Skip to content

Stop Chasing Reach: Why Niche Influence Matters More in Cybersecurity

As a cybersecurity start-up or scale-up you don't need everybody to know your name. You need the right people to keep encountering it for the right reasons.

Photo by Jonathan Gong / Unsplash

The recent LaunchPad and CYBR.SEC.CON events got me thinking - there are many examples in the lifetime of a cybersecurity company when the quality of your connections will pay more dividends than chasing fleeting mass spotlights.

There was a time when technology marketing seemed relatively straightforward. Build awareness, generate leads, get prospects in front of sales, and explain why your product was different.

However, people don’t buy technology like that anymore. They haven’t for the last 10 years.

By the time a cybersecurity buyer picks up the phone to a vendor, they have already researched options, looked at competitors, read reviews, asked colleagues, followed conversations on Reddit, visited specialist sites and perhaps listened to a podcast or two. Gartner recently found that 67% of B2B buyers now prefer a rep-free buying experience, and research from TrustRadius found that more than half of all technology buyers seek information from former colleagues or known peers. We trust people we know more than the vendor claims, and we trust the people who really know more than generalist commentators.

The bottom line is that the customer has already made 80% of the buying decision before you even know they exist.

How do you influence someone you don’t know exists?

The instinctive response from companies is speak more loudly – make more announcements, chase more PR coverage, find more stuff to talk about. And maybe if you are a larger, established cybersecurity brand you can afford to invest in that. But that old school approach misses the fundamentals of today’s buyer behavior.

Buyers are drowning in vendor noise and competing approaches, and in response are narrowing the circle of people and sources they trust. The influence that once sat with a relatively small number of large media and analyst houses has become fragmented across hundreds of smaller communities and sources.

The right audience beats the biggest audience

In cybersecurity you can’t be all things to all buyers in all situations, so businesses have to decide where and how to show up to build a reputation and relevance before the customer starts to actively look for it.

A specialist cybersecurity publication will reach CISOs, security architects, researchers, investors, potential partners and other journalists who are already interested in the subject. A purple team podcast might only have a few thousand regular listeners, but they return precisely because it discusses a problem they care about. A respected DFIR analyst might have a modest Substack following but enormous credibility among the people who make decisions in your particular corner of security. Participate intelligently in discussions in as many relevant places as you can without immediately trying to sell something, and six months later when someone has the problem you solve, they search the category and encounter you again. Except this time you aren't an unknown company asking for their attention. You are a name they recognize from places and people they already trust.

This is particularly important for small cybersecurity companies because you begin without the reassurance that comes with an established brand. Your prospective customer is not simply evaluating the product, consciously or otherwise they are accumulating evidence that your company is credible enough to consider.

Breaking through the chaos of BlackHat or competing for column inches in the big tech papers is not really an option for the smaller company, so be smart about how you get noticed by the people who matter.

Rethink what tier 1 means to you

Specialist or niche media, engaged communities, customers and influential practitioners can all contribute to your credibility.

These are your tier 1 targets – not the Wall Street Journal, or even PC Mag. Pester your PR team for coverage in the WSJ and big tech media when you have a financial or business story for a mass audience, not when you are still building your reputation and relevance to your buyers.

This doesn't mean that major media coverage has stopped being valuable. A significant story in a traditional tier 1 publication can introduce a company to an enormous audience and confer credibility that is difficult to reproduce elsewhere.

The mistake is treating it as the only coverage that really counts. Treat it like that big customer you unexpectedly won, fantastic for evidence of success, but a single point of evidence that won’t sustainably grow your business (or in this case your reputation).

For an emerging cybersecurity company, becoming known within to a relatively small audience through niche media can be far more beneficial to business growth than briefly becoming visible to a very large audience of non-buyers. The niche communities contain the people who recommend technologies, influence buying groups, advise their peers and help determine which new companies deserve further attention.

There is a fitting lesson in the history of CYBR.SEC itself. What became today's much larger community began in Houston with around 120 people, rooted in local security user groups. Its value allowed it to scale and diversify into other community connection events such as CYBR.SEC.CON and LaunchPad, not the depth of its pockets nor its prime time news coverage.

As a cybersecurity start-up or scale-up you don't need everybody to know your name. You need the right people to keep encountering it for the right reasons.

Latest