How bold is too bold? The CFO-forward test
Key takeaways
- In our Cult Products Awards report, the outliers among 77 RSA startups increased their trustworthiness by taking risks, not despite taking them.
- If you get no reaction, you are forgotten: nobody can hum the Avengers theme because it is exactly what you would expect.
- The ceiling is real: a security-focused VC has watched deliberately irreverent brands create measurable go-to-market drag in consensus-driven buying.
- The working test is whether your champion can forward your website to a finance stakeholder without wincing.
- Boldness must trace to a real differentiator and fit the team; playfulness imposed on researcher-founders reads as fake.
Table of contents
Every cybersecurity founder we meet holds two instincts at once. The first: we have to stand out, because the category is a sea of sameness and we are drowning in it. The second: we cannot afford to stand out too much, because our buyers are the most professionally suspicious people in software and one wrong note could cost us the deal. Founders usually assume one instinct must be wrong. Neither is. The interesting question is not whether to be bold. It is where the ceiling sits, and it turns out there is a working test.
The case for bold: forgettable is the expensive option#
Start with the evidence for boldness, because it is stronger than most founders believe. When we scored the 77 startups exhibiting at RSA's Early Stage Expo and Next Stage for our Cult Products Awards report, the companies that stood out were not trading credibility for attention. The outliers increased their trustworthiness by taking risks. Confidence in the brand read as confidence in the company; a strong, distinctive presence signaled a team that knew exactly what it was and was not apologizing for it. The crowded middle, well executed and interchangeable, earned no such credit. We wrote up the full pattern in security brands all sound the same.
Which points at the real cost most founders never price in: the cost of no reaction. Here is the test we use in creative reviews. Try to hum the Avengers theme. Almost nobody can, from a franchise with billions in box office, because the music is exactly what you would expect and nothing more. Now try Game of Thrones. Everyone can. One composition took a risk and lodged itself in memory; the other was competent and evaporated. Brands work the same way. If you get no reaction, you are not being safely neutral. You are being forgotten, and forgotten does not make shortlists. Our own line for it: Marmite, not butter. Butter offends nobody and nobody has ever crossed a street for it.
It can be very risky not to be bold. Safe and forgettable is a risk; it just sends the invoice later.
The ceiling is real: what irreverence costs in the room you are not in#
And yet the founders' second instinct, the fear, is grounded in something real too. In our research, a security-focused VC who has watched many portfolio companies go to market described watching deliberately irreverent brands create measurable go-to-market drag. Not a vague chill. Slower cycles, harder internal advocacy, deals that leaked energy at every approval step. The detail that should stop every founder mid-rebrand: a CISO privately asked whether presenting that vendor internally would be embarrassing.
Understand why that question is fatal, because it is not about taste. Security buying is consensus-driven. A practitioner champion discovers you, but the CISO gathers agreement across engineering, legal, procurement, and finance before anything is signed, and your materials travel through that whole chain without you in the room. Your website gets forwarded to a CFO who forms an opinion in seconds, and that CFO is not your audience, shares none of your industry's in-jokes, and controls the money. A brand that delights practitioners but makes your champion hesitate before forwarding it upward is not bold. It is friction wearing boldness's clothes, and you will never see the deals it costs you, because they die quietly in rooms you were never invited to.
The test: can your champion forward you to finance without wincing#
So here is the line, stated as a test you can actually run. Pull up your homepage and imagine your best internal champion, the practitioner who loves you, about to forward it to their CFO with a note saying "we should look at this." Can they hit send without wincing?
If yes, whatever boldness you have is inside the ceiling, and you almost certainly have room for more. If they would hesitate, add a caveat to the email, or send a sanitized deck instead of the site, the brand is creating drag exactly where you can least afford it. Notice what the test does not ask. It does not ask whether the CFO will love the brand, laugh at it, or remember it. It asks only whether the brand survives being forwarded to someone who is not its audience. Survival is the bar. Delight is for your actual buyer.
See it in action.
The test also exposes the false binary founders bring to this conversation: that the choice is between bold-and-risky and safe-and-dull. The real spectrum runs from forgettable through distinctive to embarrassing, and the profitable zone, distinctive, is wide. Most cybersecurity brands fail it from the forgettable side, as the category's own websites demonstrate. The irreverent failures are rarer; they are just more visible, which is why they dominate the cautionary tales.
Bold must trace to something, and it must be yours#
Two qualifiers keep boldness on the right side of the line, and both are about honesty rather than volume.
First, boldness must trace to a real differentiator. Bold for bold's sake is decoration, and buyers metabolize it as noise within a quarter. The question to ask of every daring choice, visual or verbal, is what truth about the company it expresses. A genuinely contrarian product philosophy can carry a contrarian brand. A distinctive founding story can carry a distinctive voice. If the boldness expresses nothing, it is a costume, and costumes read as costumes.
Second, boldness must fit the team who will live it. In the same research that surfaced the VC's warning, another pattern: playfulness imposed on researcher-founders reads as fake, and security buyers are professionally suspicious of fake. A team of quiet ex-agency researchers fronted by a jokey mascot brand is a mismatch every buyer can feel in the first meeting, when the website's voice and the founder's voice fail to be the same voice. Boldness has more registers than humor. Precision is bold. Total conviction is bold. Naming the uncomfortable truth in your category is very bold. The right register is the one the founders can sustain in person, on their worst day, in front of a skeptical room.
How we draw the line in practice#
Two mechanisms turn all this from judgment calls into process.
The first is the archetype cocktail. Rather than choosing one brand archetype from the classic twelve, we build a weighted mix of about three. Cybersecurity gravitates to the Sage by default, the expert who knows, which is why the category all sounds the same; the Sage alone produces whitepapers in a trench coat. The interesting work is pairing Sage trust with something bolder, in proportions the team can actually inhabit. The weighting is the safety mechanism: enough Sage to carry the CFO-forward test, enough of the bolder note to be remembered at the peer dinner. When we ran the archetype exercise with Geordie, it moved their messaging from fear-led to Caregiver-led empowerment, bold as a category position precisely because everyone else was selling dread. Henry Comfort put the choice plainly on our podcast: "You can talk a lot about fear. You can talk a lot about risk. You can talk a lot about uncertainty or doubt. But actually, there's so much opportunity in this field."
The second is a rule about roles in creative review. It is the creative team's job to go too far, and the business's job to draw the line. Both halves are load-bearing. If the creative work never crosses the line, you have no idea where the line is, and you end up parked in the forgettable middle by default, having never tested the boundary. The nightmare outcome of a review is not a client saying "too far." Too far means the edge is now mapped, and one step back from it is exactly where a brand should live. The nightmare is a client saying you did not push far enough, because it means the whole exploration happened inside the safe zone and the money bought no information at all.
Which returns us to the founders' two instincts. Stand out: correct. Fear the edge: also correct. The resolution is not a compromise between them. It is a sequence. Go too far deliberately, find the edge, then govern the result with one question: would your champion forward this to finance without wincing? Ship the boldest thing that passes.

Phill Keaney-Bolland
Co-founder and Designer, Yaya
Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.