As a mentor for 2 different incubator programs, I’ve been seeing and evaluating a lot of pitches this week and last. Office hours and demo day for ICE71. Mentor matching for MassChallenge. And then the past 20+ years of being pitched to by security vendors.
And there is one thing that I want to address. In maybe half of the pitches that I’ve seen, the presenter mentions a very public data breach, by company name, as an example of what their technology could solve. Or in the most egregious cases, they say directly “Don’t be the next .” I know one person who shall remain nameless, but they have a career of 60-minute conference presentations where it’s just the logos of companies that had a data breach and nothing else. No lessons learned other than “buy stuff from us”.
And deep down inside, I want to scream and slap them silly. I don’t do it of course, but still….
I understand why you would want to name companies and data breaches. It adds a concrete example to what your solution protects against. It’s timely because of the news. It’s a great hook to get people interested in what follows. It helps non-technical people understand where your security solution fits into their world. It could create awareness in prospects that a problem exists. If you’re talking to VCs, they sometimes need a little bit overt showmanship to get excited enough to give you the next seed round.
It’s also a lazy attempt at spreading Fear, Uncertainty, and Doubt, or FUD.
And more importantly, when you talk to a CISO or other IT security buyer, it has exactly the opposite effect than what you intended. That is, they put you into their mental list of “bozo salespeople”. They wonder if you’ll start throwing their name around on your slides in the future. If they like your company, they’ll find another account team. If they don’t, then they’ll just add you to the denylist of vendors and ghost you.
When you get lazy and spin FUD, it’s actually counterproductive.
Of course, there are some alternatives to this approach that work much better:
- Make the conversation more about the technique, not the victim. Then you can talk about how you detect/block/recover from that technique. The victim’s name doesn’t really matter. Neither does a very large retail chain or however you want to name the victim without explicitly naming them.
- Use your executives like CSO and CTO. This conversation is highly nuanced, and these folks have the best instincts to be talking to customers. Unfortunately, they don’t scale, so you sometimes have to use marketing and PR channels to broadcast your executives to reach a larger audience.
- Combine several data breaches with the same technique into a synthesized target profile. IE, “Across all of the retail customers that we have, we have observed that….”
- Talk about the attacker and their typical methods and capabilities. With some of the more common attackers or attacker groups and thanks to MITRE ATT&CK and some of the other frameworks, we have models for how to do this.
Published on February 14, 2021.
Last Updated on 6 months ago.
