Buyers of early-stage security products know the product is immature. They get comfortable with the people instead. A missing team page is a hole in the buying journey.
Phill Keaney-Bolland
Ask a cybersecurity founder who their product is for and the answer usually starts specific and ends broad. "Security teams at mid-market SaaS companies. Although honestly, anyone with a cloud footprint could use it." The second sentence feels safe. It is the expensive one.
The fear underneath it is rational. Narrow the ideal customer profile and the addressable market on your fundraising slide gets smaller. Every instinct says keep the doors open, because you do not yet know who will walk through them. At startup scale, that instinct is wrong. The narrow niche is not the risk. It is the only affordable way to matter.
Start with the mechanism. When a buyer can line you up against four competitors and compare feature for feature, the comparison happens, and it resolves the way comparisons always resolve: on price. In our webinar research with CISOs and senior security buyers, the pattern was blunt. Undifferentiated brands get commoditized, and commoditization erodes margins. Not slowly, and not only at renewal. It shows up in the first negotiation, when procurement asks why you cost more than the vendor whose website says the same things yours does.
Broad positioning guarantees this outcome. If you claim to serve everyone with a cloud footprint, you have volunteered to be compared with everyone who makes the same claim, which in cybersecurity is a very long list. The category's own sameness makes it worse. When we scored the 77 startups exhibiting at RSA's Early Stage Expo and Next Stage for our Cult Products Awards report, we found a crowded middle tier: companies executing well, saying similar things, in a similar register, and blending into one another. Well executed and undifferentiated is still undifferentiated.
If buyers can compare you, they will, and the comparison ends at price.
Here is the arithmetic that makes niching a commercial decision rather than a branding preference. Becoming the obvious choice costs money: content, presence, repetition, the slow accumulation of recognition among a defined group of buyers. An incumbent can afford to run that play across an entire category. You cannot. You can afford to run it for one narrowly defined buyer with one urgent problem.
That is the real trade. Broad positioning buys you a faint presence everywhere. Narrow positioning buys you a strong presence somewhere, and somewhere is where deals happen. The smallest commercially viable niche, small enough to dominate on your budget and large enough to sustain the business, is not a compromise. It is the entry strategy. You expand later, from a position where a group of buyers already treats you as the default answer to their problem.
There is a wrinkle from our CISO research worth naming, and we go into it properly in CISOs don't want more tools. Buyers trust narrow specialists and simultaneously want to consolidate. The resolution is not to fake breadth: claim one lane with total clarity, be the best at it, and be honest about where the roadmap goes next.
Niching down tells you how big to aim. It does not tell you where. For that, the most useful exercise we run with founders comes from Blue Ocean thinking. Map what every competitor in your space emphasizes: the capabilities they lead with, the proof points they repeat, the language they share. Then work through four moves. What can you eliminate that the category treats as mandatory? What can you reduce below the category standard? What can you raise well above it? What can you create that no one offers at all?
The point of the exercise is not a longer feature list. It is to find the gap where comparison becomes impossible, the position from which a buyer cannot line you up against the alternatives because you are not playing the same game. Figma is the clean public example. The market leader in design tools was not prioritizing real-time collaboration. Figma made it the center of the product, became impossible to compare on the incumbent's terms, and eventually displaced it. The lesson is not "copy Figma." The lesson is that the winning position was sitting in plain sight, in the gap between what the category emphasized and what users actually needed.
A common objection at this point: "but buyers require X, so X has to be front and center." Sometimes the first half is true and the second half is not. Every category has table stakes, the capabilities a product must have to be taken seriously. In security that list is long: integrations, discoverability of assets, reporting, the compliance checkboxes. You must have them. You must not build your story on them, because everyone has them, and a story everyone can tell is not a story. It is background noise.
The discipline is to separate the two lists. One list is what gets you past the technical evaluation. The other is the single thing that makes you the obvious choice for your niche, the thing you say first, loudest, and everywhere. When those lists get mixed, the homepage turns into an inventory and the buyer leaves without a reason to remember you. We wrote about the cost of that in the five-second homepage: you get seconds to land who you are for and why you are different, and table stakes never land it.
There is now a second audience for your positioning, and it is even less patient with vagueness than a CISO. When Deepak Gupta of Grakka joined our podcast to talk about answer engine optimization for cybersecurity, he described how security buyers actually use LLMs. They do not ask for a category. They describe a use case in context: a company of this size, a team of this shape, this specific problem, give me the top options. The engine returns three to five recommendations. "You are not getting 20, 30 links and you don't want to waste your couple of hours doing research," as he put it. Not twenty links to work through. Three to five names.
Think about what that selection step does to generalist positioning. An LLM asked for the best option for a precisely described buyer is matching claims against context. The vendor that claims to serve everyone matches nothing precisely, and a vendor that matches nothing precisely does not make a three-name shortlist. Gupta is blunt about the alternative: "You cannot just say that I'm serving every single company, every single industry... You have to have a specific niche in mind." The niche you feared was limiting is exactly what the machine needs to recommend you. His other warning matters here too: the website is still the front door, and if the messaging fails when a human clicks through, the recommendation is wasted.
This is not a future problem. Different engines cite different sources today, and enterprise buyers are often already asking Copilot. We cover what this means for the most crowded category of the moment in how to stand out in agentic security.
Machine-readable positioning is narrow positioning. There is no generalist answer to a specific question.
The method we use to turn all of this into a working value proposition has five steps, and the order matters.
Every part of that sentence does work, and the last clause is the one founders skip. If "unlike everyone else" is empty, the rest is a commodity description with better grammar.
The founders who resist this usually resist it because niching feels like settling for less. It is the opposite. A category of one is the largest position available to a company your size: one hundred percent of a market you define, instead of a rounding error of a market someone else owns. It is not about being better than everyone else. It is about being different by design.

Phill Keaney-Bolland
Co-founder and Designer, Yaya
Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.
The latest news, technologies, and resources from our team.
Buyers of early-stage security products know the product is immature. They get comfortable with the people instead. A missing team page is a hole in the buying journey.
Phill Keaney-Bolland
AI for security, security for AI is now the default pitch. Differentiation in the most crowded corner of the market lives one level down, in philosophy, refusal, and story.
Phill Keaney-Bolland
Justin Woody planned 100 buyer conversations for Twine and did 250. Nearly all of them pointed at a different problem, and the company pivoted before writing code. Here is how validation actually works.
Phill Keaney-Bolland
Cybersecurity founders want to stand out and fear standing out. Both instincts are right. There is a working test for where the line sits, and it involves your champion's CFO.
Phill Keaney-Bolland
Founders debate launch timing endlessly: before or after the raise, before or after the product feels ready. There is no perfect moment. There is a market calendar, and it should set your date.
Phill Keaney-Bolland
Buyers describe a use case to an LLM and get a shortlist of three to five names. How security startups earn a place on it, and why the answer runs through a website you own.
Phill Keaney-Bolland