very hard. And when I do outreach is I don't contact the GRC folks or network security, you know, no one that would ever care about application security. So, I think that's really important.

20:13Robert HurlbutYeah.

20:13Chris RomeoAnd you hit on something that is part of the frustration. Right, that a lot of people have with the sales profession, especially in the tech space, is there's just a lot of sales folks that will go outbound and just plaster. They don't do any research into who they're messaging to. They just send the same message 500 times over per day, hoping to get the, you know, 0.02% hit rate or whatever they're going to get from completely cold outreach. And so, yeah, I mean, those are the ones that are, that are the most annoying. And, but I also appreciate when I get somebody who's obviously researched what I'm doing at the moment and actually has a legitimate thing that I might be able to use. Like, those are the, those are the powerful ones. And so, yeah, kudos for doing your research there and not just, you know, spraying everybody you can in the AppSec industry, hoping something sticks, right?

21:11Robert HurlbutYeah.

21:12Chris RomeoThat's part of the new way people buy. People don't want to be hit up, you know, with something cold that has nothing to do with their world. Occasionally you catch somebody on the right day where they just had an epiphany and this is the thing I need. But more than likely, they're not, they're gonna be annoyed by just a blast, you know, message that comes to them that's not specific to their problems. Yeah, no.

21:40Sean VargaAnd Chris, you kind of mentioned something. If you're cool with it, I'd love to jump into number 4, the living document.

21:45Chris RomeoSure.

21:46Sean VargaUm, because you mentioned something about preparation and whatnot. So when I was at Secure Code Warrior about 6 years ago, I had this epiphany. Um, my parents were, we originally were from Connecticut. Uh, my dad got a new job when we were, I was 8 years old. We moved to Massachusetts. Uh, when I was 10 and they were lucky enough to design and, uh, build a modest home on, in Massachusetts. And so I was there as an 8-year-old being annoying, but playing with my toys, asking when we could leave when they were in the, in with the architect going over plans. And I grew up, uh, my parents spending every weekend watching this old house, so they couldn't be more excited. And they were, they were in the plans like, oh no, let's make this bigger. Let's make this smaller. No, the door needs to be here. And I was working one day and I was like, you know, you are managing so many critical data points in an AppSec project that you need like a blueprint. It needs to be living because you're always getting more and new information from your customer interactions, whether it's when you're talking to a company for the first time and you're taking them through some sort of evaluation process, or as a customer, they're both So I've came up with this concept of living document that I'm extremely passionate about, and I bring the concept to wherever I go. And the team at Sitecode's been awesome to use it, which is you have these specific data points that you need to get right. What languages and frameworks do you write in today? What SCMs, what multiple SCMs, are they on-prem or are they in the cloud or are they self-hosted? Do you— are you using a CMDB? Is it ServiceNow? What is your ticketing system? It's— there's just an immense amount of questions to ask, and you need to have this document that you bring up and you share your screen and it manages all these things. When's your project go-live date? Who are all the stakeholders? Where is everybody located? So when we schedule meetings, we or friendly to someone that's in California or the UK or wherever it might be. And my experience with using it for the first time 6 years ago and sharing my screen and showing them as they say things, here are my pains, this is how I'm gonna measure success, right? These are the outcomes. These are my CISO's goals for the year. As I'm typing, as they're talking, 2 incredible things happen. One is they're like, wow, a sales rep is actually listening to me. What a concept. And 2, they, they, they kind of have this like physical reaction where they go, it's like they hired a project manager that's taking down all these data points. And giving it back to them to say, hey, I got you. I'm taking everything you're saying and I'm going to be the concierge of this process and make sure I have this all project managed out. And so you have it and then you can give that to them and you just win so many friends. I mean, I was on a call with a Fortune 500 this morning and I had my living document up and, you know, hey, How many SCMs? Oh, you have like a million. Good to know. And you even have some, some subversion out there. Let me put that, right? That note about subversion. Um, it's important that I take it down because later on that might come back to bite us, right? Maybe you need support. Hey, I, everything is aligned. The 1,000 points that we need on the technical requirements is aligned. It's that subversion that is that last little piece. If I didn't write it down, Mm-hmm. and have it in that living document, then I will, I would forget. I mean, how do you remember? I don't remember anything these days. I mean, with 3 little kids and a lot going on, you have to write these things down and it's 1,000 times harder for the people that you're selling to. So that I live and die after empathy, the living document is everything. And number 5, it has that go-live date, right?

26:04Chris RomeoMm-hmm.

26:05Sean VargaSo Bob Brennan, the former CEO of Veracode, love that guy. He said, Sean, you know what apps— he's, well, not to me. He said this to the entire company. We sell diet and exercise. That's what application security is. We're selling a process. And once you get past, uh, understanding what a company's technical requirements are and meeting those in a POV, if they get to the point where they say, yes, you technically meet our requirements and yes, you meet our licensing and cost for our project. You gotta fit into when they actually have time to deploy it.

26:45Chris RomeoMm-hmm.

26:45Sean VargaSo regardless of meeting all these different milestones in the milestone-driven process, it all, one of my favorite questions to ask from the first call is, all right, Chris, let's say you find a solution that meets your needs, any solution in the world, when would you actually want to and have the time to go live with it, start the subscription. You know, most everything is a SaaS subscription these days. And once you get that date, that tells you everything because they, they won't buy, they won't do anything until they can actually deploy it. So they might start a project, it's June, whatever, today, right now with you. But if they can't actually deploy June of next year, then That tells you everything about the project. So it's a really important thing and it's, and it's their timeline. It's not yours. I'm not doing some sales tactic. Hey, you know, if you get it this month, you know, half off, whatever nonsense is. You told me from the beginning, Chris, that you need to go live with this solution because of a renewal date or whatever compelling event. That's their, that's their date. And you have that right there and it shows up and Next call you go, ah, you know, we're, we gotta pull that back. We gotta do it sooner, or we gotta push it out. Just makes your life so much easier. And again, it's, you built so much credibility and respect with, with AppSec leaders when you show how detail-oriented you are. So, uh, I'm jumping ahead. I'm getting in my flow.

28:14Chris RomeoYou're describing in my mind what is a consultative approach to sales, which is in, in all of my companies, that's what I've done. That's what we've done with, with various sales teams, team members. Is if you go, nobody wants somebody that's going in, you know, for the quick close or the, you know, no, that just doesn't, it doesn't work in, based on the things you're describing, these are complicated technical projects. But I think that's really, that is one of the hidden nuggets that you've shared from this conversation is by asking that question up front, you have a great idea for what their success looks like. But also, what does their process look like? If they're saying, yeah, we need to go live on June 30th, 2026, they're not buying this quarter. It's not going to happen. It's just nobody's buying a year. They say, well, I'll just buy it and have it ready in case something happens. No, they're going to buy in the first quarter of 2026. It gives you some predictability. But I love that consultative approach, and that's what I've tried to do and tried to instill in salespeople that I've worked with. It's like, care about the success of the people on the other side, which, you know, it feeds back into empathy as you described it there. Like having their goal in mind is really what people want.

29:30Robert HurlbutYeah.

29:31Chris RomeoBecause they don't care about sales targets and things like that that are in the salesperson's world. They care about help me be successful in this thing that I'm trying to partner with you. So it's consultative and partner-based or partnership-based. Because there's a shared goal now that you have as the salesperson to help me get to my solution that I need on June 30th of next year. I think that's a powerful way to approach it.

29:54Sean VargaI appreciate it. No, and it's just, just things I picked up along the way. It's something we use at Secure Code Warrior a lot, and I've just taken it, you know, from that to, to SciCode, and we've really embraced that. So no, I, I appreciate it. And all, all credit goes to everybody I've worked for. So that's excellent.

30:10Chris RomeoYeah. So then we get to know your solution. Wait, you have to actually know the thing that you're selling? I can't just show up on the demo and go, hey, why don't you drive, uh, Mr. or Mrs. Prospect? You just drive, see what you can find. I'll just sit back and take notes.

30:24Sean VargaNo, 100%. And the reason why I didn't have this is, you know, it's, it's obvious, uh, and, and those that are in AppSec, it's obvious, uh, that you have to be very technical, right? I hear that a lot is you need to be a technical rep. You need to really know how your solution works. And I put it at 6 because I don't care how smart you are, it takes a while to understand what your solution is actually good at and what to be talking about. See, those first couple months you're at a company, you really have to rely on your solution architect. But as time goes on, as one of the things I always say, When you join an AppSec company, you're gonna— sales reps, I'm a crazy person when it comes to looking at data and like what good looks like and how, how do you track towards success? If an AppSec vendor does not give a new rep a current customer, particularly if you're selling to larger enterprises, to learn what the customer uses and how is it going, what's working well, and to get that customer story, they usually flame out. You need that customer so you can hear on the calls where you're not necessarily doing much. Usually it's customer success manager, solution architect, or handling the rollout of the customer. But just to hear like, okay, I'm going to be turning on pull request blocking and this is how it works and this is the capabilities. Oh, and they really like that. That's good. Oh, they don't. want to do this now, because that doesn't make sense. They want to start with secrets or it's, it's so critical. So you build it up over time and, but you ultimately need to know your solution's value prop and who's it made for, who's it work really well for. And it's the only way you can effectively sell it because people sniff out immediately that you have no idea what you're talking about.

32:17Robert HurlbutLet's take a look at number 7, understand AppSec SLOs, SLAs, and MBOs.

32:28Sean VargaYeah. So one of the things that I picked up over the last couple years is, especially because I've been in the scanning space for the last couple years, is understanding, you know, what are your service level objectives? Are you fixing criticals in 15 days, 30 days? What have you agreed to? Because One of those living document questions is, Mr. and Mrs. Customer, have you come to agreement with your CIO, CTO, at least on your P1 apps? When are you going to fix a particular critical high severity vulnerability? Right? It tells you a lot on if the SLOs are created and agreed on, or maybe they're not there yet, which is completely fine because AppSec is still very new to a lot of organizations, but that's ultimately what you're aligning to. And it's very telling both ways if one exists or if one doesn't exist already. If one doesn't exist, then you have to go out and say, I'm so excited that you're looking at our AppSec testing tool today, at our application security solution. We have to get The head of DevOps, the CIO, CTO, all those that own application development, we gotta get on the same page. And what's gonna be the SLO? What are we gonna agree to? What are you gonna fix?

33:50Robert HurlbutRight?

33:51Sean VargaBecause the solution can be the best solution in the world with no false positives, the most prioritization, and, you know, built into everybody's developer processes. But if the devs haven't been told by their leaders when they should fix, then nothing matters. Um, so it's really critical to dig into that. And then the other thing is MBOs, right? Managed by objective. How are AppSec people Mm-hmm. gold, right? What are they driving towards? Because you might have some shiny, shiny solution that could fix a lot of their problems, but if you aren't aligned to what they're being managed on, you know, what their goal is, hey, I need to remove all critical secrets by the end of the year. Um, or put in a pre-commit hook to block secrets from ever getting into E SCM. Um, you have to just be aligned to it because obviously they'll be driving to what their goals are. I mean, I have goals, everybody has goals, and that's what matters a lot.

34:46Chris RomeoMm-hmm. Let's, uh, we can jump over the understand all stakeholders. I think we talked about that in the context of the living document. Um, but I'm talking about participate in security community. This is not something that I normally hear AEs pushing. is the need to participate in security communities. So what's the value that's, that's created there?

35:06Sean VargaYeah, so I'm definitely a broken record on Secure Code Warrior. I just had such a wonderful experience there, uh, when I was there years ago, uh, for 4 years. And again, just listening to the success before, uh, one of the co-founders, Jap, an amazing human being, said, because Secure Code Warrior was an Australian-based company, we just went to OWASP chapters and ran secure coding tournaments. People loved the experience and they reached out and said, we need this for our environment, right? And so that's when I started to get the OWASP chapters and I hear about DevOps Days and BSides, and there's so many other wonderful security groups out there that, you know, outside of those that I mentioned, they tend to be a little bit more network security, GRC, other things outside of application security. But I did a, a, um, a presentation earli— earlier for, for SciCo at our last QBR. We called it Grassroots and talking about the importance of outreach to your communities and being part of it and interacting in it. And when I was doing some Googling and, and trying to figure out how to talk about this, when something's very hard in life, it tends to create communities. So AppSec, my contention is because it's so hard, that's why there's these really lively security groups tailored to that world. OWASP, which is OG, been around forever. There's DevOps Days, BSides. And so that's where your practitioners are, you know, go, don't be a boisterous vendor that's trying to do demos. That's, that's completely against, you know, everything that they stand for. But just go and start to listen, see what people are talking about, learn, meet people in your community, and, um, just be involved. And it's a great way to, you know, meet those that might be able to benefit from your solution. And that's the wonderful thing about, you know, AppSec is so hard, right? It's not, Uh, like cloud security, find an open port, close a port, or network security. It's, it's very involved and you just have to, you have to live it. Somebody told me at RSA in my early days is, um, Sean, you just have to decide to be fully committed to what you're doing to be successful. And at the time, as an idiot 21-year-old, that wasn't necessarily all focused on work. It didn't hit me then, but it resonated years later. I'm like, oh, you have to be fully committed. Um, and that's, and that's why I think it's really important.

37:51Chris RomeoYeah, it's definitely important to be a part of the community because running an OWASP chapter for a number of years, there was a, there was a pattern of like, you know, folks that were AEs that'd kind of come in for one meeting and then you'd never see them again. But they'd also make the rounds around, hey, you know, I'm so-and-so from, this is my company, here's my business card. Like, that's not how you'd be successful in the community as a salesperson. Being successful means becoming part of the community. So you're at the events for a period of time and people get to know you. And then who knows, somebody might have a question about the technology that you have. If you only show up for one night, they're more than likely going to not engage with you and talk about the things that you're doing in your company. But if you become part of that community where you're there for a period of time and now you're just another member of the community, it's just a different relationship. And I've seen it happen a number of times.

38:50Sean VargaExactly. No, I couldn't agree more. So no, it's been awesome. And there's so much fun, right? When I, pre-COVID, when I was running Secure Code Warriors, Tournaments at different OWASP chapters across the eastern U.S. It was just so much fun, and I saw the power, the value to. We ran one. You know, shout out to Laura Diener, the CISO now at DTCC. She was a CISO at the time at S&P Global, and we wanted to run a OWASP tournament at OWASP New York City, and we needed a venue. And at the time, I was talking to S&P Global, and I was like, "Hey." You have this wonderful office. I assume you have office space. Would you host OWASP New York and do this event? And she's like, yeah, that's the biggest no-brainer in the world. I support the community that matters a lot to me and it's recruiting. I get to pull in a bunch of practitioners into, you know, the world of S&P that I love and, and that's the value of it. So I think that's one of the key points to foster in, in these groups. So, um, it's a big deal.

39:56Robert HurlbutSort of wrap up the list. You have number 10, partners crossing the chasm.

40:03Sean VargaYeah. So partners are extremely important. And if you've ever seen my LinkedIn posts, I cannot spell. I need to like super Spell checks. I don't know if that's the right way to spell chasm, but I don't know if anybody out there has read the book Crossing the Chasm, but it talks about the concept of, you know, early adopters and innovators, and then there's laggards and things of that nature. And so when you're looking at a cohort of buyers in any market, those that are innovators and early adopters, they're mostly likely gonna find you. They're they're searching somebody out. Hey, I've got this issue. I'm gonna Google. I'm I'm I don't care about taking on a new vendor that might not be you know a giant size company. But if they're good people doing work that having with a solution that works, I'm okay with reaching out to them. There's a huge chunk of the market, and it's nothing against them that say, you know, I need a Robert. I need a Chris. to lean on as a third party, as a partner to help me. I, you know, I've got AppSec issues or I found it, like I talked to a company recently, um, that's in the concrete business that the CIO's like, Sean, I have like 300 developers. I have no idea where they came from. You know, it's, it's, everybody's got developers today, right? And Partners are such a great way to get an all-encompassing trustworthy approach to like, how do I dress this layer? Right? So it's really, really important. I can only reach out to myself and cold outreach and community outreach to maybe 50% of the market. It's probably being generous. The rest of the market is talking to the Guidepoint Securities, the WWTs, Optives, the Trace3s, the Heads, you know, the companies, you know, go on and on. And all of those companies I mentioned, they all have amazing AppSec consultant practices. You know, we were lucky at Psycode to bring in Jimmy Zhu, who ran Trace3's global AppSec, APIsec, CloudSec practice for a bunch of years. And Having, really earning the trust of these AppSec consultants is so important. I just was talking to, um, one of the partners a couple hours be— before this podcast, and they were giving the background of why they were able to introduce us to this major company. And they're like, oh yeah, our head of, uh, AppSec, thoroughly tested you and is blown away by its results. And that is so critical that not only that you deal with partners because they're in the ear of people that you want to work with, but it's specifically working with those app, those app psych leaders, because the sales reps at partners that I mentioned, they are so busy. And particularly right now, they're getting texted by every person in the world. And they quite honestly, everybody can buy CrowdStrike. You have a library, you could probably find a use for CrowdStrike, right? Not everybody has a sophisticated SDLC where they're thinking about how do I start commenting on PRs and doing pre-commit hooks and everything else. And so they're going to be very close to the vendors that they can sell at any company, no matter if it's a dentist chain or GPMC. And the way you really get into these partners is proving your technology to these AppSec leaders. So for an AppSec salesperson, right, a vendor to be successful, he can't just be a lone wolf. I'm going to cold outreach and I don't need other people's help. You need the help. And we brace that and we brace it here at Cyco, which is awesome. But Yeah, partners are just critical and I love them, right? They're really, really interesting, good, very experienced practitioners.

44:22Robert HurlbutAll right.

44:24Chris RomeoWell, I'm going to give you a second to think about your key takeaway because I'm going to share mine first, which I don't normally do. But I think it's important because we're primarily addressing an AppSec audience, the people that listen to this podcast. And so, The key takeaway that I want to share with our audience here is that, you know, salespeople are people too. They have families, they have children, they're real people behind the scenes. And, you know, it's, you don't have to, we don't have to live in the days of old where salespeople are our opposition. Sean took us through a number of different scenarios of the living document and thinking about the success of the customer, understanding the goals and the, you know, service level optimizations and and SLAs and all these things. And so that's my key takeaway that I knew that already, but I'm sharing it for our audience's sake just to put it out there because, you know, these are salespeople are real people too. If you don't need their solution and somebody happens to reach out to you, just tell them, go away, leave me alone. They'll leave you alone. They're smart in that way. But John, how about you? What's your key takeaway that you want to leave the audience with?

45:32Sean VargaFor me, it's Wow. Yeah, just embrace the community. I think is the biggest thing is, you know, live your truth. First of all, in life is you got to understand what motivates you, right? And once you understand what motivates you and where your happy place is, is then dive in, right? AppSec, I love AppSec. I could never be a dentist. I couldn't wake up every day and just do 5 sets of cavities every day. Like this is the same thing. I would lose my mind.

46:07Chris RomeoYou know, that's half a Mercedes. You just described half a Mercedes-Benz right there. You do 5 cavities, but I'm okay. I'm joking.

46:15Robert HurlbutRight.

46:16Sean VargaAnd AppSec, every day is a new day. It's a new challenge. You never know what's going to happen and it just works your brain. It's critical thinking. And so I would say for those that Enjoy AppSec. Just lean into it. Enjoy it. You know, understand each day is going to be a challenge and be prepared for it and plan for the worst and hope for the best.

46:40Robert HurlbutAwesome.

46:41Chris RomeoWell, Sean, thanks for sharing the OWASP Top 10 for AppSec sales. I think it's been very valuable for folks who are primarily not going to be sales folks, but they get a perspective about, you you know, what are, what are good sales folks doing from a process perspective? And they'll be able to, to detect when somebody really has their best interests in mind now that they have this perspective. So thanks for sharing that with the audience. And we just appreciate having you on as a guest.

47:08Sean VargaNo, it's been wonderful.

47:10Robert HurlbutIt's been an honor.

47:11Sean VargaSo this is, this is great.

More like this