- Home
- Services
For cybersecurity founders and investors
A CISO buyer on your side.
I spent 14 years evaluating and replacing security products.
Then I reviewed over 4,000 cybersecurity companies while building CybersecTools and Mandos.
Today, I bring that data-backed experience to your product and investment decisions.
Free · 15-minute call with me

Featured in

What I bring
Experience
How security buyers decide
14 years leading security teams and evaluating security products.
CybersecTools
What security buyers compare
9,178 products, and where people go looking for alternatives.
Mandos
Where the market is going
3,775 companies tracked: positioning, exit readiness, 450+ data points.
What you get
A CISO buyer with market intelligence on your team.
Three ways I can help
CISO Positioning Audit
Fine-tune your positioning, and build a killer sales pitch that drives revenue.
A two-week project
- A score on seven dimensions. Your website and sales decks graded on the CISO Positioning Framework, so you know exactly where you lose a CISO buyer.
- Copy you can use. A rewritten homepage, product benefits, and key sales deck slides.
- A clear plan. What to change first, and a walkthrough together.
- 30 days of support. Follow-up questions by email after the report lands.
- MCP access for 30 days. Query the Mandos record straight from Claude, ChatGPT, Cursor, or your own tools.
Mandos Advisory
Save time, effort, and runway by building only what enterprise buyers pay for.
Ongoing support
- Two strategy calls a month. Sixty minutes each on your positioning, what rivals just launched, and what you tell the board.
- Four written reviews a month. Decks, homepages, outreach scripts, or pricing. Back to you within 48 hours.
- A monthly competitor brief. Feature releases, executive hires, and market moves in your exact category.
- Message me between calls. For the objection that lands in the middle of a live deal.
- Platform access throughout. The Mandos platform and MCP server for the length of the engagement.
Mandos Diligence
Understand what the product does, how it differs from competitors, and why a security team would buy it.
Per deal or ongoing support
- A product and pitch review. The deck and technical documents checked for supported claims and gaps.
- A detailed competitor comparison. Products, features, integrations, and the requirements they address.
- A written investment assessment. Findings, risks, and questions to resolve, followed by a call with your team.
- Market research between deals. Monthly brief on funding, disclosed valuations, acquisitions, and hiring.
- Positioning support for your portfolio. Reviews and buyer feedback for the companies you have backed.
- Platform access throughout. The Mandos platform and MCP server for the length of the engagement.
Need advice on one specific question? Book a 45-minute advisory call.
How it works
Free · 15 minutes
The fit check
We discuss your challenges and see if I can help.
In writing
Scope
We agree on the work and the timeline, before anything starts.
Two weeks or ongoing
The work
Research, reviews, and findings. Written by me, not a template.
Once, or every month
What comes back
Actionable steps you can take right away.
See the work before we talk.
“We didn’t expect a report this thorough, the level of detail went well beyond what we anticipated.”
See an example CISO Score from Mandos
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
How Oasis Security reads to a CISO buyer
Verdict
Oasis sells to the person who signs. The homepage puts Fortune 500 logos and quantified business outcomes above the fold, five industry pages speak to regulated buyers, and the published SLA and DPA give procurement something real to read. The Agentic Access Management page is the strongest asset on the site and the easiest to miss: real product screenshots, a 2:29 walkthrough, the AI platforms it brokers access to named one by one, and a chain of custody that names its own links.
Two things hold the score at 6.5. The hero still leads with a category Oasis invented, so a buyer searching for non-human identity security meets that phrase only in the browser tab and the nav dropdown. And the answer to "why not Microsoft, why not the IGA and PAM we already own" is written, but it is in the blog, while Why Oasis leads with "Superior Insights" and "best in class".
Read this as a re-score. The number has not moved since 29 August because the site has not moved. Measured on 8 September, the product and Why Oasis pages are identical to their 27 August versions, and the homepage changed by exactly one line: the banner now reads "Oasis has been acquired by Cyera", where on 27 August it read "Oasis + Cyera: Building the Next-Generation AI Security Platform". The Cyera deal is closed. Every fix the last score asked for is still open.
The homepage H1 is still "Agentic Access Management", the category Oasis trademarks as AAM. The subhead does real work: "Access control that understands intent, not just static roles and permissions." But "non-human identity" never appears in the hero a visitor reads. It sits in the browser tab title and the Product nav dropdown. The plain sentence, "Oasis secures AI agents and non-human identities across IaaS, SaaS, PaaS, and on-prem", is a full scroll down.
Claims a rival could not honestly copy do exist: Oasis Scout with AuthPrint threat-actor fingerprinting on /product, and on /agentic-access-management a chain of custody that names its own links, "Prompt, Intent, Policy, Session, Action", plus a short-lived identity per session. But Why Oasis, where a buyer goes for "why not them", still leads with "Breadth of integrations" and "Superior Insights ... best in class". No named rival on any page, and none answers Microsoft Agent 365.
Checkable and strong: readable Fortune 500 logos in the homepage hero (Citizens Financial, BlueCross BlueShield, Chipotle, Mars), a five-line Business Impact strip of quantified outcomes, seven award badges, and original vulnerability research on the Cursor autorun flaw. Two gaps hold it here. Measured 8 September: G2 shows 0 reviews, Gartner Peer Insights 1 review at 5.0. Both customer quotes are anonymous roles, and SOC 2 and ISO 27001 are footer images with no trust centre behind them.
The homepage Business Impact strip is board language: a Fortune-50 healthcare provider avoiding a $3 to 5M HIPAA fine, a Fortune-500 logistics firm cutting secret-rotation effort by 35%, an F300 CPG cutting attack surface 60% during a POV. Procurement gets a published SLA with 99.9% uptime, service credits and severity response times, plus a DPA. Five industry pages address regulated buyers. Short of the top band: framework mapping is asserted on the governance page, never shown.
Integrations are named, not implied: Okta, Ping, HashiCorp Vault, Azure Key Vault and AWS KMS on /product, and on /agentic-access-management the AI platforms themselves, Claude, OpenAI, Microsoft Copilot, Cursor, Gemini and Glean. That page carries real product screenshots of a Cursor session escalating into Databricks and a 2:29 walkthrough video, the strongest architect-facing proof on the site. Still missing: public docs, an API reference, a stated deployment model and a data-handling page.
Two registers on one site. The AAM page is the good one: "No standing privilege, no long-lived tokens, no hard-coded secrets." The product page is where it slips, and none of it moved in ten days. Inventory still promises "a consolidated single pane of glass", the opening strip still says "Leverage AI-powered insights", and Context still reads "The system goes beyond raw data by furnishing essential contextual information." The lifecycle strip still misspells "Decomission".
Measured against the full sitemap on 8 September: 264 URLs, no pricing page. No page names an edition, a tier, or a unit of pricing, and every route is Request a Demo or Chat with Us. What is public is the contract, not the packaging: the SLA states 99.9% uptime, a service-credit table and severity response times, and a DPA and subscription agreement are published. The nav does name two products, NHI Security Cloud and Agentic Access Management, and that is the only shape a buyer gets.
Fix these first
- 1Put the searched category in the H1. Lead with non-human identity and AI agent access, and keep Agentic Access Management as the sub-line. Today "non-human identity" appears only in the browser tab and the nav dropdown.
- 2Promote the Agentic Access Management page. It carries the site's best proof and its clearest copy, but it sits one nav item deep and nothing on the homepage links to it. The homepage banner points at the Cyera post instead.
- 3Move the "why not them" answer onto Why Oasis. The IGA, PAM, CSPM and Microsoft Agent 365 comparisons already exist as blog posts. Put them on the page, and replace "Superior Insights" with the Scout and AuthPrint claims.
- 4Publish packaging without publishing prices. Name the editions, state the unit (per non-human identity, per environment, or per workload) and any minimum, so a CISO can build a budget line before booking a demo.
- 5Stand the trust signals up. Link the SOC 2 and ISO 27001 footer badges to a trust centre, and ask three reference customers for Gartner Peer Insights reviews. Measured 8 September: G2 shows 0, Gartner shows 1.

Stop losing enterprise deals on your homepage.
Generic positioning loses enterprise deals. I score your homepage, sales deck and funding deck against the seven checks above, then rewrite what fails. Buyers and investors get your value in 30 seconds.
See what you getWhat clients say
“Nikoloz provided direct and actionable feedback via assessment to help us better engage with our target audience of CISOs and security professionals. His focus on risk-reduction outcomes, and ability to reduce technical jargon, has helped us to target our messaging more effectively.”
John SkittGTM & Co-Founder at LinuxGuard“Nikoloz gave us a completely fresh, outside look at what we’re doing, how we do it, and how we’re performing. He had never worked with us, yet he nailed the CISO perspective on our positioning and our market. We didn’t expect a report this thorough, the level of detail went well beyond what we anticipated. The whole team understood it, and we’ve already started implementing the changes.”
Markus ManzkeCTO of ZeroBS/AvydosBefore we work together
- Will I work directly with you?
- Yes. I do the research, review the materials, write the findings, and join the calls. You work directly with me throughout the engagement.
- What happens on the discovery call?
- We talk through the decision or problem you need help with, your timeline, and the materials you already have. If I can help, I follow up with the work, price, and delivery date in writing.
- Can we start with one project?
- Yes. Start with a CISO Positioning Audit or a review of one company. For regular reviews and market research, we can agree on ongoing support.
- What does a technical review cover?
- I assess the demo, documentation, and other evidence available. The memo separates supported claims from questions that need more work. Hands-on testing and customer interviews are agreed separately.
- Can you sell to your network or make introductions?
- No. I have a tight-knit network of security professionals, and I want to keep it that way. I don't make introductions, and I don't sell for you. You get my judgment as a buyer and the data behind it, not a rolodex.
What do you need to decide?
Bring your product, your message, or the company you are assessing. In a free 15-minute call, we'll discuss where I can help and what the work would involve.
Need advice on one specific question? Book a 45-minute advisory call for $500.