This post was originally published on this site

Welcome to the second Cloud CISO Perspectives for September 2026. Today, Alicja Cade and Nick Godfrey, senior directors, Office of the CISO, share their guidance for cybersecurity startups on how to win over the CISOs who will become crucial business partners and customers.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', ), (‘btn_text’, ‘Visit the hub’), (‘href’, ‘https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-‘), (‘image’, )])]>

How cybersecurity startups can win CISOs

By Alicja Cade, Senior Director, Financial Services, Office of the CISO, and Nick Godfrey, Senior Director, Office of the CISO

Alicja Cade headshot 2

Alicja Cade, Senior Director, Financial Services, Office of the CISO

Cybersecurity startups play a crucial role in technology as they build to solve both legacy, existential challenges and the latest problems on the cutting edge. A key part of winning and transforming the cybersecurity field is becoming a strategic partner to CISOs and their security teams.

Google has supported more than 50 cybersecurity founders over the past four years through our Google for Startups program, including Authologic, BforeAI, Build38, Cerby, Crowdsec, Risk Ledger, and Mokn.

Christian Torres, co-founder and CEO, Kriptos, and a Google for Startups participant, said that building connections between startups and CISOs is crucial to solving critical security challenges.

NickGodfrey8975-hi

Nick Godfrey, Senior Director, Office of the CISO

“The Google for Startups program has been the most impactful initiative we’ve joined as a cybersecurity company. Unlike other accelerator programs, this one speaks our language — the challenges, the ecosystem, and the conversations are 100% aligned with what we do every day at Kriptos. The access to CISOs and security leaders has been invaluable, and the connections we’ve built through the program are ones we now see regularly across industry events. It’s put us exactly where we need to be,” he said.

Cybersecurity startup founders face many competing taskmasters as they fight for survival, from demanding capital funders to the relentless pressure of growing their market and networks. CISOs should be key stakeholders for cybersecurity startups so that founders focus on solving thorny challenges in a way that works in the real world.

Listening to CISOs and understanding the businesses that they serve takes time and effort, and if done right can help deliver better value and create a lasting enterprise foundation and network of allies.

Here are three top tips from September’s Gemini Startup Forum for Cybersecurity, part of the Google for Startups program, where we offered vital guidance, addressed critical domains, and helped foster deep dialogue for the next generation of AI-native cybersecurity startups.

Tip 1: Listen then design and deliver for your customers

Avoid becoming a round peg in a square hole by combining your problem-solving startup with listening to CISOs who have to protect real systems, networks, and people. Listening to CISOs and understanding the businesses that they serve takes time and effort, and if done right can help deliver better value and create a lasting enterprise foundation and network of allies.

Here’s how to develop trusted CISO relationships:

  • Host diagnostics meetings. Your meetings with CISOs should focus on mapping their operational bottlenecks and co-authoring collaborative solutions while studying their pain points.

  • Create “unselling” spaces to build peer trust. Host intimate, pitch-free roundtable discussions on industry challenges or establish a critique-only advisory board to build genuine relationships with CISOs without the pressure of a sales environment.

  • Use neutral networks that don’t include venture capitalists. Engage with CISOs in low-friction environments by contributing to open-source security projects and participating in academic and geopolitical risk forums where security leaders gather to solve broad industry problems.

  • Avoid the bait-and-switch pitch. Never disguise a sales pitch as a research or feedback session, as tricking a CISO into a product demo will permanently destroy their trust.

  • Center their business context. Don’t limit your listening to the technical security stack, because the CISO’s primary job is to enable and protect the broader business strategy.

Tip 2: Evaluate AI security to filter out noise

Instead of just using AI to assemble the product, startups should critically evaluate what makes your approach unique and how you communicate that to potential customers.

  • Define your moat by investing in proprietary datasets, specialized fine-tuning, and unique orchestration layers that create a true technical moat. Don’t be a wrapper.

  • Secure the intelligence by proactively designing your models to resist adversarial attacks, prompt injection, and data poisoning. In cybersecurity, model robustness is your ultimate trust signal.

  • Deliver high-fidelity outcomes by clearly communicating how your AI product reduces cognitive load for defenders, minimizes false positives, and integrates safely into existing operations.

Avoid using generic marketing buzzwords like “cognitive,” “autonomous,” or “revolutionary” without the technical documentation, case studies, and whitepapers to back them up. In a skeptical market, transparency is your best sales tool. 

Tip 3: Enthusiastically embrace your sector

Keep a sharp eye out for common due diligence pitfalls during investment and merger and acquisition cycles. These include ensuring that internal engineering and cybersecurity practices meet external claims, but also evaluating the regulatory context of your business sector as well as the security and reliability of your product and service. 

You have to know whether you’re required to abide by data sovereignty, data residency, and other requirements. To avoid this pitfall, engage with broader stakeholders early who know the sector and its nuances well.

How to keep the conversation going

Even beyond the crowded field of aspiring cybersecurity companies, startups broadly can benefit immensely by making sure that they listen carefully, evaluate objectively, and take to their sector requirements enthusiastically. 

“Google’s Office of the CISO has been a bridge between LetsData and the security leaders we need to reach. Sometimes that bridge is advice on how our offering maps to a CISO’s real priorities. Sometimes it is a direct introduction to a CISO who is looking for exactly what we build. For a startup, a warm introduction at that level is priceless,” said Ksenia Iliuk, founder and COO, LetsData.

To learn more about how Google Cloud’s Office of the CISO can help support your organization, check out our CISO Insights hub.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', ), (‘btn_text’, ‘Watch now’), (‘href’, ‘https://www.youtube.com/watch?v=Wpo-5ke9uvQ’), (‘image’, )])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Agentic hacks, real proofs: Inside Google’s PageBreak project: Distinguishing a genuine, exploitable flaw from a convincing hallucination has become a major challenge, often increasing the burden on product teams. PageBreak is an internal AI agent of Google’s Product Security team developed to test the security of our first-party web applications and address this challenge. Read more.
  • Investing together: Wiz Defend and Google Security Operations: Continuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigate. Read more.
  • A unified view of Android security updates for enterprises and OEMs: We’re introducing new libraries that give enterprise partners and OEMs a complete, real-time picture of a device’s security posture. Read more.
  • Delivering new partner security agents and AI defenses with Gemini Enterprise: We’re expanding our catalog of partner-built security offerings in the Gemini Enterprise ecosystem to help you leverage your full security context. Read more.
  • Google named a Leader in the External Threat Intelligence Service Forrester Wave: We are proud to announce that Forrester has named Google a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026. Read more.
  • Wiz named a Leader in the Proactive Security Platforms Forrester Wave: Forrester’s Proactive Security Platforms evaluation for Q3 2026 rated Wiz with top scores across eight areas, reflecting our commitment to securing the AI era. Read more.
  • Strengthen your CI/CD pipeline with new Secure Source Manager capabilities: To help you better address software supply chain threats, our Secure Source Manager lets you manage your source and CI/CD systems with unified authentication and authorization mechanisms. Read more.
  • Building an AI detection engine that understands agent intent: Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior. Read more.
  • Using AI to discover and fix high-priority exposures across public services and critical infrastructure: New initiative partners with under-resourced organizations to uncover, remediate exploitable risk at scale. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', ), (‘btn_text’, ‘Learn more’), (‘href’, ‘https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-‘), (‘image’, )])]>

Threat Intelligence news

  • ShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft: Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. Read more.
  • Proactively defend by hardening code pipelines and CI/CD infrastructure: Check out our actionable blueprint for software and platform architects designed to safeguard the software supply chain against threat vectors that are actively being exploited, third-party risks, and architectural vulnerabilities throughout the entire software development lifecycle. Read more.
  • Infostealer incursion: How stolen credentials breach cloud, code, and AI environments: Wiz Research analyzes NordStellar data to map the credentials targeted by infostealer families and assess their potential impact across cloud, code, and AI environments. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: Patching browsers with AI, agents, Rust, and your tabs: Jasika Bawa and Doug Turner of Chrome Security explore how Google Chrome now uses AI agents to autonomously identify and patch security vulnerabilities at an unprecedented scale, significantly accelerating the browser’s update cadence. Listen here.
  • Cloud Security Podcast: All about Project Atlas, Wiz’s AI vulnerability research: Nir Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.