Why Fear-Based Selling Fails in Cybersecurity | Braintrust
Home Blog Fear-Based Selling in Cybersecurity
Behavioral Neuroscience & Selling

Why Fear-Based Selling Stops Working in Cybersecurity

A security operations analyst at a dim desk facing a wall of repeating red threat alerts, leaning back from the screens with an unimpressed expression.
Zach Strauss
Zach Strauss
Chief Marketing Officer, Braintrust
9 min remaining
Zach Strauss
Chief Marketing Officer, Braintrust

About

Zach Strauss is the Chief Marketing Officer at Braintrust, a communication skills-based growth consulting firm focused on sales performance and leadership development. He partners with revenue leaders at enterprise organizations to translate how the brain actually decides into marketing and revenue systems that move the number.

Experience Highlights

  • Go-to-market strategy for neuroscience-based training
  • Demand generation built around buyer psychology
  • Content and positioning for complex enterprise sales
  • Revenue operations across marketing, sales, and enablement

Areas of Expertise

NeuroSelling Revenue Strategy Sales Enablement B2B Demand Gen Content Strategy Buyer Psychology GTM Systems Behavior Change

A cybersecurity field team opens the way it has opened for six years. Breach statistic. Threat landscape slide. A dollar figure attached to what happens if the buyer does nothing. Two years ago that sequence produced a second meeting. Now the CISO listens politely, says the roadmap is set through Q3, and the opportunity turns into a no-decision that nobody can quite explain in the pipeline review.

Sales enablement leaders at cybersecurity vendors are watching this happen across whole teams at once, which is the tell. When one rep's numbers slide, it's a rep problem. When threat-led pitches stop converting across the board, the message didn't get worse. The audience changed.

Cybersecurity has spent a decade industrializing fear as a go-to-market motion, and the buyers it aims at have adapted the way any nervous system adapts to a signal that fires constantly and predicts almost nothing. What replaces fear is not softer messaging. It's a different variable entirely, and the research on fear appeals identified it decades ago.

Why cybersecurity needs a different approach

Plenty of markets overuse urgency. Cybersecurity is structurally different in five ways that change what a rep actually has to do in the room.

The buyer is professionally desensitized. A security practitioner processes threat language as a job function, all day, every day. In Vectra AI's 2024 State of Threat Detection and Response research, 81% of SOC practitioners said they spend more than two hours a day triaging security events, and practitioners reported they can realistically deal with only 38% of the alerts they receive. Of the alerts that arrive, they classify roughly 16% as real attacks. This is a buyer whose working environment has already trained them to discount threat signals at scale. Your opening slide enters a channel that is saturated and already discounted.

38%
The share of incoming alerts SOC practitioners say they can realistically deal with. Threat signal is not scarce in this buyer's world. Attention is. Source: Vectra AI, 2024 State of Threat Detection and Response.

The buyer is also being sold to constantly. One 2026 analysis of security buying published on Security Boulevard reported that CISOs receive roughly 60 cold outreach attempts a week and reject most within about five seconds. Five seconds is not evaluation. It's pattern recognition. If your opening looks like the other 59, it gets sorted before anyone reads the claim.

Budget is tighter than the threat narrative implies. The IANS Research and Artico Search 2025 Security Budget Benchmark Report, based on 587 CISOs surveyed in April 2025, found security budgets grew 4% year over year, down from 8% the prior year and the lowest rate in five years. Security spending as a share of total IT spend fell from 11.9% to 10.9%. Only 11% of CISOs described their teams as adequately staffed. Raising the perceived size of the threat does not create budget in that environment. It creates a buyer who feels worse and still cannot act.

Compliance and the board are the real forcing functions. Splunk's CISO Report 2025 found 83% of CISOs participate in board meetings somewhat often or most of the time, and it surfaced a revealing split: 15% of CISOs ranked compliance status among their top performance metrics, compared with 45% of board members. The person you are selling to and the body that approves the spend are measuring different things. Audit findings, framework deadlines, and cyber insurance requirements move money on a calendar. Ambient dread does not.

The committee is large, and each member has a different fear. Gartner's research on complex B2B purchases puts typical buying groups at six to ten decision makers. In a security deal that means a CISO, a security architect, an IT operations lead, a procurement analyst, a legal or privacy reviewer, and a business sponsor, each of whom would answer "what's the risk here" differently. A single threat narrative aimed at the CISO leaves five people with no reason to advocate for you internally.

What fear appeals actually require to work

The most useful research here is not new, and it did not come from sales. It came from public health, where researchers spent decades studying why some frightening messages change behavior and most produce nothing at all.

Kim Witte's Extended Parallel Process Model, introduced in Communication Monographs in 1992, describes what happens when a person encounters a threatening message. The brain runs two appraisals, not one. First, threat appraisal: how severe is this, and does it apply to me? Second, efficacy appraisal: is there a response that actually works, and can I personally carry it out?

The second appraisal decides everything. When perceived threat is high and perceived efficacy is also high, people enter danger control. They engage with the risk, evaluate the recommendation, and take protective action. When perceived threat is high and perceived efficacy is low, people enter fear control. They manage the feeling instead of the risk, through avoidance, denial, defensive dismissal, or reactance against whoever delivered the message.

Under fear control, the buyer is not solving your problem for you. They are solving their discomfort, and the fastest way to do that is to make you go away.

Witte and Allen's meta-analysis of 98 fear-appeal studies, published in Health Education and Behavior in 2000, confirmed the pattern and added the warning that matters most to anyone building a pitch deck: strong fear appeals should be used cautiously, because they backfire when the audience does not believe it can effectively avert the threat.

Now apply that to a security buyer's actual situation. Threat perception is already at ceiling. There is no headroom left, which is why bigger numbers do nothing. Efficacy is where all the variance lives, and efficacy in this market is genuinely low. The buyer already owns a great deal of tooling. In the same Vectra research, 73% of SOC practitioners reported more than 10 security tools in place and 45% reported more than 20, while 47% said they do not trust their tools to work the way they need them to. IBM's 2025 Cost of a Data Breach Report put the average breach lifecycle at 241 days. The honest internal answer to "can I do something meaningful about this" is frequently "not with what I have, and not this quarter."

11%
The share of CISOs who describe their security team as adequately staffed. Low perceived efficacy is not a messaging problem you can talk a buyer out of. It is their operating reality. Source: IANS Research and Artico Search, 2025 Security Budget Benchmark Report.

Why "we already have a tool for that" is usually a fear response

Those are textbook fear control conditions, and they reframe the objection every cybersecurity rep hears most.

"We already have a tool for that" is usually not a competitive objection. It is a fear-control response. It is the fastest available way to close a threat loop the buyer cannot otherwise close. Saying it out loud restores a sense of coverage in about four seconds, at no cost, without a budget request or a fight with IT operations.

That distinction changes what a rep should do next. Reps who hear it as a feature comparison start arguing about capabilities, which raises threat again and pushes the buyer further into defense. The buyer's counter-move is to end the meeting warmly and stop replying. What sales teams log as ghosting is often just fear control running its course.

Why the threat statistic stopped registering at all

There is a second mechanism stacked on top of the first, and it explains the speed of the dismissal.

The amygdala's response to a threat cue is not fixed. It attenuates with repetition. Work published in NeuroImage in 2014 by Plichta and colleagues, titled "Amygdala habituation: a reliable fMRI phenotype," showed that amygdala activation to repeated emotional stimuli declines reliably across presentations, consistently enough to be treated as a stable individual trait. Habituation is strongest when the repeated signal is non-contingent, meaning it fires regardless of what the person does and does not reliably predict a consequence for them specifically.

That is a precise description of the cybersecurity threat message: same category of statistic, same severity framing, arriving weekly from dozens of senders, uncorrelated with anything that actually happens to this buyer's organization. The response curve flattens.

The important part for enablement is this. Habituation is not skepticism. A skeptical buyer argues with your number, which at least means the number was processed. A habituated buyer does not argue. They simply do not allocate attention, and the conversation moves on without the claim ever landing. That's why reps describe these calls as going fine and then going nowhere. Nothing was rejected. Nothing was received either.

Jeff Bloomfield, who founded Braintrust and wrote NeuroSelling, frames the underlying principle this way: the buyer's brain decides whether a conversation is safe and worth attending to before it evaluates a single claim inside it. In cybersecurity, threat-led openings fail that gate faster than in almost any other market, because the gate was trained by the buyer's own job.

What this looks like for sales enablement leaders in cybersecurity

The fix is not "sell on value instead of fear." That's the advice every market gets, and it doesn't tell a rep what to say on Tuesday. What the research points at is specific: hold threat roughly where the buyer already has it, and put the entire message into raising efficacy. Here is where that changes behavior.

Change what discovery is looking for

Most security discovery hunts for pain, which is a threat-appraisal exercise aimed at a buyer whose threat appraisal is already maxed. Point discovery at efficacy instead.

Retire "what keeps you up at night." Replace it with questions that surface where the buyer does and does not believe action is possible. What did your team try last in this area, and what happened? When that control fires, who picks it up and what do they do next? Which of your current tools would you turn off tomorrow if coverage held? What has to be true by the audit date, and who is holding that date?

Those questions do something the fear questions cannot. They tell the rep exactly which efficacy gap the deal turns on, and they tell the buyer that this seller understands operations rather than headlines.

Change what the deck spends its slides on

Most cybersecurity decks front-load threat and back-load operability. Invert it. Compress the threat landscape section to a single claim the buyer has to accept as true about their own environment, sourced from discovery rather than from an industry report, and spend the recovered slides on the efficacy question.

Efficacy content is concrete: what the first 30 days look like, who on the buyer's team has to do what, how much runs without adding headcount, what an existing tool stops doing once this is in place, and what the buyer will be able to tell the board on a named date. A CISO who cannot picture the operational reality of week three has low response efficacy no matter how good the technology is, and low response efficacy sends the deal into fear control.

Change how reps handle the tool-overlap objection

Train the response as a diagnostic, not a rebuttal. The rep's next sentence should not compare features. It should ask what happens operationally: when that tool flags something in this category, what does your team do with it? How often does that path complete? What's the part of it that still lands on a person?

Almost always, the buyer has coverage on paper and a broken path in practice. That gap is the efficacy gap, and the buyer has to articulate it themselves for it to count. A rep who argues coverage gets a defensive buyer. A rep who asks about the operational path gets a buyer describing their own problem out loud, which is the only version of the problem a committee will fund.

Change what gets rehearsed, and rehearse it in the pattern reps will face

This is where most enablement programs lose the change. A messaging update gets delivered in a two-hour session, the deck gets swapped, and by week three the field is back to the breach statistic, because the old opening is the one that lives in muscle memory under pressure.

Three things need live rehearsal, in scenario, with a coach, scored against a standard, and repeated past the point of comfort. First, the efficacy question set in discovery, until the rep can run it without the script. Second, the tool-overlap exchange, because that one arrives fast and the default response is reflexive. Third, the board translation: taking whatever the buyer just described and restating it in the terms the board is measuring, given how far apart CISOs and boards sit on what counts as a top metric.

That's a behavior change, not a content change. Content changes fade in two weeks. Behavior changes hold when reps practice them under realistic pressure and get coached on what they actually did, not on what the deck says they should have done.

Where this leaves your team

The industry's threat messaging did not stop working because buyers got smarter or more cynical. It stopped working because the signal was repeated until the response to it flattened, and because the one variable that determines whether a frightened buyer acts or defends was never the variable the pitch was built around.

Efficacy is that variable, and it is the one thing a cybersecurity vendor can genuinely provide that a threat statistic never can. Teams that make this shift tend to notice it first in a boring place: fewer polite second meetings that go nowhere, and more deals where the buyer describes their own operational gap without being pushed.

Worth a conversation? If your field team is running threat-led pitches that used to convert and no longer do, that's a behavior gap before it's a messaging gap, and it's worth diagnosing before the next content refresh. Start a conversation with Braintrust about what NeuroSelling looks like for a cybersecurity sales team.

About the Author: Zach Strauss is the Chief Marketing Officer at Braintrust, a communication skills-based growth consulting firm focused on sales performance and leadership development. He works with revenue leaders at enterprise organizations across financial services, insurance, life sciences, software, manufacturing, and private equity to translate how the brain actually decides into revenue systems that move the number. Connect with Zach at zach.strauss@braintrustgrowth.com or reach him directly on LinkedIn.

Serving sales teams at enterprise organizations

Braintrust is a communication skills-based growth consulting firm offering programs rooted in neuroscience and behavioral psychology, designed to develop the consistent communication habits proven to drive higher sales performance and leadership effectiveness.

Financial Services Insurance Life Sciences Software Manufacturing Private Equity

Frequently Asked Questions

Why does fear-based selling stop working in cybersecurity?

Because the buyer's threat response has habituated. Security practitioners process threat language as a job function and receive dozens of threat-framed vendor messages a week, so the signal is repeated, non-contingent, and no longer predictive of anything specific to them. Amygdala response to a repeated threat cue attenuates with exposure, which means the breach statistic in your opening is not being rejected. It is not being processed at all.

What is the Extended Parallel Process Model, and why does it matter in security sales?

The Extended Parallel Process Model, introduced by Kim Witte in Communication Monographs in 1992, holds that a threatening message triggers two appraisals: how bad is this threat, and can I actually do something about it. High threat plus high efficacy produces danger control, where people act on the risk. High threat plus low efficacy produces fear control, where people manage the feeling through avoidance, denial, or defensive dismissal. Cybersecurity buyers sit at high threat and low efficacy, which is why more threat produces more defense.

Is fear ever useful in a cybersecurity sales conversation?

Yes, but only as a small part of the message and never as the lead. Witte and Allen's meta-analysis of 98 fear-appeal studies found that strong fear appeals work when paired with credible efficacy, and backfire when the audience does not believe it can avert the threat. In practice that means holding threat roughly where the buyer already has it and spending the conversation on whether a response is realistic for that specific team.

How should a rep respond to “we already have a tool for that”?

Treat it as a diagnostic, not a rebuttal. Instead of comparing features, ask what happens operationally when that tool fires, how often the response path completes, and which part still lands on a person. Most buyers have coverage on paper and a broken path in practice, and the buyer has to describe that gap themselves for it to carry weight with the rest of the buying committee.

What should cybersecurity sales enablement teams change in discovery first?

Point discovery at efficacy instead of pain. Retire questions like “what keeps you up at night,” which target a threat appraisal that is already at ceiling, and replace them with questions about what the team tried last and what happened, what happens after a control fires, which existing tools could be turned off if coverage held, and what has to be true by the audit or framework deadline.

How long does a change like this take to show up in the field?

A messaging update alone typically fades within two to three weeks, because the old threat-led opening is what reps default to under pressure. The change holds when the new behaviors are rehearsed live in scenario, coached against a standard, and repeated past the point of comfort, particularly the efficacy question set, the tool-overlap exchange, and the board translation.