Building better GTM for lean cybersecurity teams. In public.
I build and test AI-assisted workflows grounded in strong product marketing and human judgment. The goal: help lean cybersecurity teams punch above their weight.
Follow along for the setup, results, costs, and lessons you can apply to your own work.
Technical products need more than surface-level GTM data.
A targeting tool can match a job title and still find the wrong buyer. In cybersecurity, the difference often comes down to responsibilities and technologies the data does not capture.
Job titles can be misleading.
For a company selling a CRM platform, sales headcount can help identify target accounts. Sales titles are relatively standardized. Cybersecurity titles are far more fragmented. One function can have dozens of title variations.
For an AI SOC platform, the question is who works in or supports the security operations center. Security analysts, security engineers, detection engineers, and incident responders can have overlapping responsibilities despite different titles.
One title can point to different responsibilities.
Title
Meaning
CISO
Security Executive
Field CISO
Vendor-side, sales-support role
CSO
Security or Strategy Executive
CPO
Product or Privacy Executive
A single word can also change the role entirely. A CISO is an executive buyer; a Field CISO typically works on the vendor side, supporting sales.
Without domain context and AI-assisted human review, a system can include the wrong people, waste budget, and erode trust.
accuracy erodes as you go deeper into the stack.
Public website scripts make analytics, CMS, chat, and CRM systems relatively easy for technographic vendors to detect.
However, the SIEM, EDR, secrets manager, and internal cloud services that matter in cybersecurity may leave no reliable public signature.
Context about the company, the role, and the security team can improve the picture. That may include reviewing a person’s broader profile, understanding the company’s products and team structure, and using AI to connect those clues. The result still requires human judgment and remains incomplete.
For example, an IAM manager job posting might ask for experience with Okta, Microsoft Entra ID, or PingOne. That does not mean the company uses all three. It may use only Okta, while a technographic enrichment vendor reports all three. If your outreach begins, “I noticed you have PingOne, Okta, and Microsoft Entra ID,” and that claim is wrong, you have lost credibility in the first sentence.
And never start cold outreach with “I noticed that.” Cybersecurity professionals recognize it as a standard AI-generated sales opener and will ignore it.
The InterimCMO manifesto
Earn buyer credibility before you scale.
Buyer credibility starts with clear positioning: who the product is for, which problem it solves, how it differs from the alternatives, and why its claims are credible.
Messaging should use the buyer’s language, reflect the competitive landscape, and support important claims with proof. Scale only after that foundation holds up with technical buyers.
Elias Terman has spent fifteen years building and advising venture-backed cybersecurity companies across:
Cloud security
Identity
Bot mitigation
Data security and privacy
AI agent security
He was Orca Security’s first marketing hire as the company grew from seed stage into a unicorn, served as CMO-in-Residence at YL Ventures, helped pioneer bot mitigation at Distil Networks (acquired by Imperva), and led marketing at Integris Software (acquired by OneTrust).
His operating roles also include CMO at Uptycs and VP of Marketing at AI agent security company Vorlon.
Get new insights, experiment plans, and findings from my work building AI-assisted GTM workflows for lean cybersecurity teams. I share the setup, results, costs, and corrections along the way.