Stage 1

Hypotheses for cybersecurity services

How to write a misery hypothesis when you sell cybersecurity services, without fear tactics. Where to look, what to guess and an example opener.

Kevin French
· 3 min read

Security buyers are the most pitched people in the enterprise. And nearly every pitch they get runs on fear.

A hypothesis runs on something else. It runs on knowing what their week actually looks like.

Why fear stopped working

Every security vendor leads with the threat. Ransomware, breaches, the attack that hit a peer last month. The CISO knows all of it better than you do. They read the same reports and they sit in the same peer groups.

So a fear pitch tells them nothing new. It just tells them you're one more vendor trying to scare a budget out of them.

What they don't hear often is someone who understands the operational grind. The tool that never got fully deployed. The audit finding that keeps coming back. The team that's two people short and burning out. That's where your hypothesis belongs.

Where to look

Start with the public record. The 10-K has a cybersecurity section now, and the risk factors often describe the program in more detail than you'd expect. Look for language about governance changes, new reporting lines or a program being built out. If the company disclosed an incident, read what they said about remediation.

Job posts tell you where the gaps are. A company hiring a security architect, three SOC analysts and an identity engineer at the same time is building something and can't staff it. A posting that names a specific platform tells you what they've already bought.

Then the people. A new CISO is one of the strongest signals in this space. There's more on that in new CISO, new priorities. Watch what security leaders post and which events they attend. Someone speaking about zero trust has a zero trust program with their name on it.

And the market. A breach at a direct competitor puts every board in that industry on alert. That's a real trigger, but use it carefully.

Four hypotheses that tend to land

The staffing gap. They're hiring and not filling seats. Your guess is that the team is covering alerts at the cost of the project work they were hired to do.

The half-deployed tool. They bought a platform and it's running at a fraction of what it can do. Your guess is that the deployment stalled when the integration got hard.

The audit loop. The same findings come back every year. Your guess is that the fixes depend on teams outside security who don't prioritize them.

The board question. The board is asking for a clear view of risk. Your guess is that the CISO is building that view by hand from a dozen tools every quarter.

An example

Say a mid-sized regional bank posts for an identity and access engineer, two SOC analysts and a GRC manager in the same month. The 10-K describes a new reporting line from the CISO to the board's risk committee.

The 10-K shows your role now reports to the board's risk committee, and you're hiring across identity, the SOC and GRC at the same time. That's a lot of new visibility and a lot of open seats at once. My guess is the board wants a clear view of risk each quarter and a short-staffed team is assembling it by hand. Is that accurate, or is the bigger pressure somewhere else?

Read it back. No fear. No breach statistics. No claim to stop every attack. Just the job they actually have.

Write to the rest of the team

The CISO is usually the economic buyer. But security work runs through other people.

The champion is often a security operations or GRC manager carrying the day-to-day load. Write to them about the workload. The technical lead might be a security architect or an infrastructure head who'll own the integration. Write to them about the platform. If the hypothesis is about board reporting, the CFO or general counsel might care too.

There's more on the CISO's world in selling to a CISO.

What to leave out

Leave out breach headlines. Leave out the line about it not being if but when. Leave out the claim that you'll make them secure.

Name what you found in their filing or their job posts. Guess at the grind behind it. Let them tell you what's really keeping them busy.

See which of your accounts are moving.

Stage 1 reads your site, finds accounts that fit and checks their filings and news. Your first Board in about two minutes. Free for 14 days, no credit card.