CISOs don't want more tools. They want fewer.
Key takeaways
- Every security tool is a job to run, so a new product pitch starts from negative value until it proves otherwise.
- Security budget is replacement budget: the question in the buyer's head is what comes out of the stack if you come in.
- The current market fear is buying the wrong thing, so de-risking language beats urgency every time.
- Buyers trust narrow specialists but want to consolidate; resolve the contradiction by owning one lane and publishing your roadmap as an explicit journey.
- Calling yourself a platform hands the win to an incumbent who already says it with more evidence.
Table of contents
Every cybersecurity pitch assumes the buyer has a gap. Our webinar research, built on interviews with CISOs and senior security buyers at companies including Apple, Yahoo, and Red Hat, found the opposite. The stack is not empty. It is overflowing. The most common misconception we see founders carry into the market is the belief that a CISO is looking for one more product. They are not. Most of them are quietly looking for three fewer.
That single misreading shapes everything downstream: the homepage that lists capabilities, the outbound that promises another dashboard, the deck that positions you as an addition. To a buyer whose team is already drowning, an addition is not a gift. It is a liability with a logo.
Every tool is a job to run#
A security product is not a capability that arrives in the post. It is work. It has to be deployed, integrated, tuned, staffed, triaged, renewed, and defended at budget time. The stacks our interviewees run already bombard their teams with notifications, and every alert is a decision someone has to make before going home.
So when your pitch lands, the CISO does not hear "new capability." They hear "new job." More tools often mean more toil, and the person you are selling to is the one who owns the toil. This is why feature lists fail as persuasion. A list of things your product does is, from the buyer's chair, a list of things their team will now have to do.
The pitch that respects the buyer starts from the work your product removes, not the features it adds.
The question in the buyer's head#
Here is the uncomfortable arithmetic. Security budget is rarely incremental. It is replacement budget. When a CISO reads your homepage, the question forming behind their eyes is not "is this good?" It is "what comes out of my stack if you come in?"
If your story has no answer to that question, the buyer has to invent one, and inventing budget justifications for a vendor they met four minutes ago is not how CISOs spend their afternoons. The winning story does the work for them. It retires a line item, and it does something the retired product could not. That second half matters. Pure replacement is a procurement exercise, and procurement exercises are decided on price. Replacement plus a new result is a strategy, and strategies get sponsored.
This is also why "we integrate with everything" is weaker than founders think. Integration says you sit alongside the stack. Replacement says you shrink it. Only one of those is what the buyer actually wants.
The market's real fear is buying the wrong thing#
CISOs are professionally suspicious for structural reasons. Nobody thanks them for the ten thousand attacks their stack stopped last quarter. One miss defines a career. That asymmetry produces a buyer who is career-exposed on every purchase, and right now the fear that dominates the market is not moving too slowly. It is buying the wrong thing.
Urgency messaging reads that fear exactly backwards. Countdown energy, this-quarter pressure, breach statistics deployed as a cattle prod: all of it signals a vendor optimizing for their own pipeline rather than the buyer's safety. What outperforms it, consistently in our research, is de-risking language. Three components:
- What you replace. Name it. The buyer needs the budget story before the technology story.
- What you do not claim. Stating your limits plainly is the single cheapest credibility purchase available to an early-stage vendor, because everyone else claims everything.
- How fast they can verify. A short path to proof, a scan, a trial, a time-boxed evaluation, converts skepticism into evidence without asking for trust up front.
De-risking is not timid. It is precise. A vendor who knows exactly what they displace and exactly where their edges are sounds more dangerous to incumbents, not less.
See it in action.
The contradiction you have to resolve#
Our CISO research surfaced a contradiction that sits at the center of security go-to-market. Buyers trust narrow specialists. A vendor that does one thing deeply reads as credible, current, and safe to evaluate. But the same buyers want to consolidate, because every extra vendor is procurement overhead, another renewal, another throat to choke.
Founders usually respond to this tension by hedging. They describe their product broadly enough to look consolidation-friendly and end up sounding like everything else. The word that hedge reaches for is "platform," and in our interviews, platform and governance layer came up as dead words. Not because breadth is bad, but because an incumbent already says them, with a decade of deployments behind the claim. When a twelve-person startup says platform, the buyer does not hear ambition. They hear a category they cannot place and a claim they cannot check.
The resolution that works is sequencing, not hedging. Claim one lane with total clarity. Be verifiably the best in that lane. Then publish your roadmap as an explicit journey: here is where we start, here is what we take on next, here is where this goes. A published journey gives the consolidation-minded buyer a reason to bet on you without requiring you to pretend you are already broad. It converts "narrow" from a limitation into the first chapter of a plan.
Narrow now, with a stated direction, beats broad-sounding and unplaceable every time.
Where the story has to land#
All of this compresses into one unforgiving moment: the first seconds on your homepage. Our research found that the most common CISO reaction to startup homepages is "I still don't know what you do." Abstract benefit language fails because the same poetic sentence could describe three unrelated products. What survives is mechanism: what your product creates, what it attaches to, what happens when it finishes, and what leaves the stack because of it. We have written separately about the five-second homepage, because that is the window your replacement story gets.
There is a second audience for the same story, and it is not the CISO. Our webinar research found that the real buyer is often one level below: a practitioner who discovers you, tries you, and carries you upward, while almost every vendor aims its messaging at the CISO directly. A replacement story simple enough for that champion to repeat in a corridor conversation, this replaces X and does Y that X never could, is a story that sells while you are not in the room. Complexity does not survive being retold. Clarity does.
The discipline pays off most in crowded categories. If you are building in agentic security, where a CISO is pitched by somebody new almost daily, the fewer-tools story is close to the only story that opens a conversation, and we have covered how to stand out in agentic security in its own piece.
The instinct this asks of founders is genuinely hard: to stop presenting your product as one more thing, and start presenting it as one less. Fewer tools, fewer alerts, fewer line items, one clear lane, one published journey. The vendors that internalize this stop sounding like the two hundred others in the inbox. They start sounding like the rare one who has actually sat on the buyer's side of the desk.
That is not a messaging trick. It is a different theory of the customer. The CISO is not a gap waiting to be filled. They are an operator running an overloaded system, looking for the one vendor whose arrival makes the system smaller.

Phill Keaney-Bolland
Co-founder and Designer, Yaya
Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.