Andrew Plato https://andrewplato.com/ Fri, 29 May 2026 03:15:56 +0000 en-US hourly 1 https://wordpress.org/?v=7.1 https://andrewplato.com/wp-content/uploads/2024/07/AP-icon-futura-150x150.webp Andrew Plato https://andrewplato.com/ 32 32 Fundamentals of Startup Sales https://andrewplato.com/fundamentals-of-startup-sales/ https://andrewplato.com/fundamentals-of-startup-sales/#respond Wed, 15 Apr 2026 22:50:48 +0000 https://andrewplato.com/?p=29777 Startup sales are rough. These fundamental sales concepts can help you take control and start closing more deals.

The post Fundamentals of Startup Sales appeared first on Andrew Plato.

]]>
I gained my sales education the hard way: I lost deals. I lost a lot of deals. This was usually because I talked too much and sounded desperate. After years of losing, I knew something needed to change. Then I had an insightful conversation with a fellow founder. He had recently exited his startup with a big payout. He said something that stuck with me, “the best sales meetings I ever had was the ones where I said nothing. Sales is about people, not products.”

With that insight in mind, I made some changes. Rather than talking, I listened. Rather than hoping for the sale, I planned for it. Rather than playing a game with the odds against me, I started changing the game, so the odds were at least even. In time, I was winning more deals than I was losing. Along the way, I accumulated a set of concepts and best practices for startup sales. Let’s walk through this list, with my favorite one at the end.

NOTE: This blog is an excerpt from The Founder’s User Manual: Practical Strategies for the Startup Leader

You Sell Pain Relief

You may think you sell products and services, but that is not what people buy. They buy pain relief. All your sales messaging must focus on this simple idea. Talk about the problems (pain points) your customers experience and how you resolve them. (I talk a lot about this in my upcoming book, Credibility Sales.)

Something Free Has No Value

Avoid giving away your company’s expertise, products, or time. Bundling free items into a paid package of products is okay. You can also do free trials. However, all of these must end with the customer paying for your products.

Furthermore, customers who demand free items do not value you. Anybody who tells you they will provide you with “exposure” in exchange for products or services is trying to cheat you.

The goal of sales is to bring in revenue. Giving away stuff is the opposite of sales.

Desperation is Repulsive

Desperation repulses good prospects and attracts bad ones. Suppress all signs of desperation, even if you really are desperate. Effective salespeople remain positive and enthusiastic during the darkest of times.

Never Waste a Loss

Salespeople are experts at inventing excuses for why a deal was lost. Avoid speculation and get the facts. Ask prospects why they chose a different product. Most people will tell you.

Understanding why you failed is more important to success than success itself.

Measure Results, Not Activity

In sales, results are all that matter. If a salesperson calls a thousand people, but sells nothing, that effort is meaningless. Monitor activity, but only measure results.

You want to track activity for analysis purposes to determine what level of effort is necessary to achieve the results you want. However, a salesperson’s incentives should never be based exclusively on activity (effort). Incentivize results.

Salespeople will constantly try to convince you that their activity is valiant and worthy of praise. Do not praise or reward people who are unable to deliver results. Instead, have them reflect on their efforts and find ways to change and improve. Activity (effort) that does not lead to results is meaningless busywork.

Salespeople who do not produce results are not merely useless, they also drag down the company. Sales is not a job for timid people. Do not retain salespeople who are not producing results.

You Cannot Sell in the Dark

No part of sales should be hidden, secret, or known only to a few people. Your processes, practices, metrics, and results must all be open, transparent, and public. Never allow your sales team to function “behind closed doors.”

Specifically, all sales goals and accomplishments must be made public. This creates pressure to perform. Weak salespeople will often complain that making sales attainment metrics public is “demotivating.” Low sales numbers should motivate salespeople to work harder. If it demotivates them, then maybe sales is not the ideal profession for them.

Hope is for the Holidays

In sales, hope is dangerous.

Salespeople would routinely tell me how they “hoped to hear from the prospect,” or similar excuses. You cannot run a business on hope. When a person is hoping, they are delegating success to fate. This allows them to dodge responsibility. Require people to have plans, not hopes. Do not even allow people to use the word hope.

No Badmouthing

Nothing telegraphs to the world your desperation, immaturity as a leader, and lack of strategy more clearly than allowing anybody in your company to badmouth competitors. As my CEO coach once said to me, “Are you in the ‘anti-them business’ or the ‘pro-you business?’”

Always be in the pro-you business.

Get to “No” Quickly

Dragging out a sales cycle for months wastes time and resources. Stress-test your prospects early in the sales process to ensure they have the budget and authority to make a sale.

Call the Bluff

One way you can get to “no” quickly is to do the opposite of what your prospect expects and call their bluff. I used this technique regularly. It is counterintuitive but astonishingly effective.

When a prospect raises an objection about your product, rather than countering their objection, agree with them. Tell them they are right and that maybe it is not a good fit. This will either cause the prospect to back down from their objection, which is good, or end the discussion.

For example:

Prospect: We require a vendor that is open 24 hours a day.

Seller: Okay. Our company is not there yet. I guess we are not a good fit for you.

Prospect: Well, that is not a deal breaker. Can you provide a dedicated support person?

Seller: Yes.

Calling the bluff (which is also called Negative Reverse Selling technique) forces the prospect to reconsider their position. If they want to work with you, they will back down from their objection. This makes the prospect convince themselves you are a good vendor.

Moreover, it encourages the prospect to negotiate and discuss other options with you. This gives you deeper insight into what the prospect really wants.

Calling someone’s bluff is difficult to do. You must resist the desire to counter objections. Moreover, you must be willing to walk away if the prospect agrees.

Calling the Bluff has multiple applications. You can also use it with a prospect who keeps putting you off or rescheduling meetings. Tell them it is obvious they are not ready for a meeting and to contact you when they are ready. This changes the dynamic and gives control to the prospect.

The Early Bird Gets the Sale

Once you have a possible prospect, get a proposal (price quote, etc.). in front of them quickly (within 24-48 hours). Without a proposal, you have nothing to sell. Moreover, invest in proposal designs and layouts that are concise and attractive.

Moving quickly shows a prospect that they are important, and you are reliable.

The Time is Now

Do not wait to contact a prospect. Do not wait to send out a quote. Do not wait. Do it now, so you can move on to the next task. Momentum begets results. Keep moving and do it now.

If It is Not in Salesforce, It Did Not Happen

Regardless of which CRM tool you use, require salespeople to enter their contacts and sales notes. I had salespeople constantly try to convince me of the important meetings or conversations they had. I would check Salesforce (the CRM we used) and they had not entered anything. I would say, “sorry, it did not happen.” Naturally, this infuriated them. I would remind them that, without documenting their engagements, I had no way to determine that they were real.

This underscores the importance of the next item on this list.

No Verbal Agreements

Never allow your employees, customers, or partners to use your own memory against you. Talk is cheap. Documentation is forever. Require all agreements, regardless of size or complexity, to be in writing.

Do Not Negotiate Against Yourself

When a customer pushes back on some aspect of a deal, resist the urge to immediately engage and negotiate. Ask the prospect for a counterproposal. Otherwise, you are negotiating against yourself.

Also, do not be afraid to walk away. This may compel the prospect to re-engage and become more agreeable to your proposal.

Ask for the Sale

Ask for payment as well. Salespeople should never feel awkward about asking a prospect to buy and pay. Closing the deal and getting paid is the entire point of sales. Salespeople who are uncomfortable asking for money should not be in the sales profession.

No Signature, No Deal

I had prospects swear up and down they were going to buy, but they could not sign a quote. I fell for this a few times and got screwed each time when the customer would not pay.

Get them to sign that is dotted. Otherwise, walk away. Without a signature, you have nothing.

Sell the Brighter Future

Focus on how your products and services will help the customer. Everybody wants to buy a brighter future.

Sell Your Way Out

When money is tight and things look bad, there is only one way out of the hole: sell your way out. Stop whining, blaming, and avoiding reality. Get out there and book meetings, do demos, and push for sales. I once turned my company from being $1M in the hole, to $750K cash positive in about 90 days. It absolutely sucked and I had to work 15 hour days, but what choice did I have? There is a limit to what you can cut, but no limit to how much you can sell.

Change the Conditions of the Test

As a startup, the odds are against you in almost every way. Your competitors have every advantage: money, time, talent, brand recognition, etc. If you look and sound exactly like your competitors, buyers have no reason to select you. They are better off sticking with an established brand. Moreover, you cannot claim to be an innovative, disruptive startup when you look like everybody else.

The only way you can start winning this game is to Change the Conditions of the Test and even up the odds. That means intentionally sounding, looking, and feeling different from your competitors. Different is good. Different closes deals. Different is your only way to stop playing your competitor’s game and make them play your game.

However, a word of warning, many of the people around you, especially investors, board members, and employees, will fight you on this. Prove them wrong.

Conclusion

You know what it takes to do startup sales? It is not made of brass. It is intelligence, discipline, and resolve. Follow these fundamentals to get your sales team on target.

Always be closing.

The post Fundamentals of Startup Sales appeared first on Andrew Plato.

]]>
https://andrewplato.com/fundamentals-of-startup-sales/feed/ 0
Overcome Buyer Skepticism with a Smart Go-to-Market Strategy https://andrewplato.com/overcome-buyer-skepticism-with-a-smart-go-to-market-strategy/ https://andrewplato.com/overcome-buyer-skepticism-with-a-smart-go-to-market-strategy/#respond Mon, 23 Feb 2026 06:34:42 +0000 https://andrewplato.com/?p=29770 The Power of Curiosity Way back in 2011, I was wandering through a trade show, numb from the identical sales pitches.  Then I saw a booth advertising the “Next Generation Firewall.”  What the heck was that? As a cybersecurity geek, I had to find out more. I trotted over to the booth, which was hopping […]

The post Overcome Buyer Skepticism with a Smart Go-to-Market Strategy appeared first on Andrew Plato.

]]>
The Power of Curiosity

Way back in 2011, I was wandering through a trade show, numb from the identical sales pitches.  Then I saw a booth advertising the “Next Generation Firewall.”  What the heck was that? As a cybersecurity geek, I had to find out more.

I trotted over to the booth, which was hopping with excitement and activity.  I listened to a passionate and absorbing presentation from the company’s founder.  This was the coolest thing to come along in cybersecurity in years.  The company was a startup, named Palo Alto Networks (PAN).  PAN is one of the largest cybersecurity companies in the world today.

While PAN’s technologies did not live up to the hype, their messaging was spectacular.  The concept of a “next generation” security technology was catnip to buyers desperate for something that could stop attacks.  This messaging was so effective, buyers were rushing to buy their products, infuriating PAN’s larger, more established competitors.

The Wall of Buyer Skepticism

When companies (especially startups) bring a new product (or service) to market, they face an imposing set of disadvantages. A lack of people, money, reputation, and customers all conspire to keep paying customers away.  However, the most insidious obstacle is Buyer Skepticism.  As a startup, you are nobody.  Prospective buyers have no reason to trust you.  Why take a chance on a startup when there are larger, more established providers?

Consequently, any startup GTM strategy must address how the company will overcome buyer skepticism.  This was exactly the conundrum PAN faced in their early days.  Their solution was to sneak right past the wall, exploiting one of the most potent human weaknesses: curiosity.

Evaluating a Product

When buyers evaluate a company and its products, they will consider a wide variety of factors.  However, we can simplify these factors into four categories (which conveniently begin with the letter “c”):

  • Credibility: Is the company trustworthy? Does it have references?  Do the people at the company sound and look like they know what they are doing?
  • Capability: Does the company’s products work? Do they integrate with other technologies?  Do they relieve pain?  Can the company prove that?
  • Capacity: Is the company able to deliver what they say? Do they have the people, relationships, and network to function?
  • Cost: Are the prices and terms reasonable? Does the company have the financial resources to delivery capability and capacity.

When a company succeeds in all four areas, they usually make the sale.

Most startups and founders focus their energy on building capability and capacity, which makes sense.  Without a product or service everything else is moot.

However, once the product is working and the company is ready to sign up customers, it is critical to start building credibility.

Established competitors already have credibility.  This is why buyers feel more comfortable buying a mediocre product from a trusted brand versus an innovative product from an untrusted company.  Credibility allows a company to pass over the Wall of Skepticism.

Using Curiosity to Build Credibility

Building credibility is exceptionally difficult, unless a startup can overcome Buyer Skepticism.  This is where curiosity becomes your superweapon.

Define a vision, that creates curiosity, follow up with credibility, then close the deal.

  1. Define a strong vision for your products and services
  2. Pique curiosity with enticing words and ideas
  3. Reassure the prospect with expertise and empathy
  4. Close the deal

Let’s step through this strategy.

Define a Vision

Why?  This is the ultimate question all startups must answer about themselves and their products.

  • Why you?
  • Why your product?
  • Why are you better than what is already out there?
  • Why not your better funded, more established competitors?
  • Why now?
  • Why are you doing this?

As the marketing guru Simon Sinek says, “people don’t buy what you do, they buy why you do it.”  To make buyers curious, you must know why you are interesting.

Consider Disney’s vision statement: “to make people happy.”  That is a simple, strong answer to why: “Why does Disney exist? To make people happy.”  Although, considering the last Star Wars movie, their success in meeting that vision is debatable.

Exploring these why questions helps a startup understand why they are unique.

Action Plan for Building Vision

  1. Get your key team members or advisors together
  2. Find compelling, concise answers to those questions asked earlier
  3. Document those answers
  4. Ensure everybody in the company can repeat those answers with conviction

Be careful with your answers.  Keep them concise and focused on customers, not yourself or your investors.

Pique Curiosity

Modern buyers are overloaded with options, sales pitches, and marketing content.  After a while, all the marketing content sounds the same.

Curiosity is both a strength and weakness.  While curiosity can make people seek out answers to vexing problems, it can also make them lower their defenses.  This is why hackers use enticing emails to convince people to click on malware.  Curiosity makes people click.

Startups can exploit curiosity to sneak into a buyer’s mind and past the Wall of Skepticism.  The buyer must see or hear a word, phrase, artwork, or design that instantly makes them think, “What is that?” or “I want to know more about that!”

To accomplish this, a startup must sound intentionally different and unique.  PAN used the phrase “next-generation,” Nike invented the phrase “Just Do It,” and Apple was “Think Different.”  All of these were unique phrases that made people want to know more about the brand.  You do not want to reveal your entire vision, merely tease it.

Action Plan to Create Curiosity

  1. What is a word, phrase, or idea you can use that makes people curious?
  2. Do those words reflect the company’s vision?
  3. How can you deliver those concepts effectively?

Be careful that your words do not create confusion.  Using obscure, obscene, or outlandish phrases may seem funny, but they may repel buyers.

Demonstrate Credibility

Once a curious buyer approaches, you must quickly demonstrate credibility.  This means rapidly accomplishing two things:

  • Show you understand the customer’s pain
  • Show that you can alleviate that pain

Only a person with extensive domain expertise can do this.  Consequently, startups must place intelligent, experienced people “upfront” to engage with potential buyers early in the sales process.  These “pre-sales” experts must be able to start and maintain engaging conversations with prospective buyers.  Mostly, they must be able to reassure the customer they are capable and credible.

Pre-sales experts are the single most important component of any go-to-market strategy.  It is a perfect role for a founder, which is exactly what PAN did back in 2011.  They deployed their founder Nir Zuk into the booth to talk directly with prospective buyers.  Zuk is a brilliant and passionate engineer, who can instantly create credibility.  Zuk continues to play a key role in evangelizing PANs products to this day.

Curiosity followed with credibility supercharges your GTM efforts.

Action Plan for Intelligence Upfront

  1. Ensure the first meeting with all potential customers includes a subject matter expert
  2. Ensure these experts:
    1. Communicate the company’s messaging and vision
    2. Show the customer they understand their pain
    3. Demonstrate their ability to alleviate that pain

For more information about building rapport with customers, see How to Get Sales Prospects to Discuss Pain.

Close the Deal

Once the Wall of Skepticism is down and credibility is established, it is all downhill from there.  The final stage is to pivot to a product pitch, reassure the buyer you can solve their problems, and close the deal.

In this final phase, be careful not to destroy the credibility you built.  You want to sound confident, not desperate.  Desperation is repulsive to buyers.  Allow the buyer to drive the product demonstration.  Let them explore the capabilities.  Show confidence in your products, even if they are not perfect.

Once this stage is complete, you should be sending a quote or proposal to the customer, ready to close the deal.

Conclusion

Buyer skepticism is a massive impediment for startups entering the market.  Spending millions on far-reaching marketing campaigns to reach potential buyers may feel like the right thing to do, however it rarely works.  Most buyers are not going to take a small startup seriously, regardless of how many emails you send them.

Conversely, unique, targeted messaging is relatively inexpensive to produce and disseminate and, if done correctly, can be significantly more effective.  This will attract curious buyers, which is exactly what a startup wants.  Curious buyers are open to hearing an innovative, disruptive new approach.  Skeptical buyers are not.

Palo Alto Networks was not the first company to use these GTM strategies.  Many successful companies have employed these techniques.  Curiosity is potent.  If you can make prospective buyers curious and then build credibility, you may see the same explosive growth.

What do you think?  Share your feedback: andrew.plato@zenaciti.com.  If you are looking to develop a creative GTM strategy, let’s chat.  Zenaciti can help.

The post Overcome Buyer Skepticism with a Smart Go-to-Market Strategy appeared first on Andrew Plato.

]]>
https://andrewplato.com/overcome-buyer-skepticism-with-a-smart-go-to-market-strategy/feed/ 0
How to Write an Effective Sales Compensation Plan https://andrewplato.com/how-to-write-an-effective-sales-compensation-plan/ https://andrewplato.com/how-to-write-an-effective-sales-compensation-plan/#respond Mon, 23 Feb 2026 06:22:54 +0000 https://andrewplato.com/?p=29765 Sales compensation plans (comp plan) are more than a formula for commissions. They are an integral element of your sales team’s success. An effective comp plan will drive success and revenue. A bad plan will drive everybody crazy. I spent over 25 years analyzing, writing, and optimizing comp plans. Along the way, I picked up […]

The post How to Write an Effective Sales Compensation Plan appeared first on Andrew Plato.

]]>
Sales compensation plans (comp plan) are more than a formula for commissions. They are an integral element of your sales team’s success. An effective comp plan will drive success and revenue. A bad plan will drive everybody crazy.

I spent over 25 years analyzing, writing, and optimizing comp plans. Along the way, I picked up a lot of best practices. Let’s explore these and how you can write an effective sales comp plan.

NOTE: this blog uses the word incentive to refer generically to both commissions and/or bonuses.

Comp Plan Types

There are many different kinds of sales jobs and therefore different incentive structures. The most common comp plans include:

    • Salary + Commission: salesperson is paid a base salary and earns commissions on each deal. Most account executives have this kind of plan.
    • Commission-only: salesperson is paid only commissions, no salary. These may include a draw on future commissions.
    • Salary + Bonus: salesperson is paid a base salary and earns bonuses on meeting specific sales goals. Sales engineers and customer success roles often have this kind of plan.
    • Territory / Team Volume: salesperson is paid a base salary plus commissions based on the performance of an entire team or territory. Most sales managers have this kind of plan.

While these plans may have different ways to compute incentives, they share a common set of components. Let’s take a look at those elements and how they build a reliable incentive structure.

Comp Plan Elements

There are five critical elements to a comp plan:

    1. Opportunity Types
    1. Incentive Basis
    1. Incentive Rate
    1. Accelerators
    1. Payout Process

Let’s examine each of these and why they are important.

1. Opportunity Type

Not all customers are the same. Some deals are more difficult to close, and some customers are more desirable. Opportunity Types provide a way to differentiate, categorize, and scale incentives appropriately to the desirability and complexity of each customer type.

For example, let’s say your company wants to break into the healthcare industry. Using opportunity types, you can create a category named “Target Accounts.” Then provide each salesperson with a list of healthcare companies. Any deal a salesperson closes with an account on the list receives an increased incentive payment. This encourages the sales team to focus their efforts on these target accounts, thus driving the business you want.

Ideally, your plan should have three to five opportunity types. Too many types and your plan will become convoluted and difficult to enforce.

Here is a suggested structure:

[table id=1 /] The definition of each type is important. If there is confusion about what constitutes each type, this may lead to arguments and disillusioned salespeople.

2. Incentive Basis

This is the starting value to compute an incentive payment. For many companies, this is the gross profit (GP) on a deal. For example, a salesperson closes a deal classified as organic for $50,000 and it has $15,000 in costs. The incentive basis (GP) would be $35,000.  Based on the opportunity types listed in the previous section, the commission would be 10% of $35,000 or $3,500.

The key to incentive basis is an ultra-clear definition. A good comp plan never creates ambiguous incentive calculations. Therefore, when you write your plan, make sure to precisely explain how you compute incentive basis. If direct costs are included, but not indirect ones, then you need to describe what constitutes a direct cost. Always provide examples, to ensure there are no misunderstandings.

3. Incentive Rate

This is how much the salesperson earns on a sale. Typically, this is expressed as a percentage of the incentive basis value and scaled to each opportunity type. Percentages are always preferable as they scale up and down based on the size of the deal. Fixed commission payments are only effective when you want to reward specific, non-income-generating accomplishments, such as setting up meetings.

Be careful with incentive rates. They need to be high enough to motivate results, but not so high they hurt your overall profitability.  Moreover, you may need to alter the rates based on margin. Low margin sales will naturally create smaller incentives. This may discourage salespeople from selling low-margin items.

4. Accelerators

Accelerators reward salespeople with additional compensation when they exceed quota.  For example, if a salesperson hit 125% of quota for a quarter, their incentive rate could go up 1%, increasing all their incentive payments.

Here is a suggested quarterly accelerator schedule: [table id=2 /]

Accelerators can have a huge impact on a salesperson’s income and motivation. However, if the accelerators are too aggressive, they might hurt profitability.

Work with your finance manager or bookkeeper to run financial models on different accelerator structures based on historical values. You may need to implement flat-rate accelerators or limit the total amount that can be paid.

5. Payout Process

For sales incentives to work effectively, salespeople must be able to quickly and reliably compute their incentive payments. Documenting the exact process the company follows to pay incentives reassures salespeople they will get paid.

Documenting the process also creates consistency and a check-and-balance process. Here are suggested steps for a payout process:

    1. Sales manager submits incentive payout request to Controller (bookkeeper, CFO, finance team member, etc.) This request details each deal closed as well as the expected incentive payment.
    1. Controller reviews and validates the requests are correct and eligible to be paid. Controller works with sales manger to make any corrections or adjustments.
    1. Controller obtains approval to pay incentives from CEO (COO, etc.)
    1. Controller returns payout request to Sales Manager indicating which incentives are approved to be paid in the next payroll cycle.
    1. Sales Manager communicates this approval to appropriate salesperson.
    1. Controller processes incentive payments in payroll

Additional Guidelines

Ultra Precise Language

Among all the challenges of developing a comp plan, the most insidious is the words themselves. The language of a comp plan must be simultaneously extremely precise and easy to read. One confusing word or ambiguous definition could land you in court with an angry employee demanding more compensation than you intended.

Consider these two examples:

BAD: Account executives (AE) earn 10% commission on gross profit for all consulting sales.

BETTER: Account executives are eligible to earn 10% incentive based on the gross profit of deals the AE was assigned and closed.

The first item is too vague and lacks key qualifiers. An employee could interpret this as they earn 10% on all sales, regardless of whether they closed the deal or not.

The second item uses some important qualifiers. For example, rather than “earning” a commission, the salesperson is merely “eligible.” This gives you more room to control what is or is not a legitimate commission. Moreover, the word “commission” is replaced with “incentive.” Commission is a loaded word with a specific, legal meaning. Incentive is more generic, giving you more freedom to define what an incentive is (or is not).

If you are not familiar with writing a comp plan, hire an expert (like me) or use well-vetted template. Furthermore, have your legal counsel review the plan to ensure it is defensible in court or arbitration.

Different Plans for Different Roles

One comp plan does not fit all. Depending on the sales roles you have, you will likely need as many as five different plans. For example, the most common roles are:

    1. Business Development Representatives (BDR): work on in-bound leads, set appoints, and so forth.
    1. Hunters / Account Executives: actively work to drive new business.
    1. Farmers / Account Managers: manage existing customers
    1. Subject Matter Experts / Sales Engineers: provide subject matter expertise to close deals
    1. Managers: oversee the team, set quotas, etc.

Each of these jobs is different and likewise must be compensated differently. For example, closing new business is more difficult than managing existing customers. Use the same plan template, but alter the Opportunity Types, Basis, and Rates to match the relevant effort for each role.

Reward Results, Not Effort

I spent countless sales meetings listening to struggling salespeople complaining about the effort they were pouring into sales. While I empathized with their struggle, effort without results is meaningless.

Comp plans must focus on rewarding the results of hard work, not the work itself. Moreover, do not reward “almost” results. Accelerators or bonuses should only kick in when quota is exceeded.

Everything Must Be Public

Finally, the entire sales process, comp plan, and quota attainment must be open and public to the entire company. This ensures that everybody in the company can trust the sales process and see overall performance. This also ensures the sales team is accountable to their quota.

Final Thoughts

An effective comp plan can supercharge your sales efforts and attract top talent. Most importantly, it rewards both the company and the salespeople. This is an important part of being a salesperson – the ability to make a lot of money when you are successful.

Skilled salespeople, armed with a good product, effective sales tools, and a generous well-defined comp plan equals a successful company.

Always be closing!

Need help with your comp plan? Contact Andrew to setup an introductory discussion. 

The post How to Write an Effective Sales Compensation Plan appeared first on Andrew Plato.

]]>
https://andrewplato.com/how-to-write-an-effective-sales-compensation-plan/feed/ 0
Leadership Hacks https://andrewplato.com/leadership-hacks/ https://andrewplato.com/leadership-hacks/#respond Fri, 11 Jul 2025 04:30:20 +0000 https://andrewplato.com/?p=29748 Running a company is a grind. Overwhelmed with the daily onslaught of problems, it is easy to fall back into bad leadership behaviors. I found that keeping leadership aphorisms (or hacks) around me would refocus me back to healthy leadership behaviors. Here are 15 I kept around me all the time. 1. You Get What […]

The post Leadership Hacks appeared first on Andrew Plato.

]]>
Running a company is a grind. Overwhelmed with the daily onslaught of problems, it is easy to fall back into bad leadership behaviors. I found that keeping leadership aphorisms (or hacks) around me would refocus me back to healthy leadership behaviors.

Here are 15 I kept around me all the time.

Plato's Leadership Hacks - 15 quick reminders to help you be the leader you want to be.

1. You Get What You Tolerate

If you tolerate bad behavior, you will get more of it. Shut down toxic people and do not allow the bad behaviors to continue.

2. Stay on Target

The more clearly you can define, describe, and quantify an expected outcome, the more likely you (and your team) will achieve it. Keep people focused on the goals, so they keep moving forward and do not become mired down in frustrations and mistakes.

3. Hope Is Not a Strategy

Unfortunately, the word “hope” has become weaponized in many organizations. Rather than defining a strategy, a plan, or a goal, people will hope everything works out the way they want it to. When things inevitably go wrong, they will treat the outcome as entirely out of their control.

When you hope for an outcome, you ceding control to fate. This makes employees passive participants in an effort, rather than active players.

To stop this, prohibit the use of the word hope in any work-related discussions. Require people to use the word plan or intend in place of hope. This reinforces the notion that they are responsible for the outcome and are expected to actively work for success.

Do not hope for success, plan for it.

4. Success is Born in Failure

Mistakes, errors, and failures will teach you more about how to be successful than any success will. You must aggressively analyze your failures and face what you did wrong.

This is especially true for sales. If you lose a deal, you must find out why you lost it.

5. Failing to Plan is Planning to Fail

People without a plan will take an entirely predictable failure and turn it into an entirely unnecessary emergency. You, your team, and your company must have a plan for – everything.

This is a frequent problem in product development. If you fail to precisely plan what the next version of a product will be, it is easy to keep pushing the deadlines out indefinitely.

6. Make It About Them

Employees will naturally direct their frustrations, failures, and fear on a leader. To counteract this, you must redirect conversations away from yourself and toward the employees and their work. Moreover, never vent your own frustrations to employees, as this only makes you sound petty and vindictive.

Make your team feel heard, needed, and important.

7. I Did Not Know What to Do, So I Did Nothing

When confronting a challenge is seldom a good idea to do nothing. Do not allow ignorance or lack of experience to stop you or your team from trying. Even a bad outcome is better than none. You can learn from a bad outcome, you learn nothing from doing nothing.

This is an example of an “intolerable” or the opposite of a core value. It is something you explicitly want to discourage in the company.

8. Do Not Take Advice from People Who Have Accomplished Nothing

Be wary of advice from people who have never been a founder or leader before (especially investors). Advice is plentiful and most of it is useless.

9. What Annoys You is Your Greatest Teacher

People or behaviors that annoy you provide a valuable window into your own personality. Look past the person and personalities and reflect on why you are annoyed. You may discover a lot about yourself.

I had a sales manager who drove me crazy. He was an inflexible, hard-charging, opportunist who did not know when to shut up. He annoyed me because his bad behaviors reflected some of my own bad behaviors. Learning how to manage him helped me manage my own behaviors.

10. Start With Why

This statement comes from Simon Sinek’s famous Start With Why video.

Before you jump into any large effort, make sure you and everybody else knows why you are doing it. As Sinek points out, organizations that can clearly define their purpose are consistently more successful.

11. When There Is Success, Look Out the Window; When There Is Failure, Look in the Mirror

This is a reminder to share success with your team. However, when there is a failure, reflect on your own behavior and actions. Take responsibility for failure and work to get better.

12. Questions Beat Answers

Rather than telling people what to do, ask them instead. Curiosity is a potent leadership tool. When you ask questions, you show interest in the other person’s ideas. This makes that person like you, and consequently more receptive to direction.

Asking questions also makes employees own the answers, reinforcing accountability. When you tell people what to do, then the solution belongs to you, which means employees are not responsible for the outcome.

Let them find the answers themselves.

13. Less is More

Intelligent, confident, and ambitious people are concise. They say what needs to be heard, and nothing more. The more you talk, the stupider you sound.

14. No Verbal Agreements

Bad employees will routinely try to gaslight leaders with decisions and agreements that never happened (or are substantially different). To avoid this, require all decisions or agreements to be in writing. This avoids misunderstandings and ensures accountability.

15. Perseverance Furthers

This was my father’s advice for most situations. He got it from the I Ching, an ancient Chinese book of proverbs. This simple concept carried me through a lot of dark times as a founder.

All your problems have a solution. You merely do not know the solution, yet. Persevere and the answers will emerge in time.

Conclusion

While these aphorisms do not solve all leadership challenges they can help. I hope…er…I plan for them to help you. 😊

This was originally published on Medium June 8, 2022.

The post Leadership Hacks appeared first on Andrew Plato.

]]>
https://andrewplato.com/leadership-hacks/feed/ 0
The Software Monoculture Is Here to Stay https://andrewplato.com/software-monoculture/ https://andrewplato.com/software-monoculture/#respond Sat, 27 Jul 2024 21:45:40 +0000 https://dev.zenaciti.com/?p=28642 The recent CrowdStrike debacle has reignited an old argument among IT and security people: what can be done about the software monoculture?

The post The Software Monoculture Is Here to Stay appeared first on Andrew Plato.

]]>
The recent Crowdstrike debacle has reignited an old argument among computer and security practitioners: should organizations do away with their software monoculture.

NOTE: I was recently quoted in a story for NPR’s Marketplace regarding this issue.

For clarity, a software monoculture is when an organization uses a small, standardized set of software, service providers, and/or hardware. The most obvious example is the dominance of Microsoft Windows on desktop and laptop computers. Software monocultures extend to security technologies as well, which is why the CrowdStrike outage was so widespread.

Like it or not, the software monoculture is here to stay. Standardized compute environments are preferred as they are easier to monitor, manage, and secure. The recent uproar over monoculture due to the CrowdStrike incident is a distraction. It avoids the real problem that organizations are unprepared for systemic outages and looking to blame somebody else for their problems.

Marge vs. the Monoculture*

In the early 2000s, my company was conducting a penetration test on a client. One of our scans crashed the customer’s network. After a tense 30 minutes, we got them back online. However, the CIO was enraged and demanded to know why we did this. When I explained that the firewall had a bug that made it crash when scanned, he persisted with his complaints. I reminded the CIO that discovering this kind of flaw is why you conduct penetration tests.

This incident was an opportunity to build resilience into the organization. However, this immature CIO was more interested in who he could blame for the outage rather than how to recover from it. Similarly, every time there is a large outage, social media fills with “thought-leaders” whining about how evil Microsoft is and that we need the government to intervene. The recent CrowdStrike debacle is no different.

Microsoft is not evil. CrowdStrike is not incompetent. Bugs like this are not indicative of some systemic failure. Mistakes happen. The mistake is not as important as how we react to it. Either you view an outage as an opportunity to improve or as an opportunity to blame.

Blaming others for the outage does nothing of value. It merely allows people to feel better about the situation. An outage should be seen as a chance to review response, recovery, and contingency plans. Organizations that had reliable plans breezed through the latest outage. Those that did not struggled to come back online.

More is Worse

Ultimately, monocultures are a net positive. A standardized, uniform, consistent environment is immensely easier to manage, monitor, and secure. This is not a new idea. Standardization has been a driving force in technology since the dawn of civilization. The entire Internet is built on standards. The benefits of a monoculture far outweigh the negatives.

This reminds me of another immature CIO I encountered. The CIO’s security team was struggling to operate their next-generation firewall (NGFW), resulting in numerous outages and security incidents. Consequently, the CIO wanted to purchase a competitive NGFW and run them both, believing that one could monitor the other. In a moment of brutal honesty, I replied: “You cannot effectively run one firewall; why do you think running two will be better?”

This CIO believed that the firewall (or monoculture) was the problem. He also believed that adding more technologies to the environment would compensate for this perceived weakness. Of course, the problem was him (and his team). They were blaming the technology for their own inexperience and ignorance. Unsurprisingly, the new firewall they installed caused additional problems and more outages.

Single Point of Fail

This CIO was consumed with preventing a “single point of failure.” The single point of failure issue is often applied to Microsoft Windows since a single flaw in Windows can lead to systemic outages. There is truth to this. However, it is not a justification for adding complexity to the environment. Making an environment more complex with a diverse set of technologies merely to avoid a possible single-point of failure only creates lots of points of failure. At least with a single point of failure you can identify, remediate, and recover more quickly.

When redundancy is necessary, it must extend to all dimensions of the environment. This is why containerization and cloud technologies are ideal for resilience. They have redundancy integrated into the platforms.

It does not make sense to spend millions building redundancy into a cloud architecture only to entrust its successful operation to a single overworked IT person or single piece of security software (like CrowdStrike). For redundancy to truly work, it must extend to all dimensions of the environment. This becomes an immensely expensive proposition, which makes it unreasonable for all but the largest organizations.

Every organization has single points of failure. They are unavoidable. It is useful to know where they are, but it is not always useful to mitigate them. Rather than implement complex redundant systems, have a robust set of contingency plans to rapidly recover in the event of an outage.

Overcoming Monoculture Anxiety

The CrowdStrike incident added a lot of stress and anxiety to already overworked IT teams.  It is natural to seek out ways to prevent the next incident.  However, the answer is not to deploy more technology (necessarily.)  CrowdStrike is an effective security control.  It is effective a lot more than it crashes.

A more reasoned response to this (or any other outage) would be:

  • Review your system backup and recovery processes. You should be able to restore any system, anywhere in your network to a previous state on a moment’s notice.
  • Consider technologies that provide rapid recovery. Microsoft has many of these embedded into the operating system.  There are plenty of third-party tools as well.
  • Have a contingency plan for effected workers. One suggestion is to quickly spin up cloud-workstations in AWS or Azure that employees can use to continue working.
  • Have a communications plan. When systems are offline, employees, customers, and partners need to know what is going on.  Have a way to contact everybody with a unified message.  This message should come from senior leadership (like the CEO).
  • Perform an annual “table top” exercises with your teams on how they would respond to an outage. This prepares people to handle the situation.
  • For mission critical systems, migrate them to containerized platforms that can automatically reset to a known good state. For security, consider moving target defense technologies.

Conclusion

Outages are inevitable. No amount of technology, people, or processes can overcome this. Rather than complain about Microsoft’s dominance, work on ensuring that when those Microsoft systems go down, they can be recovered and reset quickly. Microsoft already has integrated functions in Windows to support this. Moreover, numerous third-party companies provide rapid recovery software.

This most recent outage demonstrated clearly which organizations had dependable contingency plans. Those that did were up and running in a few hours. Those that did not spent time blaming others rather than fixing their problems.

The monoculture is here to stay. How we react to it can change.

* This is a reference to the Simpson’s episode, Marge vs. the Monorail.

The post The Software Monoculture Is Here to Stay appeared first on Andrew Plato.

]]>
https://andrewplato.com/software-monoculture/feed/ 0
What Is a Managed Security Service Provider (MSSP) https://andrewplato.com/what-is-a-mssp/ https://andrewplato.com/what-is-a-mssp/#respond Tue, 07 May 2024 05:32:03 +0000 https://dev.zenaciti.com/?p=3480 What are the components of a managed security service provider (MSSP)?

The post What Is a Managed Security Service Provider (MSSP) appeared first on Andrew Plato.

]]>
Years ago, I completed a large industry analysis project where I researched the managed security business.  At the time, MSSP was rapidly gaining traction with new providers sprouting up everywhere.  Fast forward seven years.  I am starting a new MSSP research project, and wondering what changed in the intervening years.

Surprisingly, not that much.

The most notable changes are the influence of cloud and AI technologies on MSSPs.  However, these factors have not altered the constituent parts of an MSSP.  

To understand what makes an MSSP, consider Gartner’s definition:

A managed security service provider (MSSP) provides outsourced monitoring and management of security devices and systems. Common services include managed firewall, intrusion detection, virtual private network, vulnerability scanning and anti-viral services. MSSPs use high-availability security operation centers (either from their own facilities or from other data center providers) to provide 24/7 services designed to reduce the number of operational security personnel an enterprise needs to hire, train and retain to maintain an acceptable security posture.

There is nothing wrong with this definition, but it describes what an MSSP does, not what they are.  There is a big difference between those two things.  If you are looking to hire (or build) an MSSP, you must evaluate not only what an MSSP can do, but what they are made of as well.  

Based on my research, an MSSP consists of four components:

  • Platform
  • People
  • Process
  • Scale

Let’s explore each of these components and how they contribute to an MSSP.  

Platform

This is the collection of technologies, tools, and products the MSSP uses to deliver their services.  Platform technologies may be developed in-house or sourced from third party vendors.  Many MSSPs use repurposed open-source products as their proprietary platforms.

An MSSP’s platform is important, but not as important as you may think.  Buyers do not, necessarily, select an MSSP because it offers an ultra-sophisticated platform (nor should they).  Rather, an MSSP’s platform is a “ticket to ride.”  When buyers evaluate MSSPs, they look at the platform first.  If it appears capable, then they move on to evaluate the other components.

The key components of an MSSP Platform include:

Component Description Commentary
Platform Technologies The component technologies of the platform. This can be a wide-range of proprietary and third-party products.
Infrastructure The architecture, hosting, and supportive components of the platform. This not only includes where the platform is hosted, but also infrastructure components such as authentication, connectivity, and redundancy.
Automation How the platform responds to incidents, implements remediations, and manages configurations. Automation allows an MSSP to react more quickly and consistently to incidents.  Highly automated platforms are fundamentally more effective at protecting an environment.

Automation capabilities may include some AI functions. However, be careful when evaluating any AI usage, since many MSSPs claim to have AI integrated into their platform, when in reality it is merely that their analysts are using AI to perform management functions.

Service Capability These are the services the platform delivers. Typical services include:
  • Firewall / NGFW
  • Endpoint security, XDR, MDR
  • Vulnerability scanning, penetration testing
  • Configuration / change management
  • Security information and event management (SIEM)
  • Incident handling
  • Compliance reporting
  • Threat intelligence and scoring
  • Email security
  • Security orchestration, automation, and remediation (SOAR)
Data Providence This refers to where and how the platform stores its data. How a platform stores customer data is critical, especially if there are any compliance requirements.  Many compliance frameworks (such as FedRAMP) do not allow any co-mingling of data with non-compliant environments.  MSSPs that co-mingle customer data are typically unable to meet compliance requirements.

Some MSSPs have taken to only storing meta-data, while leaving the raw log data contained within the customer environment.  This is preferrable, from a security perspective, but still will run afoul of some compliance regimens.

People

Even with automation and AI, MSSPs are completely dependent upon people to run everything and support customers.  The team that runs, manages, and monitors the platform are what makes an MSSP function.  Without them, there is no MSSP.

MSSP teams usually include analysts, support staff, engineers, and developers. 

Analysts are the primary service delivery people. They operate the platform, perform security scans, respond to incidents, and deliver reports.  Some MSSPs also employ analysts to perform adjacent professional services such as penetration testing or virtual CISO services.  Analysts form the backbone of an MSSP.

Support staff handle the logistics and customer management functions.  This team may include project managers, customer success representatives, and other non-technical people.  Effective MSSPs use the support team as a “buffer” to allow the analysts and engineers to focus on service delivery. 

Engineers operate the infrastructure for the platform. They may also serve as a second-tier support for analysts. Engineers typically operate in background, and only interact with the customers for more complex or bespoke needs, such as assisting with incident response.  

Developers design, built, and deploy the platform and relevant infrastructure components.  Some MSSPs do not differentiate between engineers and developers, and unite them into a common platform group.  Developers often have their own supporting staff of project managers and testing engineers.  

For buyers, it is difficult to assess the skillset of an MSSPs people.  You are not going to be able to meet many of the analysts and engineers working on your account.  However, you can assess the team that engages you in the sales process.  Savvy MSSPs place technical resources early in the sales process.  This ensures the MSSP is building credibility with prospective customers, rather than merely explaining their capability.

Process

Process is the assortment of procedures, practices, policies, and internal culture that operates an MSSP.  Process makes an MSSP sparkle.  Good MSSPs have well defined, well documented, well-maintained processes.  Moreover, they are constantly revising, adapting, and updating them to suit the perpetually shifting threat landscape.

In contrast, bad MSSPs have … nothing.  It is not uncommon for companies to charge into the MSSP business, believing that as long as they have the correct technologies and people to staff the SOC, they are good.  An MSSP is largely useless without effective processes.

Moreover, Process is what gives an MSSP its value.  MSSPs get acquired for their processes, not for their platform or people.  If you are evaluating an MSSP, you want to look closely at the processes they use to conduct their services.

Scale

Scale is not a discreet component, but rather a factor of an MSSP’s overall strategy and tactical execution.  Scale is how effectively an MSSP handles change.

For an MSSP to be successful, it must be able to put its platform, people, and processes in motion.  This means designing those components to be agile and adaptable.  It also means having the organizational maturity to accommodate a growing customer base.

Scale is where immature MSSPs implode, and savvy MSSPs explode.  Once they begin to acquire customers, the MSSP reaches a critical point where the platform, processes, and people must rapidly change.  This stresses those components, particularly the people.  If the organization lacks effective leadership or empowers people who are uncomfortable with change, the MSSP will begin to struggle.  The company will become unable to handle increased customer load, which will cause customers to become dissatisfied.

Change is discomfort, and savvy MSSPs embrace this discomfort.  They have internal DevOps-style practices that integrate change, growth, and adaptability into everything.

Customers evaluating an MSSP should consider how the MSSP has adapted to the changing threat landscape.  As a customer, constant change can be frustrating. However, if an MSSP can manage this change effectively, it demonstrates and organizational strength and maturity, which is something you want as a customer.

Factors Influencing MSSPs

As I mentioned in the introduction of this article, there are number of influential factors on MSSPs at this time.  In this section, I will address some of the more prevalent influences and how they have changed the MSSP landscape in the past few years.  

Cloud

Ten years ago, MSSP was an “on-premise” business.  In other words, their products were concentrated on managing and monitoring traditional, on-premise technologies (firewalls, IDS, endpoint, etc.).  Today, nearly all MSSPs are cloud-based.  Their platform resides in the cloud and even the management of on-premise equipment, such as firewalls, is handed through cloud products.

AI

Likewise, ten years ago AI was nothing.  Now it dominates every discussion about anything.  Currently, the use of AI in MSSPs is inconsistent.  Much of the AI messaging among MSSPs feels like marketing hype, and not substantive, technical improvement.  Where AI tends to land first is inside the third-party products that use some kind of AI detection method for malware.

Slowly AI is making it into SIEM platforms. However, AI use for threat hunting remains nascent.  Most MSSPs lack the internal expertise to fully integrate AI into their platforms.  Moreover, training an AI to analyze log data is difficult.  Without a sizable set of “positive” (or wanted) events, it is difficult for an AI to identity what constitutes “negative” (or unwanted) events.  Since most SIEM platforms do not store “non-events” this blinds the AI.

Where AI is making a difference is with analysts.  Use of AI for generating scripts, tools, and automations can dramatically accelerate an analysts efforts.  What used to require hours of painstaking coding, testing, and revising of automation scripts can be done in seconds with a prompt to ChatGPT.

However, buyers of MSSP services need to be mindful of this difference.  Merely because an MSSP says they use AI, does not mean it is integrated into the platform (or accessible to the customer).  Analysts using AI to develop scripts or automation is a good thing. However, that does not make the MSSP “AI enabled.”  This is where marketing fluff and process reality can diverge.

Co-Management

Another perpetual challenge with MSSPs is the co-management conundrum.  On the one hand, customers often demand access to the controls the MSSP manages.  On the other hand, giving a customer control creates a race-condition where the customer and MSSP can conflict on management styles or discipline.  Co-management is not necessarily good for customers or MSSPs.  Customers should be prepared to pay more for co-managed platforms vs full-managed ones.

Platform Images

This MSSP platform strategy is special to me, as it was a strategy I played a hand inventing.  In 2017 when I began my research, most MSSPs used a single, monolithic platform where they co-mingled all customer data.  This presented several challenges for using MSSP services in highly regulated environments, where data co-mingling is not permitted per compliance requirements.

My innovation was to use the automation capabilities of cloud environments to deploy an MSSP platform into customer’s own cloud accounts.  This functioned much in the same way as using an Linux or Windows image from a repository.  The image is instantiated independently in each customer’s environment.  Once deployed, it is then customized to suit the customer’s unique needs.  This deployment strategy eliminates all co-mingling issues and will support restrictive compliance requirements.

In 2018 when I built this platform, it was a novel concept.  Today, it is everywhere.  Many MSSP have fully embraced this deployment strategy, as it unlocks lucrative compliance funded opportunities. These types of environments are also more adaptable to customer needs.  

Buyer’s Guide

For companies considering an MSSP, here are some questions you ask to evaluate each dimension of the MSSP:

Component

Questions

Platform

  • Describe the architecture of your platform.
  • How is the platform deployed (automation, images, hardware, etc.)?
  • What services (capabilities) does it offer?
  • What software (agents, etc.) must we install in our environment?
  • How does this software communicate with the platform?
  • What access do we have to the platform and its components?
  • What third-party products does your platform use?
  • How do you update the platform?
  • How is the platform licensed?
  • Where is the data stored?  Is the data co-mingled?
  • What reports / data analysis is provided?
  • If AI is used, describe how and where.

People

  • How is your SOC organized?
  • What teams do you have?
  • Describe how you on-board analysts?
  • What kinds of training, education, or career development does the team receive? 
  • Who responds to my tickets or phone calls?
  • Who manages my account?
  • How often can I expect to hear from an analyst?
  • Are there any regular meetings, check-ins, or reviews
  • If there is an emergency, who do I call? 
  • How will I be contacted in the event of an incident?

Processes

  • Describe how my company will be onboarded to the platform.
  • Define the data flow within your environment.
  • How are access rights assigned, managed, and monitored?
  • Describe how your team manages an incident? 
  • Does your company perform “post-mortems” on incidents? 
  • If vulnerabilities are detected (if this is part of the service), how will I be notified? 
  • What role does your company have in remediating vulnerabilities?

Scale

  • What kinds of performance metrics do you have for your platform?
  • How do you measure success among your teams?
  • How often do you revise internal processes? 
  • How is your platform updated, revised, or adapted to changing conditions?
  • How does the organization manage change?
  • What is the experience and background of the leadership? 
  • Does the leadership have information security expertise?
  • What is the roadmap for the MSSP?

A savvy MSSP can answer these questions (and more).  An immature one may struggle, or resort to marketing fluff.

Conclusion

MSSPs are an integral part of the information security landscape.  In the past decade they have transformed from simple firewall management, to full-service outlets that can accommodate a diverse set of security services.

There are numerous benefits to engaging an MSSP.  The most significant is that an MSSP can focus on security.  Unless your company intends to build a robust, in-house information security practice, it makes sense to outsource some (if not all) security functions to an MSSP.

For marketing and sales teams, your go to market efforts should focus on explaining the benefits of your four components.  Why is your platform unique? How is your team effective?  What practices or processes make your MSSP special?  And how do you adapt, change, and grow with the volatile security landscape.

While the MSSP market has evolved in the past few years, it has not fundamentally changed.  AI and automation are helping MSSPs scale, but they are not altering what makes an MSSP function.  If you are looking to hire, or build and MSSP, then it is important to evaluate the four primary components of an MSSP.

The post What Is a Managed Security Service Provider (MSSP) appeared first on Andrew Plato.

]]>
https://andrewplato.com/what-is-a-mssp/feed/ 0
Platform of Platforms https://andrewplato.com/platform-of-platforms/ https://andrewplato.com/platform-of-platforms/#respond Wed, 28 Feb 2024 02:14:58 +0000 https://zenaciti.com/?p=2767 Palo Alto Networks' platform strategy is flawed, but not the idea. Security desperately needs a platform of platforms.

The post Platform of Platforms appeared first on Andrew Plato.

]]>
Recently, Richard Stiennon took Palo Alto Networks (PANW) to task for extolling the virtue of their security platform.  If you missed this, it is a great article with Stiennon’s classic insight and wit: https://stiennon.substack.com/p/there-is-no-such-thing-as-a-cybersecurity

Stiennon is right to criticize PANW’s platform strategy.  As Stiennon correctly states, “No CISO in the world is going rip out Wiz or Orca because their hardware appliance vendor has a similar product on sale.”  PANW is also not the first to try the platform approach.  Cisco (CSCO), Symantec, and McAfee all tried and all failed.  Microsoft (MSFT) is trying the platform strategy as well right now.

It is a flawed strategy. However, it is not a flawed idea.

PANW is right that security people need a single platform.  Where they are wrong is how they are doing it.

PANW is building a Platform for Products. The PANW platform only manages PANW products, which makes it inherently limited. This is flawed.

What they should be building is a Platform of Platforms (PoP). 

What is a Platform of Platforms?

In an ideal world, cybersecurity teams would have a single portal where they could go to interact with their entire information security environment.  This is a Platform of Platforms.  A PoP would not necessarily manage every aspect of all those disparate products, but rather provide a simplified way to see their status, access key data, and perform routine functions.  A PoP unites the entire security infrastructure into a single portal.

With a PoP, security teams could integrate any security product, whether it is PANW, Cisco, Wiz, Crowdstrike, etc. into the platform.  Those products would then publish a set of capabilities to the platform.

For example, the PoP would not manage an endpoint security product like Sentinel One.  Yet, it could show a list of endpoints not secured along with other useful reports, such as malware blocked.  It might also perform some common management functions, like kicking off a network-wide scan or search for a specific file-hash value.

The PoP is a window into endpoint security, but does not replace Sentinel One’s native management tools.

Now before you dismiss this idea, have you looked at ServiceNow or SalesForce lately?  They are essentially PoPs.

PoP Drop

Naturally, you are shaking your head saying this is impossible.  Ten years ago the management portals companies built for their products were completely closed.  Now everybody uses an API, and those APIs are published (some publicly.)  APIs are insanely powerful.  They open up a product’s possibilities in ways most vendors cannot even imagine.

PoPs could use these APIs to interact with each product, to obtain data and execute functions.  SIEM and XDR platforms have been building huge databases of functionality to accommodate a vast library of third party tools.  This effort would only be slightly more complex than those efforts.  Moreover, this is exactly the kind of problem AI could help solve.

Sounds like a SIEM

SIEMs are the closest relative to a PoP.  The challenge with SIEMs is that they are focused exclusively on managing data from products.   A PoP would go a step further to actually interact with a product’s native API.  However, a SIEM would make a logical starting point to build a PoP.  Some of the larger SIEM products are rapidly approaching a PoP-like functionality.

Who Runs PoP Town?

Naturally, the question is who owns or runs this PoP.  No single security vendor could do this.  Building a PoP would require a company with vast resources and a reasonably neutral position to the vast set of security products on the market.

This is why PANW’s platform is unlikely to succeed.  It demands you buy completely into the Cult of Palo Alto Networks.  PANW is not going to build a platform that enables customers to not use PANW products.

The obvious answer to who could do this is the cloud service providers: AWS, Microsoft, and GCP.   They have the resources and are reasonably neutral to security products.  AWS is already partially there with their Security Hub product.  Azure has a security console now, but it is a clunky mess.  And GCP has not been acquiring security companies for fun.  They obviously have big ideas as well.

A PoP was part of my own vision for a product years ago.  I envisioned a platform that could not only build itself but configure a disparate set of tools and provide a single management interface.  My vision was too big for my funding, so I downgraded it into a compliance product.

PoP Benefits

The single greatest challenge in cybersecurity is and always has been complexity.  The more complex a system is, the more difficult it is to protect it.  Modern enterprise environments are insanely complex and insanely complex to secure.

The ultimate purpose of a PoP: create a simpler, more streamlined way to interact with the security architecture.  Provide a single place where a diverse group of people, from leadership down to operations can access and interact with the security environment.

A PoP would not replace existing management consoles.  Those would still have a place in a PoP environment.  There are plenty of use-cases where administrators would need to drop down into a native console to perform administrative functions.

I fully admit that a PoP is a bit of a pipe-dream at this point.  The effort necessary to build a viable, working PoP is extreme.  However, this is yet another way that cloud providers could continue their consumption of the security industry (see Cloud Eats Security.)

The post Platform of Platforms appeared first on Andrew Plato.

]]>
https://andrewplato.com/platform-of-platforms/feed/ 0
Think Different https://andrewplato.com/startup-sales-think-different/ https://andrewplato.com/startup-sales-think-different/#comments Mon, 01 Jan 2024 19:48:18 +0000 https://zenaciti.com/?p=2690 Do not play your competitor's game, make them play your game.

The post Think Different appeared first on Andrew Plato.

]]>
Do you remember the “Think Different” Apple Computer ads from 1984? The one where the woman throws the hammer at the screen while an audience of zombie-like users are blown away.  (Here is a YouTube if you missed it.) There is a reason this ad was effective.  It not only asked the viewer to think different, the ad itself was different.  Wildly different.

In the early 1980s, computers and their ads were dull, beige experiences populated with dorks in sweater vests.   Apple presented a stark contrast between their vision for computers and that of the computer titans of the time (namely IBM). In a single ad, with a single message (“Think Different”) Apple changed the entire computer market.

Of course, Apple would go on to fire their founder and almost destroy the company, but that is a different story with a different leadership lesson.

However, in 1984 Apple innately understood an important rule of running a startup: do not play your competitor’s game, make them play your game.

Nobody Gets Fired for Buying IBM

When you run a startup, you are always at a disadvantage.  Startups lack the people, money, time, and name recognition that larger, wealthier companies have.  Large companies will always use their dominant position to squash smaller startups.  Any competition with larger, entrenched players is inherently unbalanced and unfair.

Moreover, buyers are also biased to select products and services from larger companies.  Smaller startups are riskier, for the same reason stated above, limited resources.  In the early 1980s, IBM dominated the computer business.  Customers believed it was safer to buy from IBM.  Thus their largeness only helped them to become larger, and therefore overshadow any competitor.

Apple was a small(ish) computer company at that time.  They had a respectable reputation among computer nerds.  Their products were more advanced than IBM and the various PC clones, but they were also more expensive.  IBM owned the market.  Apple was playing a game that only IBM could win.

Enter the 1984 ad.  Suddenly, Apple is the coolest thing around.  Everybody wants one.  Where other computer companies struggled, Apple saw an opportunity.  There was an untapped potential that IBM was not addressing.  Computer buyers wanted to be special, unique, and … different.

Apple’s ad provided the market an exceptionally clear choice: we are cool, they are not.  Contrast is supremely appealing to buyers.  When the choices between options are clear, buyers can associate their identity to the product.  Buyers are not merely computer owners, they become Apple computer owners, which is different, special, and unique.

Apple changed the game.  Incidentally, Apple did the same thing in 2007 with the iPhone.  Which is why the rectangle in your hand looks the way it does.

The lesson here for startup sales and marketing teams is this: do not do what everybody else is doing.  That is a surefire way to disappear into the noise of a marketplace.  You must stand out from the crowd.  Even a poorly organized marketing effort that is unique and attracts attention is better than a well-crafted one that is the same as everybody else.  Be different. Intentionally different.

So, how do you do this?

Cultivating Creativity

For starters, you need creative people and an environment that inspires them.  That is easier said than done.  Creative people are unpredictable, weird, and sometimes terrifying (just hang around any art school for a few minutes, if you need this point proven.)  Anything that is truly unique is inherently scary, because it has no predecessor to prove it works.  This makes it easy for critics to dismiss creative ideas as stupid, dangerous, or destined to fail.

Creativity can be uncomfortable.  Investors, particularly the kind that are convinced they know everything, may aggressively challenge creative messages.  Some investors have this malformed methodology where they invest millions of dollars into a disruptive, creative company, only to then squash all disruptive and creative ideas.  They suffocate their own investments.

Likewise, employees may freak out when presented creative messages.  This is also a fear reaction.  When people achieve a level of comfort in a job, they will fight hard to maintain that comfort.  This means rejecting anything that threatens to disrupt that comfort, like a strange, new idea.

As a leader (founder) you must not only sell your creative ideas to customers, but also reassure the people around you (employees, investors, partners, etc.) that it will work.  You will not know if it works until it does (or does not.)  When people ask for data or proof that your crazy idea will work, you can only point to other instances, such as Apples 1984 advertisement, where a disruptive, creative idea did work.

Unfortunately, not all disruptive, creative ideas work.  The history of marketing is littered with creative ideas that cratered soon after launch.  One that pops into my mind was the LifeLock ads from 2007 where the CEO dared people to steal his identity.  It was definitely different.  It also laid down a challenge for hackers to prove him wrong, which they did…quickly.

The wrong kind of different.

Creative Guardrails

So how do you cultivate a creative space without falling into a creative crater?  Guardrails.  Lifelock’s idea failed because it compelled people to do something wrong.  The Lifelock team needed some basic guardrails around their messaging.

This is a funny contradiction about innovation and creativity: to encourage innovation you need to be open minded, but not so open minded you do something insane.  Guardrails place reasonable constraints around messaging to ensure it stays in a productive and practical space.

What do these guardrails look like?  They are unique for each company, however here are some generic ones you can consider:

Example Guardrails

  • Do not ask the audience to do anything illegal, immoral, unethical, or disgusting. Lifelock needed to follow this guardrail.
  • Do not associate your product with something repulsive, cruel, or oppressive. Apple’s ad did the exact opposite. It associated their product with freedom, beauty, and self-expression.
  • Avoid the taboo topics: sexuality, religion, politics.  These topics are too emotionally charged to be wielded effectively these days.
  • Do not insult people’s characteristics. It is not funny or clever to insult immigrants, disabled people, or redheads for example.
  • Do not trivialize things that cause(ed) people pain, suffering, or misery. For example, slavery is never funny.  Do not ever use it, no matter how cute or sensitive you think you are.
  • Tantalize, do not arouse. You do not want your audience feeling uncomfortable, embarrassed, or awkward.  You want them to be curious, inspired, and/or excited.
  • Do not use copyrighted content. You can hint at it.  The best way to do this is to use similar words or designs.

Guardrails only can go so far.  And every time you create one, you may find yourself quickly breaking it.  The goal of any disruptive message is to want to make people know more about you.  Whatever images, phrases, or concepts you have, they should all leave your audience asking: “I want to know more about them, they look interesting.”

Conclusion

Thinking differently is vital if you want to stand out from the crowd.  Whatever your competitors are doing, you must be intentionally and overtly different than them.  Otherwise, there is nothing special about you and therefore no reason to select you over a more well-established brand.

The post Think Different appeared first on Andrew Plato.

]]>
https://andrewplato.com/startup-sales-think-different/feed/ 1
Do Startups Need Rockstars? https://andrewplato.com/do-startups-need-rockstars/ https://andrewplato.com/do-startups-need-rockstars/#respond Mon, 04 Sep 2023 19:46:14 +0000 https://zenaciti.com/?p=2497 In the early startup stage, rockstar employees can create more trouble than they solve.

The post Do Startups Need Rockstars? appeared first on Andrew Plato.

]]>
I was meeting with a fellow founder recently. He was recruiting for a role in his company. An VC advised him to find a rockstar employee who could “move the needle.”

Rockstars are those hotshot employees that founders and investors crave. They are the unicorn CRO, CMO, or Product Managers that promise big ideas, big connections, and big sales to the company.

“Do I need to hire rockstars at this point?” pondered my founder friend.

“Fuck no!” I exclaimed with usual tact. “They are way more trouble than they are ever worth,” I continued. This kicked off a lively discussion (with fewer f-bombs.)

Rockstars are distractions. They feed egos not growth. What startups need are experts.

Rockstars vs. Experts

When you are in that tenuous early phase of a startup, you need people who are agile, creative, and can execute effectively against less-than-ideal plans. You want experience. However, many of the people who sell themselves as experienced startup rockstars, are merely frauds cashing in on a single success years (or decades) ago.

What startups need are experts who have experience sans the attitude.

How do you differentiate rockstars from experts?

  • Rockstars are always telling stories about their amazing accomplishments of the past as a method to impress you. Conversely, experts use the past as an example of when they learned something.
  • Rockstars routinely drop names of all the big shots they know. They will become especially name-droppy when under stress. Experts are more interested in ideas and goals, than personalities.
  • Rockstars show minimal interest in the company’s plans or vision. Experts want to discuss the plans and goals all the time. They want to make sure they are meeting expectations.
  • Rockstars demand a big compensation package and a lofty title. Experts want fair pay and a reasonable title that reflects their role, duties, and authority.
  • Rockstars believe they are exempt from the company’s hiring practices, policies, or procedures. They expect “short cuts” on the way to getting an offer. Experts may not like all the procedures, but respect them as a necessary part of running a business.
  • Rockstars tell you they know everything and have “been there done that.” Experts are quick to tell you what they do not know and want to learn.
  • Rockstars ignore the founder when it suits them. Experts challenge the founder when it makes sense.
  • Rockstars are overqualified. Experts are slightly underqualified.

Rockstars are not necessarily arrogant, self-absorbed jerks. They are usually quite personable and likable. They are after all, selling you on themselves. Difficult to do that if you are unlikable. Likewise, experts are not all humble, self-aware monks. They often have coarse personalities. The difference is how these two candidates approach their role. Rockstars coast on their previous success, experts want to build new success.

Rockstars Feed the Ego

Why are startups so enamored with rockstars?

When a startup is in its early stages, it is desperate for credibility. This is especially true in the early funding rounds. The founder(s) and investor(s) want to validate that the company, its products, and its market are all viable. They are desperate to get the company on the map and make a name for themselves (so they can all exit with big paydays.)

The responsible way to do this is to focus on building a great product, creating loyal customers, and cultivating valued partners. Those are all “heads-down” activities that take time. They are not sexy. They are the nuts and bolts grind of everyday.

Rockstars promise a shortcut. They are the Billy McFarland’s of Startup world. They make promises of great successes using their huge network and vast experiences, in exchange for a giant comp package. Foolish founders and weak investors fall for this, as they are desperate to validate the business. As such, the rockstars feed the egos and make everybody feel important.

Of course, the same thing always happens. These rockstars waste time and money, dancing and waving their hands, constantly telling everybody of what a genius they are. Eventually the walls close in and they jump ship, to the next startup desperate for credibility.

People do not magically give a company credibility. Those people must be able to execute the company’s mission. If they cannot do that, then it does not matter who they know or what successes they had in the past.

What About All Those Startup Rockstars?

They did not start as rockstars. The people who become real rockstars, started out as experts. They applied themselves, stuck to a vision, and generated success iteratively. Also, most rockstars had tremendous help on their path to fame. You do not build the next ChatGPT alone in your garage. It takes the contributions of numerous people, united around a set of common goals.

Think Past Your Ego

The rockstar issue is one of the many issues you will face as a founder where you must think past your own ego. The ego-centric thing to do is to hire rockstars, as they will make you feel good about your company. The intelligent thing to do is to hire people who will challenge you and bring creativity to the company. These people may not always make you feel comfortable, but they are much more likely to execute against the company’s vision and mission.

The post Do Startups Need Rockstars? appeared first on Andrew Plato.

]]>
https://andrewplato.com/do-startups-need-rockstars/feed/ 0
How to Get Sales Prospects to Discuss Pain https://andrewplato.com/sales-prospects-discuss-pain/ https://andrewplato.com/sales-prospects-discuss-pain/#respond Sun, 23 Apr 2023 18:20:36 +0000 https://zenaciti.com/?p=2404 Encouraging prospects to discuss their pain requires building credibility and trust. Storytelling is how you can open the door.

The post How to Get Sales Prospects to Discuss Pain appeared first on Andrew Plato.

]]>
In my previous blog on Customer Pain, I discussed the importance of focusing on a prospect’s (or customer’s) pain. Customers, particularly in the information security space, do not buy products or services so much as they buy pain relief.

NOTE: in this blog I use the terms prospect and customer interchangeably although they are different. The concepts of pain apply to both prospects and paying customers.

Consequently, it is important to focus conversations around the pains your prospects experience.  This requires sales and marketing people who are able to get prospects to discuss their pain.  Most people are not going to reveal their weaknesses to a sales person.

I spent many years selling security products and services.  I found that the way to get prospects to open up, was to simply be curious.

Curiosity

Curiosity is amazing. It creates a safe environment where people can openly discuss their pain.  However, you need be careful. Too much curiosity to quickly can make people defensive.

Over the years, I developed a set of questions to ease into discussions about pain.

  • Tell me about the problems you are experiencing.
  • How is this impacting (harming) you?
  • How long has this been going on?
  • What have you done to make things better?
  • What results did you get?
  • Have you tried anything else?
  • Are you satisfied with your current efforts?
  • Do you think there are better ways?
  • How do you feel about this?

When people open up and reveal pain, you must show empathy, concern, and more curiosity. Then you are building a relationship based on support and care, rather than a merely transactional sales engagement. Curiosity is magical in how well it disarms people and reveals truth.

Being curious also refocuses the conversation away from you (and your products) and on the customer. People like to talk about themselves. They will like and trust you when you let them talk about themselves.

Storytelling

However, not every customer will be receptive to curiosity. It may cause the customer to take up a defensive posture where they will reveal nothing. In this case, you need to nudge them back to a safe space. Telling a story can do this.  But not any stories, rather a stories with the specific intent of communicating “I am like you, I get you.”

Again, most salespeople mess this up, as they tell stories about themselves. For example, anybody blathering about what a big shot they were when they worked at some big boy company, is not communicating empathy. They are communicating ego.

What are these stores like? I tinkered around with this for years. I found that stories that are tangentially relevant, were the most effective. A tangentially relevant story is about pain that is similar (not identical) to the prospect’s pain.

For example, when I was meeting senior level security people, I would often tell stories about when I did security operations (SOC) work for a customer. I did not focus on me (or confidential customer information), but rather on the clumsy tools and soul-crushing politics of the organization. In other incidents, I would tell stories about the frustrations of deploying particular technologies which were similar (but not identical) to the technology the customer was installing.

The intent of these stories was twofold:

  • I have “been there done that”
  • I understand your pain

The reason my stories worked, was the tangentially relevant details.  For example, when I mentioned the politics of the organization.  Superficially, this sounded like innocuous complaining, but when people hear these details, it reinforces the credibility of the story. Moreover, it communicated to the listener, “I have had to put up with this stuff too.”  Small, unusual details are what make stories more real.

Once I had reassured the customer I understood them, they were more receptive to a question such as “tell me about your pain.”

Incidentally, while I did draw upon my experiences for stories, I also altered the details so as not to reveal confidential information. Stories do not need to be absolutely accurate. Removing key details ensures you are not violating confidentiality while still benefiting from those experiences.

Training Sales to Tell Stories

Invariably, this prompts the question, how do you train salespeople to do this?

  1. Stop pitching. Reorganize your sales methods to stop all pitching. The first few meetings with a customer should be 100% listening and gathering information. Any discussion of your product or services should be relegated to later.
  2. Build Buyer Personas. While not discussed in this blog, it is vital you understand who you are selling to. Buyer Personas help define these people. More specifically, they should define what is important to these buyers.
  3. Role Play: Gather your sales team and role play scenarios.  Hire a sales coach to help.
  4. Remove Ego and Collaborate. You do not need to actually experience something to tell a story about it. With an ounce of creativity and a lot of humility, you can borrow stories (and be honest with customers that you borrowed it.) Remember, the story is not about making you seem smart or cool, but rather reassuring the prospect you understand them and have credibility. Collaborate with other’s and listen to their stories. The stories you need are everywhere around you.

That last item is the real magic. The gateway to stronger relationships with customers is to remove your ego from every engagement. I can tell in an instant when a salesperson cares about me or themselves. It is all in how they present information.

If you can tell a genuine story, that shows you care, you can build a strong relationship based on trust, and not merely selling.

The post How to Get Sales Prospects to Discuss Pain appeared first on Andrew Plato.

]]>
https://andrewplato.com/sales-prospects-discuss-pain/feed/ 0