Here are three top tips from September’s Gemini Startup Forum for Cybersecurity, part of the Google for Startups program, where we offered vital guidance, addressed critical domains, and helped foster deep dialogue for the next generation of AI-native cybersecurity startups.
Tip 1: Listen then design and deliver for your customers
Avoid becoming a round peg in a square hole by combining your problem-solving startup with listening to CISOs who have to protect real systems, networks, and people. Listening to CISOs and understanding the businesses that they serve takes time and effort, and if done right can help deliver better value and create a lasting enterprise foundation and network of allies.
Here’s how to develop trusted CISO relationships:
-
Host diagnostics meetings. Your meetings with CISOs should focus on mapping their operational bottlenecks and co-authoring collaborative solutions while studying their pain points.
-
Create “unselling” spaces to build peer trust. Host intimate, pitch-free roundtable discussions on industry challenges or establish a critique-only advisory board to build genuine relationships with CISOs without the pressure of a sales environment.
-
Use neutral networks that don’t include venture capitalists. Engage with CISOs in low-friction environments by contributing to open-source security projects and participating in academic and geopolitical risk forums where security leaders gather to solve broad industry problems.
-
Avoid the bait-and-switch pitch. Never disguise a sales pitch as a research or feedback session, as tricking a CISO into a product demo will permanently destroy their trust.
-
Center their business context. Don’t limit your listening to the technical security stack, because the CISO’s primary job is to enable and protect the broader business strategy.
Tip 2: Evaluate AI security to filter out noise
Instead of just using AI to assemble the product, startups should critically evaluate what makes your approach unique and how you communicate that to potential customers.
-
Define your moat by investing in proprietary datasets, specialized fine-tuning, and unique orchestration layers that create a true technical moat. Don’t be a wrapper.
-
Secure the intelligence by proactively designing your models to resist adversarial attacks, prompt injection, and data poisoning. In cybersecurity, model robustness is your ultimate trust signal.
-
Deliver high-fidelity outcomes by clearly communicating how your AI product reduces cognitive load for defenders, minimizes false positives, and integrates safely into existing operations.
Avoid using generic marketing buzzwords like “cognitive,” “autonomous,” or “revolutionary” without the technical documentation, case studies, and whitepapers to back them up. In a skeptical market, transparency is your best sales tool.
Tip 3: Enthusiastically embrace your sector
Keep a sharp eye out for common due diligence pitfalls during investment and merger and acquisition cycles. These include ensuring that internal engineering and cybersecurity practices meet external claims, but also evaluating the regulatory context of your business sector as well as the security and reliability of your product and service.
You have to know whether you’re required to abide by data sovereignty, data residency, and other requirements. To avoid this pitfall, engage with broader stakeholders early who know the sector and its nuances well.
How to keep the conversation going
Even beyond the crowded field of aspiring cybersecurity companies, startups broadly can benefit immensely by making sure that they listen carefully, evaluate objectively, and take to their sector requirements enthusiastically.
“Google’s Office of the CISO has been a bridge between LetsData and the security leaders we need to reach. Sometimes that bridge is advice on how our offering maps to a CISO’s real priorities. Sometimes it is a direct introduction to a CISO who is looking for exactly what we build. For a startup, a warm introduction at that level is priceless,” said Ksenia Iliuk, founder and COO, LetsData.
To learn more about how Google Cloud’s Office of the CISO can help support your organization, check out our CISO Insights hub.







