How to Get Cybersecurity Buy-In From the C-Suite: Lessons From a CISO Inside Private Equity

From the Cybersecurity Ecosystem Show conversation with Kevin Lewis, CISO at E78 Partners

Watch on: Spotify, Apple, YouTube

Most security leaders lose the budget argument before they open their mouth. They walk into a room full of operators and finance people, start talking about EDR coverage and tenant licensing tiers, and the faces go blank. Kevin Lewis has watched it happen. He has done it himself, recently.

"I made the mistake two weeks ago of trying to explain the difference between a P1 tenant and a P2 tenant, security wise, to people who were not security people," he said. "And I just watched all the faces on Teams die."

Kevin is the CISO at E78 Partners, a boutique consulting firm whose primary clients are small and mid-size private equity funds and their portfolio companies. He runs security internally and sits in fractional CIO and CTO seats across client companies, most of them in med spa and healthcare right now. He watches the same problems play out across a stack of organizations at once.

On this episode of the Cybersecurity Ecosystem Show, he laid out what the industry has actually gotten right, why the talent shortage story does not match what he sees in a resume stack, and the management habit that does more to stop shadow AI than any policy document.

What is cybersecurity finally getting right?

Kevin's answer was not a technology. It was a posture change.

"The cybersecurity industry in the past was a no, you can't do that," he said. "And now it is a, that's important to business, let's figure out a way to make this work so that the business can keep moving."

He credits the shift to information flow. Security used to sit at the bottom of a chain that started at the CIO or CTO, and direction came down as a task with no context attached. Do this. Here is five thousand dollars. We are not telling you where the company is heading.

"Because I have a seat at the table, my decisions are different, because I have all of the information," he said. "Data is power."

Kevin is not saying the title gets you influence. He is saying the information gets you better decisions. Once you know the revenue direction and where the margin comes from, that five thousand dollar budget conversation usually has better options hiding inside it.

How do you get cybersecurity buy-in from a CFO?

You translate risk into a daily dollar figure and a reputation cost. Kevin's method starts with one question: what does a day of zero work cost this company?

"Let's say it's ransomware," he said. "If the company is down and we can't access data, our clients can't access data, how much money are we making a day? And then throw on top of that, how much money is it costing us for this remediation?"

He learned that framing in fashion and apparel, where the chain is easy to see. "If we can't design, if we can't get things back from the factories, nothing's shipping, we're not making money." Then he layers on the part with no clean number attached.

"When there's a breach, the company's reputation can be ruined. You can have a mass exodus of clients. It can shut you down, and people will not work with you."

The CEO and COO are usually the easier sell. The CFO is where the resistance lives, because the CFO has already decided what security should cost. Kevin has been asked more than once why the company needs both an XDR and a SIEM. "Same reason you need antivirus," he said. "And firewalls."

The habit underneath all of this is the one worth stealing. Kevin builds Power BI dashboards that pair security metrics with the business metrics attached to them, so the number a control moves is a number the executive team already tracks.

"They can't speak my language," he said, "but I try to speak their language."

That is a discipline, not a personality trait. It is also the gap Rivial's platform closes for banks, credit unions, and other examined institutions: risk expressed in dollars, tied to specific systems, in a format a board can act on instead of a red square on a heat map.

What private equity teaches you about speed

The biggest adjustment Kevin made moving into PE-backed consulting was clock speed. What counts as fast in private industry is about two weeks. In private equity, fast means two days. That sounds like a recipe for cutting corners, and he is clear that it is not. "Things can always be done faster, but you don't want to do them at a pace that you're going to make mistakes," he said.

What makes it work is a trade PE tends to honor. "Private equity is really good at respecting the experts they brought in," he said. He is direct about timing, cost, and scope, and that honesty buys him room. "You want this in two days, but if you want it right, it's going to be five days. And generally they're fine with that."

Then the part every consultant should write down: "But it better be done in five days."

Every day the company is not saving or making money is a day of lost return. That framing is not unique to private equity, it is just enforced there.

Where is AI actually paying off right now?

Kevin's best example is not a security tool. It is a reporting pilot at one of his med spa clients, which ran 15 different systems: blood work, patient information, medications dispensed, and more. His team pulled all of it into a single data lake through APIs and put an agent on top.

"Instead of having to build out Power BI reports, the agent actually does that," he said. "The COO can go in, or the head medical doctor can go in, and ask the agent for what their KPIs are and a report, and it will just pull it and build it on the fly."

The value is not the report. It is the collapse of the waiting period. "The information to make decisions is happening in real time with real reports. You're not waiting a week for a Power BI person to build this KPI report for you."

He called it one of the most interesting and probably most lucrative returns he has seen. The win came from consolidating data before adding intelligence on top, the unglamorous half nobody posts about. And this is healthcare, where HIPAA, PII, and PHI are what his day-to-day already revolves around.

The talent shortage is really a mentoring problem

Ask Kevin what is broken and the department-of-no reputation comes up first, still only half fixed. The second answer is staffing, and his diagnosis is not the one you usually hear.

Kevin does not have a computer science background. He has a political science degree, a master's in cybersecurity he earned later, and a career that began while he was waiting to hear back from the New York City Police Department. Computers were not on his radar. He got in, and good mentors carried him.

"I think we've lost focus on that," he said. He mentors the people who work for him, and he requires the people directly below him to mentor the people coming up behind them.

Why did mentoring fade? First, churn. "People are trying to keep their head above water," he said. "Stopping and teaching someone to do something takes a lot more time than just doing it."

Second, gatekeeping. With salaries and roles under pressure, people hoard what they know because it feels like job security. "What I tell people is share all the knowledge you have and go learn something more. That's how you keep ahead, not by gatekeeping."

He is also skeptical of the shortage narrative. Taylor raised the familiar complaint that entry-level postings ask for five years of experience while people with degrees spend years trying to break in. "I love the CISSP entry level," Kevin said. "You need like ten years verified for a CISSP. It's not entry level."

His read: "As much as we hear about there's a shortage in the cybersecurity industry, we need people, companies aren't paying out or hiring for that." They buy a tool instead. "They don't realize that most of the time you need someone who's experienced and can use that tool to actually make it worth the investment." The same trap is being set again with AI.

What does a hiring CISO actually look for?

Kevin asks HR to forward him every resume. No certification requirements. No degree requirements. "Some of the most intelligent people I've ever met in my life didn't go to college," he said.

Two things move the needle. The first is personality and fit. "I always say that I can teach almost anyone computers. I can't teach them personality." He wants a team that gets along, laughs a little, and switches into serious mode when it matters.

The second is the piece most career-changers skip: the network.

"A lot of people jumped from no computer experience to getting some security certifications," he said. "There's a whole middle layer in there called the network, where all of this security is happening, that they are not familiar with."

He came up through help desk and network management, and he wants to know whether a candidate understands what is moving underneath the alerts.

"Most infiltrations are through the network," he said. "Do you know how a network should be running to look for those anomalies and go, that looks a little odd, let me investigate that? That's a big one that I see missing."

His framing for anyone building a path in: "It's a linear growth to security, not a big hop."

Why fear-based security awareness training backfires

One belief repeats across small companies, and it costs them: cybersecurity is not an issue because we're not a target. "Yes, you are," Kevin said. "You just made yourself a target with that mindset." His fix is education that reaches everyone, entry-level employee through CEO, because "the end user is your best friend or your worst enemy."

But how you deliver that education matters more than whether you deliver it, and here is where Kevin diverges sharply from the industry.

"I do not believe in security training through fear," he said. "Like your job's in jeopardy. I think that just creates animosity."

He does not like the gotcha framing of phishing simulations either, and he put it off for a long time because of it. "We're all adults," he said. "Let's have an adult conversation about this. Let's not force the issue, let's not threaten job security."

When he did adopt them, he reframed what the number means. This is the reframe most worth carrying out of the episode.

"I look at it as a metric for how I'm doing my job, not how the end user is," he said. "How is my security team doing getting the message out?"

Flip the scoreboard and a rising click rate stops being a list of employees to punish. It becomes a signal that the message is not landing, which is a problem the security team owns. Fear-based training makes people pull back and stay quiet, and quiet is the last thing you want from your last line of defense.

Two habits round out the playbook. Kevin gets ahead of the news. When a scary cybersecurity story starts circulating, accurate or not, he sends clients a short summary. "Hey, you may see this out there." That creates a dialogue instead of a rumor. "Make it so cybersecurity isn't the scary boogeyman."

And he stays calm when something breaks. No screaming, just triage and a debrief afterward, a habit he picked up writing after action reports for a DOD contractor. "Calm, cool, collected. We're going to handle this. I think that builds a lot of confidence in the end user."

How do you stop shadow AI? Answer faster

Kevin's control for shadow IT and shadow AI is not primarily technical. It is response time.

"I tell my team, respond immediately," he said. The failure pattern is always the same. The business has a need. Someone asks IT or security whether they can use a piece of software. The request sits, or gets ignored. So they go do it on their own.

"And now with AI, they're using a free Claude and putting proprietary information in," he said.

Respond quickly and the dynamic inverts. "If you're answering and responding in a timely manner, the end user respects you, and then you can make sure that the tools are secure and within budget."

Later in the conversation he put the inverse case. "If you aren't responsive to a business need, the business workers, the line level who need it, are going to find a way to get what they need. So I'd rather work with them than against them."

He backs that up with discovery. He deploys a tool that inventories every piece of software on company machines, which he also uses for pre-close due diligence on private equity deals, and he watches network egress to see which SaaS applications people are reaching. Private equity loves the exercise for a reason that has nothing to do with security: shadow IT is usually a cost problem too. He recently found a company paying ten times what a Microsoft license would have cost for an inferior Visio alternative.

Policy sits underneath all of it. E78 is SOC 2 compliant and helps clients reach SOC 2 and HIPAA compliance, and Kevin is clear-eyed about what documentation does and does not do. Acceptable use, acceptable software, and an AI policy are all necessary now.

"Although that's not going to stop the shadow IT and shadow AI," he said. "That's going to give you the baseline to work off of when you're implementing something."

How to claw back a rogue tool without making an enemy

The Visio story is the philosophy in miniature. Kevin found out who was using the unauthorized tool and who was actually active in it. Then he sent one email: we're transitioning off this, we're simplifying our tech stack. If you use it regularly, I can get you a real Visio license. If you only use it once or twice, Word has an alternative that works fine. Here is my help desk if you want to talk through your options.

"So you create a conversation and an exit path," he said.

No shaming, no sudden shutoff, no ticket black hole. A reason, a replacement, and a person to talk to.

Start with the policy, then build the program

Kevin's AI point lands where every governance conversation lands: you need the written baseline before the tooling means anything. If you do not have an AI policy yet, do not start from a blank page. Download Rivial's free AI Security Policy Template. It is an instant download, no sales call required, and it gives you the acceptable-use foundation the rest of this hangs on.

And listen to the full conversation with Kevin. The career path alone is worth it, from a poli sci degree and a pending NYPD application to running security across a private equity portfolio. You can connect with him on LinkedIn or at [email protected].

Here are the key takeaways from this blog:

  • Information beats title: the seat at the table matters for the business context it carries, and leaders read into revenue and direction make better calls on the same budget.

  • Sell in dollars per day: start with the cost of a day of zero work, add remediation and reputation, and pair security metrics with the business metrics executives already watch.

  • Consolidate data before you add AI: the med spa pilot worked because 15 systems were unified first, turning a week-long report request into a real-time answer.

  • The shortage is partly a spending choice: companies buy tools instead of experienced people, and gatekeeping plus lost mentoring keeps the pipeline from filling itself.

  • Hire for personality and network fundamentals: certifications without protocol knowledge leave the middle layer empty, and most infiltrations run through that layer.

  • Score phishing against your own team: click rates measure how well security communicated, and fear-based training buys silence instead of safety.

  • Responsiveness is a shadow AI control: answer fast and people bring you their tools, and when you find a rogue app, offer a reason, a replacement, and an exit path.

The Cybersecurity Ecosystem Show connects practitioners, investors, vendors, regulators, and everyone in between. New episodes drop weekly. Subscribe so you don't miss one.

Reply

or to participate.