A cybersecurity field team opens the way it has opened for six years. Breach statistic. Threat landscape slide. A dollar figure attached to what happens if the buyer does nothing. Two years ago that sequence produced a second meeting. Now the CISO listens politely, says the roadmap is set through Q3, and the opportunity turns into a no-decision that nobody can quite explain in the pipeline review.
Sales enablement leaders at cybersecurity vendors are watching this happen across whole teams at once, which is the tell. When one rep's numbers slide, it's a rep problem. When threat-led pitches stop converting across the board, the message didn't get worse. The audience changed.
Cybersecurity has spent a decade industrializing fear as a go-to-market motion, and the buyers it aims at have adapted the way any nervous system adapts to a signal that fires constantly and predicts almost nothing. What replaces fear is not softer messaging. It's a different variable entirely, and the research on fear appeals identified it decades ago.
Why cybersecurity needs a different approach
Plenty of markets overuse urgency. Cybersecurity is structurally different in five ways that change what a rep actually has to do in the room.
The buyer is professionally desensitized. A security practitioner processes threat language as a job function, all day, every day. In Vectra AI's 2024 State of Threat Detection and Response research, 81% of SOC practitioners said they spend more than two hours a day triaging security events, and practitioners reported they can realistically deal with only 38% of the alerts they receive. Of the alerts that arrive, they classify roughly 16% as real attacks. This is a buyer whose working environment has already trained them to discount threat signals at scale. Your opening slide enters a channel that is saturated and already discounted.
The buyer is also being sold to constantly. One 2026 analysis of security buying published on Security Boulevard reported that CISOs receive roughly 60 cold outreach attempts a week and reject most within about five seconds. Five seconds is not evaluation. It's pattern recognition. If your opening looks like the other 59, it gets sorted before anyone reads the claim.
Budget is tighter than the threat narrative implies. The IANS Research and Artico Search 2025 Security Budget Benchmark Report, based on 587 CISOs surveyed in April 2025, found security budgets grew 4% year over year, down from 8% the prior year and the lowest rate in five years. Security spending as a share of total IT spend fell from 11.9% to 10.9%. Only 11% of CISOs described their teams as adequately staffed. Raising the perceived size of the threat does not create budget in that environment. It creates a buyer who feels worse and still cannot act.
Compliance and the board are the real forcing functions. Splunk's CISO Report 2025 found 83% of CISOs participate in board meetings somewhat often or most of the time, and it surfaced a revealing split: 15% of CISOs ranked compliance status among their top performance metrics, compared with 45% of board members. The person you are selling to and the body that approves the spend are measuring different things. Audit findings, framework deadlines, and cyber insurance requirements move money on a calendar. Ambient dread does not.
The committee is large, and each member has a different fear. Gartner's research on complex B2B purchases puts typical buying groups at six to ten decision makers. In a security deal that means a CISO, a security architect, an IT operations lead, a procurement analyst, a legal or privacy reviewer, and a business sponsor, each of whom would answer "what's the risk here" differently. A single threat narrative aimed at the CISO leaves five people with no reason to advocate for you internally.
What fear appeals actually require to work
The most useful research here is not new, and it did not come from sales. It came from public health, where researchers spent decades studying why some frightening messages change behavior and most produce nothing at all.
Kim Witte's Extended Parallel Process Model, introduced in Communication Monographs in 1992, describes what happens when a person encounters a threatening message. The brain runs two appraisals, not one. First, threat appraisal: how severe is this, and does it apply to me? Second, efficacy appraisal: is there a response that actually works, and can I personally carry it out?
The second appraisal decides everything. When perceived threat is high and perceived efficacy is also high, people enter danger control. They engage with the risk, evaluate the recommendation, and take protective action. When perceived threat is high and perceived efficacy is low, people enter fear control. They manage the feeling instead of the risk, through avoidance, denial, defensive dismissal, or reactance against whoever delivered the message.
Under fear control, the buyer is not solving your problem for you. They are solving their discomfort, and the fastest way to do that is to make you go away.
Witte and Allen's meta-analysis of 98 fear-appeal studies, published in Health Education and Behavior in 2000, confirmed the pattern and added the warning that matters most to anyone building a pitch deck: strong fear appeals should be used cautiously, because they backfire when the audience does not believe it can effectively avert the threat.
Now apply that to a security buyer's actual situation. Threat perception is already at ceiling. There is no headroom left, which is why bigger numbers do nothing. Efficacy is where all the variance lives, and efficacy in this market is genuinely low. The buyer already owns a great deal of tooling. In the same Vectra research, 73% of SOC practitioners reported more than 10 security tools in place and 45% reported more than 20, while 47% said they do not trust their tools to work the way they need them to. IBM's 2025 Cost of a Data Breach Report put the average breach lifecycle at 241 days. The honest internal answer to "can I do something meaningful about this" is frequently "not with what I have, and not this quarter."
Why "we already have a tool for that" is usually a fear response
Those are textbook fear control conditions, and they reframe the objection every cybersecurity rep hears most.
"We already have a tool for that" is usually not a competitive objection. It is a fear-control response. It is the fastest available way to close a threat loop the buyer cannot otherwise close. Saying it out loud restores a sense of coverage in about four seconds, at no cost, without a budget request or a fight with IT operations.
That distinction changes what a rep should do next. Reps who hear it as a feature comparison start arguing about capabilities, which raises threat again and pushes the buyer further into defense. The buyer's counter-move is to end the meeting warmly and stop replying. What sales teams log as ghosting is often just fear control running its course.
Why the threat statistic stopped registering at all
There is a second mechanism stacked on top of the first, and it explains the speed of the dismissal.
The amygdala's response to a threat cue is not fixed. It attenuates with repetition. Work published in NeuroImage in 2014 by Plichta and colleagues, titled "Amygdala habituation: a reliable fMRI phenotype," showed that amygdala activation to repeated emotional stimuli declines reliably across presentations, consistently enough to be treated as a stable individual trait. Habituation is strongest when the repeated signal is non-contingent, meaning it fires regardless of what the person does and does not reliably predict a consequence for them specifically.
That is a precise description of the cybersecurity threat message: same category of statistic, same severity framing, arriving weekly from dozens of senders, uncorrelated with anything that actually happens to this buyer's organization. The response curve flattens.
The important part for enablement is this. Habituation is not skepticism. A skeptical buyer argues with your number, which at least means the number was processed. A habituated buyer does not argue. They simply do not allocate attention, and the conversation moves on without the claim ever landing. That's why reps describe these calls as going fine and then going nowhere. Nothing was rejected. Nothing was received either.
Jeff Bloomfield, who founded Braintrust and wrote NeuroSelling, frames the underlying principle this way: the buyer's brain decides whether a conversation is safe and worth attending to before it evaluates a single claim inside it. In cybersecurity, threat-led openings fail that gate faster than in almost any other market, because the gate was trained by the buyer's own job.
What this looks like for sales enablement leaders in cybersecurity
The fix is not "sell on value instead of fear." That's the advice every market gets, and it doesn't tell a rep what to say on Tuesday. What the research points at is specific: hold threat roughly where the buyer already has it, and put the entire message into raising efficacy. Here is where that changes behavior.
Change what discovery is looking for
Most security discovery hunts for pain, which is a threat-appraisal exercise aimed at a buyer whose threat appraisal is already maxed. Point discovery at efficacy instead.
Retire "what keeps you up at night." Replace it with questions that surface where the buyer does and does not believe action is possible. What did your team try last in this area, and what happened? When that control fires, who picks it up and what do they do next? Which of your current tools would you turn off tomorrow if coverage held? What has to be true by the audit date, and who is holding that date?
Those questions do something the fear questions cannot. They tell the rep exactly which efficacy gap the deal turns on, and they tell the buyer that this seller understands operations rather than headlines.
Change what the deck spends its slides on
Most cybersecurity decks front-load threat and back-load operability. Invert it. Compress the threat landscape section to a single claim the buyer has to accept as true about their own environment, sourced from discovery rather than from an industry report, and spend the recovered slides on the efficacy question.
Efficacy content is concrete: what the first 30 days look like, who on the buyer's team has to do what, how much runs without adding headcount, what an existing tool stops doing once this is in place, and what the buyer will be able to tell the board on a named date. A CISO who cannot picture the operational reality of week three has low response efficacy no matter how good the technology is, and low response efficacy sends the deal into fear control.
Change how reps handle the tool-overlap objection
Train the response as a diagnostic, not a rebuttal. The rep's next sentence should not compare features. It should ask what happens operationally: when that tool flags something in this category, what does your team do with it? How often does that path complete? What's the part of it that still lands on a person?
Almost always, the buyer has coverage on paper and a broken path in practice. That gap is the efficacy gap, and the buyer has to articulate it themselves for it to count. A rep who argues coverage gets a defensive buyer. A rep who asks about the operational path gets a buyer describing their own problem out loud, which is the only version of the problem a committee will fund.
Change what gets rehearsed, and rehearse it in the pattern reps will face
This is where most enablement programs lose the change. A messaging update gets delivered in a two-hour session, the deck gets swapped, and by week three the field is back to the breach statistic, because the old opening is the one that lives in muscle memory under pressure.
Three things need live rehearsal, in scenario, with a coach, scored against a standard, and repeated past the point of comfort. First, the efficacy question set in discovery, until the rep can run it without the script. Second, the tool-overlap exchange, because that one arrives fast and the default response is reflexive. Third, the board translation: taking whatever the buyer just described and restating it in the terms the board is measuring, given how far apart CISOs and boards sit on what counts as a top metric.
That's a behavior change, not a content change. Content changes fade in two weeks. Behavior changes hold when reps practice them under realistic pressure and get coached on what they actually did, not on what the deck says they should have done.
Where this leaves your team
The industry's threat messaging did not stop working because buyers got smarter or more cynical. It stopped working because the signal was repeated until the response to it flattened, and because the one variable that determines whether a frightened buyer acts or defends was never the variable the pitch was built around.
Efficacy is that variable, and it is the one thing a cybersecurity vendor can genuinely provide that a threat statistic never can. Teams that make this shift tend to notice it first in a boring place: fewer polite second meetings that go nowhere, and more deals where the buyer describes their own operational gap without being pushed.
Worth a conversation? If your field team is running threat-led pitches that used to convert and no longer do, that's a behavior gap before it's a messaging gap, and it's worth diagnosing before the next content refresh. Start a conversation with Braintrust about what NeuroSelling looks like for a cybersecurity sales team.