Nobody wants to book your demo

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya6 min read

Key takeaways

  • Only 42% of the 77 startups we scored give visitors anything of value before asking for their contact details.
  • Visitors arrive cold, warm, or hot, and only the smallest group ever books a demo.
  • Security is bought as an experience good: self-serve trials, free scans, product tours, and no-strings POCs outperform demo-only websites.
  • Never gate a case study; the person reading it is evaluating you.
  • Cold outbound is negative-yield in a small community that talks.

Count the doors on a typical cybersecurity startup website. There is usually exactly one: book a demo. It sits in the header, anchors the hero, and repeats down the page like a chorus. When we scored the 77 startups exhibiting at RSA's Early Stage Expo and Next Stage for our Cult Products Awards report, the pattern held across the category. Most marketing activity aims at the very end of the buying journey, the demo booking, and only 42% of the startups offer anything of genuine value before asking for contact details.

The uncomfortable truth is that the door almost nobody wants to walk through is the only one on offer.

The first date problem#

For our webinar on why CISOs don't want to talk to you, we interviewed CISOs and senior security buyers at companies including Apple, Yahoo, and Red Hat. One finding came through with total consistency: they do not want to book your demo. People hate meetings. They hate being sold to. They hate handing over their details, because they know exactly what happens to details.

It is a bit like going on a first date and immediately asking the person to marry you. You would not do that in person, so why is it the first and only thing your website asks of a stranger?

A demo is not a small request. It asks a busy, professionally suspicious person to give up half an hour, sit through a pitch, and enter a sales process before they know whether you are even relevant to them. Our CISO research is blunt on why that lands badly. CISOs are career-exposed. Nobody thanks them for the ten thousand attacks their stack stopped, and one bad purchase can define a career. The current market fear is buying the wrong thing. An early meeting request reads as pressure, and pressure reads as risk.

Cold, warm, and hot visitors#

Visitors arrive at your website in one of three states.

Cold visitors know they have a problem. They do not yet know what can fix it, and they have never heard of you. Warm visitors know the problem and the kinds of products that address it, but they do not know you. Hot visitors know the problem, the options, and you. They are close to a decision.

Only the smallest of these three groups will ever book a demo. A website whose only destination is a demo form serves the hot group and turns everyone else away, which is exactly what our awards research found the category doing: aiming nearly all activity at the small minority ready to buy now, while ignoring the much larger group who are not ready yet.

That larger group is not a rounding error. It is next year's pipeline. Serve each temperature with something useful, because in this market you must give before you get.

Each state has a matching gift. Cold visitors need education: name their problem clearly, show them the ways it can be fixed, and teach them something they can use whether or not they ever buy from you. Warm visitors need evidence: how your approach differs from the category they already understand, what it would replace in their stack, and proof it works in an environment like theirs. Hot visitors need friction removed: pricing they can find, a trial they can start, and yes, a demo button. The mistake is not having a demo. The mistake is offering nothing else.

Security is bought by touching it#

Security is bought as an experience good. Buyers cannot evaluate it from a brochure or a slide deck. They need to touch the product and watch it behave in something like their own environment. In our CISO research, the vendor motions that earned the most praise were all versions of letting the buyer experience the product on their own terms:

  • A self-serve 30-day trial, deployable across the whole organization, startable in five minutes without talking to a human.

See it in action.

  • A low-friction scan as the primary call to action, with "talk to us" as the quieter secondary option.
  • A short product tour video in the how-it-works section, so a visitor can see the product without booking anything.
  • A no-strings, time-boxed proof of concept that ends with a findings report the buyer keeps either way.

Notice what these have in common. Each one hands the buyer evidence and control. Each one lets them verify your claims quickly, privately, and without entering a sales process. De-risking beats urgency with this audience: say what you replace, say what you do not claim, and show how fast they can check for themselves.

Build the buying journey the buyer wants: evidence first, commitment later.

The champion does the selling#

There is a second reason self-serve motions win, and it is about who actually buys. Security purchases are increasingly bottom-up. A practitioner discovers you, tries you, and becomes your champion. The CISO gathers consensus and signs, and finance forms its own view of you from your website. The real buyer is often one level below the CISO, yet almost every startup aims its website squarely at the CISO and puts the product behind a sales call the practitioner never wanted to have.

A demo-only site makes the champion's job harder at every step. They cannot try the product without inviting a salesperson into their evaluation. They cannot forward proof that sits behind a form. The self-serve trial, the scan, and the tour are the tools your champion uses to sell you internally when you are not in the room. Design for the person doing your selling, and make sure everything they need travels well when forwarded.

Never gate a case study#

A special mention for a self-inflicted wound: the gated case study. Someone reading a case study is not a casual browser. They are evaluating you. They are looking for proof that you have done this before, for a company like theirs. Putting a form between that person and the proof stops them at the precise moment they are trying to convince themselves to buy from you. Give the case study away. The reader is doing your selling for you.

Cold outbound digs the hole deeper#

If demo-first websites underperform, demo-first outbound is worse. In our CISO research, cold outbound consistently came out as negative-yield. It does not merely fail; it costs you future revenue. A former CISO told us about a vendor whose clever, sarcastic follow-up message genuinely landed. As an opener, it would have worked. It arrived after six canned, automated messages, and by then the deal was dead permanently.

The security community is small and it talks. Peers and word of mouth are the real channel, and you rarely get a second attempt with a buyer you have annoyed. Every automated sequence you send is spending trust you have not yet earned.

Give before you get#

None of this means deleting the demo button. It means demoting it. The demo becomes one door among several: the right one for the small hot group, while the scan, the trial, the tour, and the ungated proof serve everyone else. Each free, useful thing a visitor takes from your site moves them one temperature warmer, on their schedule rather than yours.

The same logic extends beyond the product. Buyers of early-stage products get comfortable with the people behind them as a proxy for the product's maturity, which is why your team page is a security control. And increasingly the first evaluation happens before anyone reaches your site at all, when an AI model decides whether to recommend you.

Ask one question about every page on your site: what does a visitor get here without giving anything? If the honest answer is nothing, you have built a website for the smallest group of buyers you have, and left the rest at the door.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

  • Website

    Buyers of early-stage security products know the product is immature. They get comfortable with the people instead. A missing team page is a hole in the buying journey.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • CISOs and buyers

    Justin Woody planned 100 buyer conversations for Twine and did 250. Nearly all of them pointed at a different problem, and the company pivoted before writing code. Here is how validation actually works.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Brand

    Cybersecurity founders want to stand out and fear standing out. Both instincts are right. There is a working test for where the line sits, and it involves your champion's CFO.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Brand

    Founders debate launch timing endlessly: before or after the raise, before or after the product feels ready. There is no perfect moment. There is a market calendar, and it should set your date.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Website

    Buyers describe a use case to an LLM and get a shortlist of three to five names. How security startups earn a place on it, and why the answer runs through a website you own.

    Phill Keaney-Bolland

    Phill Keaney-Bolland