I worked at RSA when our whole conference fit inside the Fairmont on top of Nob Hill. Now it spills out of Moscone and takes over half of downtown San Francisco for a week. Cybersecurity marketing has come a long way in those twenty-plus years. The budgets are serious, the talent is the best it’s ever been, the craft is real.
Which is exactly why it’s so maddening to watch so many cybersecurity marketing teams just doing the same old same old. Coasting. Trying to shortcut their way to the top. The growth and professionalism of our industry have made winning harder. You won’t win by coasting.
Below are four of the shortcuts I see marketing teams taking and how you can escape this trap.
The elephant in the room: this is a brutal market
First, some credit where it’s due, because marketing cybersecurity today is genuinely hard. There are thousands of vendors and dozens of solution categories. Put yourself in a buyer’s shoes: limited time, a full inbox, and no reward for looking at every last option. They can’t. So they don’t.
That’s exactly why coasting is fatal here. Slap a new logo on the same old marketing playbook, and you’re just one more boat bobbing in the sea of sameness. Why would a buyer read your post, sit through your webinar, or stop at your booth?
Maybe your product is genuinely great. Product is one of the four P’s, and it matters. But great product rarely wins mindshare on its own – not when you’re up against the platform giants and a hundred well-funded startups. Place, promotion, and the positioning underneath them are where the game gets won or lost. If you fail to stand out in these areas, your company will not succeed.
Mea culpa
Before I start pointing fingers at others, let me point one at myself. I’ve tried all of these shortcuts below. I only started looking inward after I’d lived through pipeline struggles at two different companies — both in the kind of crowded, look-alike markets where nobody stands out. My mistake was assuming the plays that had worked for me before would work again. They didn’t.
Once I saw the pattern, I couldn’t unsee it. Everywhere I looked, cybersecurity marketers were reaching for the same shortcuts. Here they are, starting with the oldest one in the book.
FUD, the original shortcut
I thought we buried fear-selling a decade ago. Somehow it keeps clawing its way out of the grave. The breach-news reshares. The hacker in a hoodie, bathed in blue light, fingers hovering over the keyboard. The dramatization of nation-state actors.
Security teams hate this stuff. Worse, they resent you for it, and these are the exact people you’re trying to win over. So I’ll keep this short: stop. FUD doesn’t work. You’re burning budget and hours on it, and every time you do, you chip away at the one thing a security brand can’t buy back: trust.
Shortcut 2: Chasing the wrong person
Everyone wants to talk to the CISO. And I mean everyone. The average CISO is busy, jaded, and buried under invitations to steak dinners, bourbon tastings, and the more ascetic drink-free breakfast roundtables. You’re one more hand waving in a very crowded room.
Here’s the question coasters don’t stop to ask: is the CISO even your buyer? Sometimes they sign the PO. Sometimes they’ve delegated that call entirely. Do you actually know? If you don’t, that’s your first assignment – find out who holds the authority to buy your product, and build your outreach and content for that specific person. Stop just assuming the CISO is your buyer – the shortcut – and find out who really is.
And don’t overlook the user. A security analyst who loves your product is the best internal advocate you’ll ever get, and analysts are far easier to reach than their bosses. Yet I know plenty of companies where SDRs get no meeting credit for anyone at manager level or below. Sit with that for a second. You’re telling your door-opening team not to bother with the very people who would champion you from the inside. Fix the comp plan. Give reps credit for analyst demos.
Good GTM teams run a dual motion. One track for the champion who’ll fight for you, one for the approver who’ll sign. You need both, and they don’t respond to the same pitch.
And how do you learn what the user actually cares about? Go talk to them. Better yet, hire them. Pay practitioners as consultants, and recruit people onto your team who’ve done the job for real. At Exabeam, I had the luxury of working alongside several sales engineers who’d sat in the analyst’s chair, and I learned more from them than from any market report.
Shortcut 3: The borrowed playbook
Learning from others is fine. Steal like an artist and all that. But too many teams run the same reflex: competitor X launched a podcast, startup Y did a splashy activation, so we need one, too. Podcasts are the clearest case. They’ve run amok. Does the world need another one? Is yours actually worth an hour of someone’s commute or treadmill time? Be honest.
This year’s most borrowed play came straight from Wiz, and its followers weren’t hard to spot. Walk the floor at RSA or Black Hat, and you’ll spot them: well-funded startups, pouring venture money into big, whimsical booth builds. They were fun. I’ll give them that. But when a few founders told me what those builds cost, I visibly winced.
Wiz did bring real theater to the show floor over the years. I just don’t think the booth was ever their secret. Their secrets were great product-market fit, a product simple enough that anyone could try it, and lead magnets people actually wanted. Copy the booth, and you’ve copied the one thing that didn’t matter.
So do the opposite of borrowing: own something no one else can. Study your competitors and make a list of what they’re not doing — that empty space is your opening. For example, one frontier sitting wide open right now is AI. And I don’t mean upgrading to an AI chatbot on your website. I mean building genuinely useful AI tools for your prospects — custom prompts and utilities that do a real job for a security team. Maybe you only produce prompts and skills and forget about PDFs. Almost nobody in this space is doing it well yet. That’s exactly why you should think about doing it.
Shortcut 4: You haven’t earned the trust
“Customers will never believe our ROI numbers.” I hear that one a lot, and it’s a dodge. The real reason most vendors don’t make an ROI case is that they’ve never done the work to build one. They know their features cold, but they have no idea what job their customer is actually trying to get done, much less how much time or money you have saved them.
Falling back on features and functions is the shortcut (and it’s not limited to cyber product marketing managers). If you can’t describe your product’s value simply, in terms that make sense to your customers, you haven’t earned the right to their attention — let alone their budget.
This year’s NOLA Marketing/Ponemon survey of cybersecurity buyers backs this up: Almost half of buyers (49%) said vendors can’t give them a good answer on ROI.
So do the unglamorous work. Have product marketing map the user’s current-state process, step by step. How long does each step take? What tools do they touch? What does it cost them in time, money, and aggravation? Then lay your product’s after-state right next to it, side by side. If your value is risk reduction, go sit with CISOs and CFOs and learn how they think about risk — how they explain it to a board — and then use their language instead of yours.
This is straight out of The Challenger Sale: teach the customer something about their own business they didn’t already know. Run a value-engineering workshop. Build an ROI model you’d be willing to defend to a skeptical CFO. I’d bet 90 percent of cybersecurity companies have never done this work. Your competitors won’t bother, so you should.
And here’s a trap to sidestep: don’t try to buy the trust. Anyone can license an analyst’s report. That’s rented credibility. Own it instead. Proprietary research and a real ROI methodology give customers something they can’t get anywhere else. That’s the whole point.
Stop coasting
None of this is complicated. It’s just hard. And hard is the point — the work your competitors skip is the exact work that sets you apart. Coasting is a losing strategy. Start pedaling.
Where are you seeing the sea of sameness in cyber marketing? Tell me in the comments — I’m collecting examples.
Want to learn even more about marketing?
Leave a Reply