Skills / Raising the round / Paying CISO advisors

Should I compensate CISO advisors — cash, equity, fund points — and where is the ethical line?

The best version of this conversation ends with them buying the product instead.

ciso-advisor-equity

SKILL.md · 1,738 words

Verified Sept 2026

Download the folder
What your agent reads.
name
ciso-advisor-equity
description
Advisor equity, advisory boards, cash retainers and fund points in cybersecurity, where the advisor is usually also a buyer. Use when a sitting CISO or security executive is offered, or asks for, an advisory relationship: sizing an advisory share grant, refusing a retainer for access while paying for a named hour of judgment, writing scope, vesting, share counts and an end date, handling employer consent, conflict-of-interest disclosure and procurement recusal, fielding a question about carried interest or a CISO angel syndicate, or quoting a compensated advisor in a case study. Covers the public record of fund-level CISO profit-sharing and its 2024 suspension. Not about reaching CISOs who do not know the company (first-ciso-meetings), which dinner circuits and paid meeting platforms are real (ciso-dinners-and-matchmakers), recruiting design partners who deploy and pay (design-partners), or dilution across stacked SAFEs (safe-stacking-math).
title
Paying CISO advisors
question
Should I compensate CISO advisors — cash, equity, fund points — and where is the ethical line?
subtitle
The best version of this conversation ends with them buying the product instead.
summary
You are paying someone whose day job is deciding what their employer buys, so their employer's rules decide before yours do. Never buy access, with cash or with equity — grant equity only for sustained specified work, pay for an hour of judgment like any other hour, get the employer's written consent before you sign, and keep the advisor away from any decision to buy your product.
group
raise
verified
2026-09-09
order
28

955 / 1024 characters

This is the top of the SKILL.md file, exactly as it downloads. Your agent reads the description field to decide when to load this skill. The rest of this page is for you.

You are being asked to give a piece of your company to someone whose day job is deciding what their employer buys. That is where general advice about advisors stops being useful, because the security advisor worth having is one step away from the budget you want. We publish no norm for what a sitting CISO should be paid to advise. What follows is what we have watched each instrument buy, and what it cost.

Ask whether they can simply buy.

You start with the question that makes everything below unnecessary. If the advisor's employer could be a customer, a paying design partnership creates no governance problem and produces the only evidence that matters. Ask for the purchase before you offer the grant. Everything here is for the case where they cannot buy.

Decide what you are buying.

You can buy three things from an advisor, and most founders pay for all three and receive one.

The first is judgment: product deep dives, technology strategy, and regular working time where a practitioner's instinct beats research. It can be specified and scheduled, and it is the only one of the three that reliably arrives. The second is access: named accounts and warm introductions. An introduction transfers credibility for one meeting and no budget, because a security purchase is triggered by something inside the buyer's company, a renewal, an incident, a mandate, and no relationship moves that trigger. The network also wears out with use, and its best use is on a deal that is already stuck. The third is credibility, the name on your website and in your deck. Be most suspicious of that one. It buys a governance problem inside someone else's company and returns nothing you can measure. An advisory board that actually meets and does work is worth many times a row of headshots on a page, and the two cost about the same to assemble.

A famous name does not create demand.

You will be tempted, in a hard quarter, to bring in a well-known security name. We have watched that move produce meetings and fail to change the trajectory, more than once, because the name arrives with instincts formed at a company that already had demand and only needed distribution. Applied to a company that has not found its fit, those instincts produce plausible, expensive activity that cannot work yet.

The most credentialed operator in our own network has taken the better part of a year of direct product exposure before introducing a company to a peer, because that person protects their credibility above your cap table. So turn the question around. Converting your most skeptical advisor is a product milestone, and you should track it. If they will not open doors yet, that is information about the product, not about them.

Buy the work, never the network.

You buy work. Equity goes to sustained, specified work, and an hour of someone's judgment gets paid for like any other hour. What you never buy, with either instrument, is access.

At seed you have no money to waste, and an advisor asking for a retainer against introductions in general is asking for an annuity. The advisors who earned their equity in our portfolio ran the deep dives and the working sessions. The ones who did not were granted equity against a general promise of introductions, and the introductions were never the constraint. The reflex is to give a recognizable name a standard grant and call the cost cheap marketing. The cost is not the equity. It is the years you spend believing that distribution is handled.

Paying for a defined hour is a different thing, and it is clean. Where the advisor's employer will never be a customer, buying an hour of product judgment at the rate they name is an ordinary purchase, the way an expert network buys one. Nobody publishes a rate for a sitting CISO advising a vendor, so build the number the way those networks do: ask what the hour is worth, agree how many of them and what they are for, and put a date on the total. That is something you can count and cancel, which equity never is.

Be clear-eyed about what the two instruments do differently. Cash is income the advisor discloses and walks away from. A grant gives a sitting security leader a financial interest in your outcome, which is the exact interest their employer's rules exist to catch. So if equity is the instrument, everything below about consent, disclosure and recusal is not a precaution you may skip. It is the price of the instrument.

Grant in share counts, with an end date.

You write the scope first. A respected operator saying they would like to work with you in some capacity is enthusiasm, not a scope. Write down the sessions, the cadence, the deliverable, and the date the engagement ends.

Then make the paper end where the scope ends. The vesting period is the length of the engagement, not your employee schedule. An engagement that ends next December on a four-year vesting schedule leaves a stranger on your cap table for years. The standard advisor template's grid of percentages is a ceiling, not a norm, and the grants actually made run well under it at every stage. Quote a share count and a strike price, never a percentage, because a percentage is a claim about a denominator that is about to change under both of you.

The instruments substitute for one another. They are not a package. An advisor you are paying for hours takes a smaller grant, because part of the value has already been paid. An advisor who invests takes a smaller grant again. Founders who stack all three price each one as if it were the only one. Use a standard advisor agreement, and keep two clauses from it: a non-compete narrowed to businesses that directly compete, and a statement that the advisor is party to nothing that conflicts with the engagement.

Their employer decides before you do.

You are asking someone to take a private financial interest in a company their employer might buy. That is their employer's call before it is theirs or yours, and the likely answer is no. Plan the relationship so it survives that answer.

Ask for the employer's written consent before you sign anything. The expert networks require it for an hour of paid consulting, so it is not aggressive to ask for it before a multi-year grant. Some advisors carry stricter rules. Anyone registered with a broker-dealer must give prior notice of outside activity, and a government CISO is bound by conflict rules that usually reach an equity grant in a vendor. Their compliance function will run its own sequence of disclosure, pre-approval, recusal, and re-disclosure. Ask those questions before they do.

The standard the profession holds itself to is how things look, not only how they are. A structure that is legally clean and looks bought has still failed. If consent is unavailable, that is your answer, not an obstacle to work around.

Keep the advisor away from the purchase.

You keep the advisory relationship and the purchasing decision in different hands, and you write down which is which. The advisor may define the need. The advisor takes no part in choosing the vendor. That belongs in the agreement, not in an understanding.

Count the cost to the deal before you grant anything. Once the interest is disclosed, their employer's purchase of your product is the one that gets read twice, and that scrutiny lands on your deal rather than on the grant. A promise that their employer will never buy is cleaner and costs you the account. Say that trade out loud. And if you quote a compensated advisor in a case study or a launch post, the federal endorsement rules require you to disclose the connection. That obligation is yours, not theirs.

Read the public record first.

You are not the first to try to pay the people who buy. A fund-level profit share paid to sitting CISOs has been tried. Its defense was structural: the payment came from the fund rather than from any one company, so no advisor could profit from a single purchase. It did not survive the appearance test, because money reached individuals in ways that bypassed their employers' disclosure processes. Structuring around a conflict is not the same as removing it.

Fund points are not yours to give. When a CISO raises them, the conversation is with your lead investor. Ask what the firm pays its network and on what disclosure terms, because that network is most of an investor's value beyond capital and you want to know how it was bought. We pay ours nothing for access or introductions; they take our calls because the companies are worth their time. Where a CISO wants exposure and their employer permits it, an investment is cleaner than a grant. It is priced, at arm's length, and disclosed.

Working the question.

  1. Ask whether their employer can buy instead. If it can, sell to them and stop.
  2. Name which of the three things you are buying, and which one you would still pay for if the other two came free.
  3. If it is access, buy nothing. No retainer, no grant. Access is not the constraint you think it is, and the network wears out whether or not you paid for it.
  4. If it is judgment, write the scope first, including the date it ends. Pay for a defined block of hours at the rate they name, or grant equity for sustained work, and never both for the same work.
  5. Ask for the employer's written consent and their recusal policy before you sign anything. If consent is unavailable, stop.
  6. Size the grant in share counts, vesting over the length of the engagement. Grant less to anyone you are also paying for hours, and less again to anyone who invests.
  7. Write the separation into the agreement, and disclose the connection before any quote or post that names them.

Working with an agent.

Give your agent the advisor's name and the company they work for. Ask it to find that employer's published policy on outside advisory work and on holding equity. Their employer's rules decide this before yours do, and the policy is usually public.

Install the skill.

You are reading the skill itself — this page and the download are the same files. Unzip it into ~/.claude/skills/ (or a project’s .claude/skills/) and Claude Code loads it when the question comes up; so does any agent that reads Agent Skills.

mkdir -p ~/.claude/skills && cd ~/.claude/skills && curl -sLO https://techoperators.com/skills/ciso-advisor-equity.zip && unzip -oq ciso-advisor-equity.zip && rm ciso-advisor-equity.zip

ciso-advisor-equity/SKILL.md

No terminal? Download ciso-advisor-equity.zip and drop into your assistant’s project files.

Kevin Skapinetz

Tell us what you see.

Whether you’re thinking about starting a company, building one in stealth, or raising a round: send Kevin or Dan what you see on LinkedIn, in your words.