Cybersecurity tool selection works better when CISOs give security practitioners a voice in buying decisions, improving adoption, security outcomes and team retention.
John Barrow remembers exactly what it was like when the CISO showed up with another shiny new security product. The decision had already been made. The money had been spent. Now the security team had to make it work.
“Hey guys, we bought this awesome technology. Y'all need to learn it,” Barrow recalled hearing at a previous organization.
There was just one problem: The practitioners responsible for operating the technology knew there were other products they thought were better. Some were cheaper. Some had better support. Some simply made more sense for the environment. Nobody had asked them.
“It would have been nice to have a seat at the table, at least to provide input or ask questions,” Barrow said during a recent episode of CYBR.HAK.CAST. “But it was never the case.”
Full CYBR.HAK.CAST episode and related article:


Barrow eventually became the guy sitting on the other side of that table. Today he's CISO at JB Poindexter & Co., overseeing cybersecurity for a parent company of multiple manufacturing businesses. He's also co-founder and managing partner of LaunchPoint Collective, where he evaluates emerging cybersecurity startups and connects them with security leaders.
When Barrow became a security leader, he made himself a promise: He wasn't going to buy technology the way his former CISO had.
The people using the security tool should help choose it
Barrow hasn't stopped scouting technology. Quite the opposite. Roughly half of his security program uses startup technology, and he describes himself as an early adopter. His team has explored technologies including agentic AI SOC capabilities and autonomous AI penetration testing — categories that some of his CISO peers considered too experimental only a year or so ago.
But Barrow doesn't equate being an early adopter with being the guy who picks all the tools. His job is to find possibilities. His practitioners help decide which possibilities become part of the security stack.
Barrow does the initial vetting, looking at a product to determine whether it aligns with an actual problem or challenge his organization faces. If it passes that test, he brings it to the technical experts on his team. They see the demo, evaluate the technology and then everybody talks about it.
“They're going to be the ones using the technology, not me,” Barrow said. “I want their insights. I want their thoughts.”
Sometimes the answer isn't what he expected. Barrow may bring his team something he thinks is impressive, only for the practitioners to tell him it's merely OK — and then point him toward something else they believe is better. He listens.
That's an important leadership lesson for CISOs. Being accountable for the security program doesn't mean you have to be the smartest person in every technology decision. Trying to be may actually make the program worse.
Security technology doesn't work if nobody wants to use it
There's also a practical reason to involve practitioners before the contract gets signed: People tend to be more invested in decisions they helped make.
If a CISO purchases a product and orders the team to use it, the organization may technically deploy the technology. That doesn't mean the team will use it particularly well. Barrow sees practitioner involvement as a way to create ownership.
“I want them to be excited,” he said. “I want their buy-in. I want them to be a part of that decision, because then we're all going to be more successful.”
The opposite is also true. Force practitioners to use technology they didn't want and don't believe in, and Barrow argues they're less likely to use that technology to its full potential.
That's an expensive problem in cybersecurity. Security products don't create value simply because they're licensed and deployed. Somebody has to configure them, tune them, integrate them into workflows, investigate what they produce and keep them useful as the environment changes.
A shelfware problem can begin long before a product actually lands on a shelf. Sometimes it begins when the people expected to operate it are excluded from the buying decision.
Your security stack can be a retention tool
Barrow's approach produces another benefit that has little to do with procurement: It helps him keep people.
His practitioners aren't simply maintaining the same collection of security products year after year. They're continuously exposed to emerging technology and invited to help determine what belongs in the environment. That gives them something cybersecurity professionals tend to value highly — the opportunity to keep learning.
Barrow believes that's one reason people stay on his team.
“They know that we're constantly elevating the program and we're adding new and the latest cutting-edge technology,” he said. “They're never stagnant. They're never bored.”
Security leaders spend enormous amounts of time thinking about employee retention through compensation, career paths, certifications and training. Technology decisions can be part of that equation, too. Give practitioners exposure to emerging technology, let them evaluate it and give them influence over the environment they're responsible for protecting.
Now technology selection isn't simply procurement. It's professional development.
The CISO doesn't need to live in the weeds
There's a potential objection to all of this: Shouldn't the CISO understand the technology deeply enough to make these decisions?
Yes, but that doesn't mean the CISO should be doing the practitioner's job.
Barrow draws a distinction between security leadership and operating security tools. As the CISO, he needs enough understanding to evaluate where the organization is going, identify problems and recognize potentially useful technologies. But he also has to operate at a strategic level, work with the C-suite and think about what's coming next.
If he spends all his time buried in individual tools, something else gets neglected.
“The strategy gets lost because there's not time to think about it or focus on it,” Barrow said.
CYBR.SEC.CON puts practitioners into the discovery process
That same philosophy is part of what CYBR.SEC.Community and LaunchPoint Collective are trying to bring to CYBR.SEC.CON 2026, Sept. 15–16 in Houston.
LaunchPoint is working with CYBR.SEC.Community to bring more than 20 emerging cybersecurity startups into the conference, where they'll have opportunities to meet CISOs and security practitioners through booths, presentations, the LaunchPad competition and surrounding events.
But the more interesting part isn't the number of startups. It's who gets to interact with them.
If the old model is a CISO seeing a product, signing a contract and bringing it back to the team, CYBR.SEC.CON creates an opportunity for a different discovery process: Put security leaders, practitioners and emerging technology in the same place before the buying decision happens.
LaunchPoint's role begins with filtering. Barrow and co-founder David Sledge evaluate startups, their founders and the technologies they're building, then look for security leaders and early adopters whose problems align with those technologies.
CYBR.SEC.CON provides the environment where the next layer of evaluation can happen. Practitioners can ask the technical questions while CISOs consider the strategic fit. Founders, meanwhile, can hear directly from the people who would actually deploy their products. Those conversations don't have to end with somebody asking for a purchase order.
Barrow said LaunchPoint's goal is fundamentally about introductions and relationships.
“Our big thing is we just want to introduce people,” he said. “We want them to build a relationship. We want them to get to know these people.”
That may be particularly valuable as AI and other emerging technologies force security organizations to evaluate new tools faster. CISOs still have to make decisions, and they still own the risk. But they don't have to make those decisions in isolation.
The people sitting at the keyboard after the purchase shouldn't discover the new security stack when the boss walks in and tells them what they just bought.
Give them a seat at the table before the decision gets made.

