Mastering Vendor Engagement in Cybersecurity
Download resourcesAbout this session
Evgeniy Kharam, a security architecture consultant and podcast host, reframes vendor engagement from the buyer's side rather than the usual sales-enablement angle. He argues that customers should set explicit expectations up front (whether interruptions are welcome, whether the meeting is exploratory or a real buying process) and treat a firm 'not now' as a normal, time-saving answer. He walks through how vendor sales teams operate internally, including quota frameworks like MEDDIC, CRM-driven forecasting, and end-of-quarter discounting, so buyers can read what is actually happening in a deal. On the buyer's side, he stresses assigning a single project owner, writing success criteria and a runner-up option before any proof of concept, watching for hidden costs beyond list price, and starting renewal conversations months in advance. He closes with tips for vetting a vendor's real support quality and for actually reading SOC 2 Type II reports rather than treating the certificate as a checkbox. A long audience Q&A covers shifting success criteria, cross-team buy-in, and assessing salesperson turnover as a trust signal.
Key takeaways
- Set explicit expectations with a vendor at the start of every call (interruptions, exploratory vs. buying intent) instead of letting the meeting drift.
- Assign one project manager to own proof-of-concept scope and timeline so shifting requirements from either side do not derail the evaluation.
- Ask vendors whether they use a qualification framework like MEDDIC and what their fiscal year-end is; both explain their questions and their willingness to discount.
- Define success criteria and a runner-up vendor before starting a proof of concept, and expect hidden costs (support, implementation, technical account management) beyond the quoted price.
- Actually read a vendor's SOC 2 Type II report instead of just confirming it exists, and start renewal conversations months ahead rather than at contract expiry.
Speakers

Evgeniy is built and wired differently. As a father of four, including twins, Evgeniy has mastered the art of remaining unflappable in adversity. This personal resilience translates into his professional ethos, where he has ascended from a firewall… Read moreRead less
Evgeniy is built and wired differently. As a father of four, including twins, Evgeniy has mastered the art of remaining unflappable in adversity. This personal resilience translates into his professional ethos, where he has ascended from a firewall deployment engineer to the Vice President of Architecture at the Herjavec Group. His journey through the evolving landscape of cybersecurity provides him with a unique, panoramic view of the industry, enhancing his capability to lead and innovate across all its domains. Evgeniy's passion extends beyond his day-to-day corporate roles. He is the co-founded of two influential podcasts—one that delves into technical security architecture and another that offers cyber inspiration for business leaders. His engagement with the community continues as he moderates panels and conducts interviews, shaping the conversation in the cybersecurity industry. He also serves as a board advisor to the Canadian Cybersecurity Network, the largest technology group in Canada. His creative spirit is showcased through his co-founding of a cybersecurity-focused ski and snowboard conference, which ingeniously merges lifestyle with professional engagement, thus captivating his audience. Currently, Evgeniy runs his own cyber/media consulting services, drawing on his extensive industry knowledge and media expertise to navigate clients through the complexities of cybersecurity. His literary contribution includes a book on soft skills for technical sales, expanding his consulting services to include mentorship on these essential topics. Whether you are here for his book, training, or consulting services, Evgeniy offers a wealth of knowledge and experience, ensuring invaluable insights tailored to the dynamic needs of the cybersecurity field.

