Retour

Explorez tous les épisodes du podcast Audience 1st

Plongez dans la liste complète des épisodes de Audience 1st. Chaque épisode est catalogué accompagné de descriptions détaillées, ce qui facilite la recherche et l'exploration de sujets spécifiques. Suivez tous les épisodes de votre podcast préféré et ne manquez aucun contenu pertinent.

Rows per page:

1–50 of 107

TitreDateDurée
What OpenClaw Going Sideways Reveals About How Humans Interact with Technology10 Apr 202600:43:20

Alex Yampolskiy walked back into my studio, sat down, complimented the pillow, and then spent the next hour telling me things that kept me up that night.

It hasn't been long since our first conversation. But in the weeks between sessions, an open-source AI agent called OpenClaw went viral and then went sideways. Tens of thousands of people rushed to install a personal AI assistant that connects to their email, calendar, WhatsApp, and terminal. Almost nobody thought about security before they hit deploy.

SecurityScorecard's research team scanned the entire internet and found over 40,000 exposed instances. No authentication. No encryption. Named in ways that let you identify the person and the company they worked for. Hackers found them before the organizations did.

In this episode, we unpack what OpenClaw reveals about how humans interact with technology and why the problem is much bigger than one tool.

AY explains why people click first and think second in the digital world, even though they'd never walk into a dark alley without looking over their shoulder. He describes AI agents as ephemeral interns with root access who disappear before you can fire them. He walks through why the speed of exploitation has dropped from days to microseconds and why human-speed defense against machine-speed offense is no longer viable.

We get into territory that most cybersecurity conversations avoid. AY is blunt about AI budgets exploding while security budgets stay flat and what that means for CISOs being asked to govern technologies they had no say in adopting. He tells me that most third-party risk programs operate one day a year, leaving 364 days where nobody is verifying anything.

He walks me through Security Scorecard's maturity framework from static, point-in-time assessments to continuous monitoring to threat-informed detection and response and is honest about where most organizations actually sit on that curve versus where they think they sit. The gap between those two points is where the real risk lives.

He makes the case that compliance and security are best friends, not twins, and that the forcing function of regulation is often the only thing that unlocks budget. He explains why the Ukrainians deliberately hacked their own infrastructure before the Russians could. And he says, plainly, that if you can't afford the secure tools, you accept the risk. No soft landing.

Listen in and enjoy.

A special thanks to our friends at Security Scorecard for partnering with us to tell this story.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Human Risk Will Define the Next Decade of Security 18 Mar 202600:49:54

Three decades. Billions of dollars in security investment. And the human element still sits behind 68% to 72% of every breach that happens. If that statistic does not make you uncomfortable, you have probably been in this industry long enough to have accepted it as inevitable. Masha Sedova has not accepted it, and this episode is the result of a career spent refusing to.

Masha co-founded Elevate Security, built it into the leading human risk management platform in the space, and watched it get acquired by Mimecast - where she now leads human risk strategy and product across a portfolio that combines email security, DLP, collaboration security, and behavioral risk intelligence under one roof. She is one of the most rigorous thinkers working at the intersection of people and security, and this conversation left me genuinely rattled in the best possible way.

We talk about what human risk management actually is and why calling it a rebrand of security awareness is a disservice to both categories.

We get into the 8/80 rule - the finding that 8% of your workforce is responsible for 80% of your incidents - and what it means for how security budgets should actually be allocated.

We cover the four personas framework, the open ecosystem bet, the board conversation, and the cultural debt that the phrase 'humans are the weakest link' has accumulated over thirty years.

I push back where I think the industry has not fully reckoned with what it is building, and Masha pushes right back.

If you work in cybersecurity in any capacity - whether you are a CISO, a founder, an investor, or a marketer trying to understand what your buyers actually care about - this episode will change how you think about the human element problem.

Listen and enjoy.

A special thanks to our friends at Mimecast for partnering with us to tell this story.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
A Deep Dive Into The Multi-Cloud Mess & How AlgoSec Connects the Dots09 May 202500:41:49

What does it really take to secure applications across a hybrid, multi-cloud environment?


In this episode of Audience 1st, I sit down with Adolfo Lopez, Sales Engineer at AlgoSec, who brings a practitioner’s lens to the cloud security conversation. From his experience as a network engineer to helping organizations operationalize cloud security today, Adolfo walks us through what most teams overlook—and how to get it right.


We cover:



  • Why visibility into application flows is foundational for multi-cloud security

  • What enterprises miss when they treat the cloud like a lift-and-shift extension of on-prem

  • Why security must be application-centric—not infrastructure-led

  • The critical role of policy discovery, orchestration, and automation

  • How AlgoSec ACE helps teams answer the question: “What will break if I make this change?”


If your team is working across AWS, Azure, GCP, and on-prem—and struggling to manage risk, connectivity, and policy alignment, this episode breaks it down practically and tactically.


To get a demo of AlgoSec, visit: https://www.algosec.com/lp/request-a-demo



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Time is the Most Valuable Asset - Are You Respecting It? | Malia Mason28 Apr 202200:48:22
What are you doing to efficiently reduce manual processes and save tireless hours of those battling threats behind the keyboard?

In this episode, I had a brutally honest conversation with Malia Mason, vCISO and Manager of Cybersecurity, about her challenges, goals, what vendors do that piss her off, and the alternatives.


Malia served in the United States Navy as a Sonar Technician Second Class and was also in charge of all of the secret data on the ship and of making sure that everyone did their cybersecurity training.


She continues to work with several veterans nonprofits as a mentor and career advisor for veterans leaving the military and military spouses as well.


She is a strong proponent of getting more women into cybersecurity and tech, serving as a mentor for young girls in inner-city schools.


Join Audience 1st Today

Join 300+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How to Think in Terms of Enabling Business to Engage CISOs | Brent Deterding21 Apr 202200:45:49
You may not have to articulate that, but ask yourself, "What is the business case? Why would a CISO spend any amount of money with me?"

How do you speak in terms that resonate with CISOs?


What are their goals and challenges?


Have you considered the constraints new CISOs have to undergo in their new roles?


When engaging a CISO, have you thought about the tech they have to adopt before pitching to them?


In this episode, I had a brutally honest conversation with Brent Deterding, newly appointed CISO of Afni, Inc., about what motivates him, what his challenges are, what vendors do that piss him off, and the alternatives.


Join Audience 1st Today

Join 300+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How to Create Value-Driven Content That Resonates with Cybersecurity Buyers | Andra Zaharia12 Apr 202200:43:31
f you are too much in love with your product vs. how you help your audience solve a problem, you're going to be disconnected from the very people you're trying to reach.

Content. The fuel that drives demand today.


There is so much of it online.


Unfortunately, though, the mass majority of content in the field has left security buyers confused and distracted.


The problem that security practitioners find themselves in right now is that they’re bombarded with high quantities of content but also high quantities of higher-quality, product-centric content too.


So, how do we go back to the core and create content that focuses on the real problems we can solve for security practitioners so they have the ability to make good decisions?


In this episode, I had a candid and practical conversation with Andra Zaharia, creator and co-host of the Cyber Empathy podcast and cybersecurity marketing expert.


We discussed the challenges she faces as a content marketing professional in cybersecurity, stereotypes to battle in order to be successful in the field, questions to ask to deliver valuable content, and the framework she uses to produce content.


Join Audience 1st Today

Join 300+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
When You Focus on the Mission, You Will Make the Money | Evan Francen07 Apr 202200:49:13
Even if you don't win right now on customer acquisition - you will absolutely win on the churn rate.

People will not leave you.


They will stay with you forever because they trust you.


When I listened to Evan Francen, CEO of FRSecure and SecurityStudio, chat with Ryan Cloutier on their podcast, he said one thing that stood out to me:


“I don’t want any friends.”


I called b******t.


And so, here we are, having a down-to-earth, candid conversation, full of “F'“ bombs and the “S” word 😱, about what motivates him, what his challenges are, what vendors do that piss him off, and the alternatives.


Look how that worked out!


Here’s hoping for a continued friendship.


Join Audience 1st Today

Join 300+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How Cybersecurity Marketers Can Distinguish Themselves from Attackers | Joseph Carson30 Mar 202200:56:14
The goal is to frictionlessly get security buyers to information in trusted ways so they can self-verify and make wise, educated decisions.

How do we build and develop business and communications skills, foster different ideas that allow us to think about how to be more ethical and innovative, and communicate better with our audience?


How do we get cybersecurity to be a cool industry that people want to be in?


These are questions that Joseph Carson, Chief Security Scientist and Advisory CISO at Delinea, asks himself regularly.


In this episode, I had a brutally honest conversation with Joseph on what motivates him, what his challenges are, what vendors do that piss him off, and the alternatives.


Join Audience 1st Today

Join 300+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How Emotional Firewalls Help Marketers Become More Resilient | Nadja El Fertasi24 Mar 202200:35:09
How we relate ourselves to others helps us deal with immediate challenges and provides us with the toolbox to navigate our immediate surroundings.

If you’re phasing into cybersecurity marketing or are already working in cybersecurity as a marketer, it may come as no surprise that you must have some thick skin for the job.


Between aggressive goals, sometimes stressful and fast-response support required, pressure to “rise above the noise”, ever-changing technology, and audiences that are sometimes hard to reach - all that can sometimes take a mental and emotional toll.


Despite the challenges we, as marketers, face, it doesn’t mean you have to suffer, lose motivation or have feelings of negativity in your personal and professional life.


There are ways to navigate fear, frustration, and imposter syndrome if you feel it like I sometimes do.


In this episode, I had a refreshing and open conversation with Nadja El Fertasi, Founder of Founder Thrive with EQ and Emotional Firewalls.


We discussed how to build emotional firewalls to become more resilient in today’s age and how to navigate fear, step out of your comfort zone, establish boundaries, and understand your audience.


Join Audience 1st Today

Join 300+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
When We Connect in Meaningful Ways, We Create Active Defenders | Ryan Cloutier24 Mar 202200:39:19
The best security controls are employees who are active participants in the defense of the organization.

When I began researching security professionals I wanted to connect with and begin building relationships with, Ryan Cloutier, President of SecurityStudio, was at the top of my list.


Why?


Because, like me, he believes in the mission before money vs. profit-at-all costs.


Part of Ryan’s motivation and the battle of things he fights against are shady marketing tactics, misleading messages, and unauthentic relationships that add more stress to his life.


In this episode, I had a brutally honest conversation with Ryan on what motivates him, what his challenges are, what vendors do that piss him off, and the alternatives.


Join Audience 1st Today

Join 300+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Successful Cybersecurity Marketing with Qualitative Buyer Data and Brain Power02 May 202500:44:46

In this provocative and no-fluff episode of Keyboard Samurai, host, Wil Kluv, sits down with Dani Woolf and Ben Siegel to unpack what’s broken in how cybersecurity vendors go to market and how to fix it using real buyer data and a deeper understanding of human psychology.


Dani and Ben, co-founders of CyberSynapse and veterans of cybersecurity GTM, break down why so many tech marketers are stuck in echo chambers, how pressure from investors leads to safe (but disconnected) strategies, and why most teams are making decisions without actual buyer validation.


They explore the psychological barriers to change, why the “herd mentality” is sabotaging innovation, and how to replace opinion with evidence through first-party qualitative research. They also take on the traditional analyst model, offering sharp critique and a more human, scalable alternative rooted in community-sourced insight.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Know Before You Go: The Empathy Codified Playbook for RSA Conference 202525 Apr 202500:59:50

Most vendors won’t admit this, but we will:


Your brand doesn’t have a messaging problem. It has a presence problem.


And it’s why buyers leave RSA feeling numb, unseen, and unready to trust you.


In this episode, Dani Woolf sits down with Zachary Hyde, someone she doesn’t always agree with, which makes this conversation one of the most honest and urgent before a major conference.


Together, they break down why most GTM teams think they’re being empathetic but are actually performing a buyer-first fantasy while still clinging to control.


If you're showing up to RSA Conference this year with a booth, a badge, and a team under pressure to "drive pipeline" - this is your mirror.


Listen before you land in SFO.


What We Cover:



  • Why vendors fail to empathize with buyers at conferences

  • How canned “empathetic marketing” actually erodes trust

  • Why emotional presence is a muscle to be consistently massaged

  • The difference between tone-matching and real psychological safety

  • Red flags buyers spot immediately and won’t tell you about

  • What to do this week to actually build trust at RSA (no fluff, no fake discovery)


 



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
What Cybersecurity Leaders Must Learn from OT Practitioners in Underserved Critical Infrastructure18 Apr 202500:35:38

In this episode of Audience 1st Podcast,


Dani sits down with Kristin Demoranville, CEO of Anzen Sage and host of the Bites & Bytes podcast, to uncover the hidden vulnerabilities in one of the world’s most overlooked critical infrastructure sectors: food and agriculture.


From insider threats in peanut processing to cyber attacks that disrupt egg supply chains, Kristin breaks down why OT security in food systems isn’t just about uptime, it’s about human lives, brand trust, and national resilience.


She pulls no punches, sharing raw stories from the frontlines:




  • Why cybersecurity leaders in food facilities are flying blind




  • What happened when nobody spoke up at Boar’s Head




  • How misinformation campaigns are now a cyber risk vector




  • Why “brown cows make chocolate milk” isn’t just a joke—it’s a symptom of a dangerous knowledge gap




We also unpack:




  • The behavioral blind spots holding back executive buy-in




  • Why empathy, not just engineering, is the key to securing food systems




  • What must change in the next 5 years to avoid preventable tragedies





This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Most Tech “Communities” Fail Before They Begin11 Apr 202500:30:59

Everyone in tech is suddenly “building community.” But most aren’t building anything close to the real thing - community that's built on mission, trust, and transparency.


In this raw, no-buzzword conversation recorded live at CyberMarketingCon, Dani Woolf sits with Ben Siegel, George Kamide, Bronwen Hudson, and Elliot Volkman, real community builders, to unpack what community actually means, why most efforts fall flat, and what it takes to build something alive, resilient, and trustworthy - especially in an industry like cybersecurity where trust is scarce and attention is fractured.


We go deep on:




  • Why most corporate “communities” are poorly disguised funnels




  • The difference between an audience, a user group, and a true community




  • What trust looks like when your members are CISOs, not consumers




  • Why growth is nonlinear, unpredictable, and absolutely not guaranteed




  • The emotional labor and invisible moderation that holds real communities together




You’ll also hear tactical advice on how to build thriving spaces across Reddit, Slack, LinkedIn, and beyond - without flashy tools or six-figure budgets.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
5 Mindset Shifts Security Teams Must Adopt to Master Multi-Cloud Security04 Apr 202500:30:38

Multi-cloud security isn’t just a technology challenge—it’s an organizational mindset problem.

Security teams are juggling AWS, Azure, and GCP, each with different security models, policies, and rules.

The result? Silos, misconfigurations, and security gaps big enough to drive an exploit through.

In this episode, I sat down with Gal Yosef from AlgoSec to break down:



  • Why multi-cloud security is so complex (and what security teams are getting wrong)

  • How to bridge the gap between network security and cloud security teams

  • How large enterprises manage cloud security policy enforcement across business units

  • The shift from one-size-fits-all security policies to flexible, risk-based guardrails

  • Why automation and visibility are critical for securing multi-cloud environments


If you want to secure application connectivity across your hybrid environment, visit algosec.com.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How to Diagnose Your Organization’s Real Growth Problem31 Mar 202500:41:21

In this episode of Audience 1st, Dani Woolf cuts straight through the noise to confront the silent killer of growth in B2B organizations: misdiagnosing the real growth problem.


Most GTM teams think they’re aligned. They’re not.


Most believe they’re solving the right thing. They aren’t.


In this raw, unfiltered solo episode, Dani unpacks why internal alignment is often a lie, how companies waste entire quarters solving surface-level symptoms, and what it takes to actually identify the bleeding neck - the one problem that’s quietly draining your growth, budget, and team morale.


If you’ve ever felt like your team is moving fast but going nowhere, this is the episode you didn’t know you needed.


What You’ll Learn:




  • Why most organizations aren’t solving their biggest growth problem and how to tell if you’re one of them




  • The high cost of chasing lagging indicators instead of root causes




  • The real reason marketing, sales, and product don’t align and why buyer truth is the only fix




  • How to recognize “growth triggers” that signal it’s time to do qualitative buyer research




  • Dani’s four-step clarity framework: Diagnose → Validate → Align → Act




  • How to stop guessing, and finally build from buyer reality—not internal theory




Don’t just walk away from this episode inspired. Take action.


Ask yourself:




  • What’s the one growth problem we think we’re solving right now?




  • Who told us that?




  • When was the last time we heard it from a buyer’s mouth verbatim?




  • What would it feel like to know we’re solving the right thing?




If you’re ready to stop guessing and start listening, reach out to Dani and her team.


Let’s uncover the bleeding neck together.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
The CISO POV Checklist That Drives Buying Decisions31 Mar 202500:41:07

In this episode of Audience 1st Podcast, Dani Woolf sits down with Jason Loomis, Chief Information Security Officer at Freshworks, to uncover the raw truth behind how CISOs evaluate security vendors, what actually moves a deal forward, and why most POVs fall flat before they even start.


Jason gets brutally honest about the emotional dynamics of enterprise buying, the real reason vendors lose trust, and what it actually takes to turn a POV into a purchase.


If you’re in product marketing, sales, or demand generation at a cybersecurity company, this episode will change how you think about the buyer journey and give you a blueprint to win trust, increase conversions, and build long-term influence with technical buyers.


What You’ll Learn in This Episode:




  • Why emotional certainty - not ROI - is the key to winning a CISO’s trust




  • The most common POV mistakes vendors make (and how to avoid them)




  • How Jason evaluates vendors - and what gets them instantly disqualified




  • The danger of relying on generic “What problems are you solving?” questions




  • Why transparency beats feature-stuffing in every sales motion




  • How to make your booth presence less awkward and more effective




  • The impact of new SEC regulations on security budgeting and priorities




  • Why buyers referring your product - even after saying no - is the ultimate win




If you’re serious about understanding what really drives buyer decisions in cybersecurity subscribe to Audience 1st Podcast. New episodes every week. Raw, unfiltered, and straight from the source - your buyers.


🎧 Listen now, take notes, and share with your GTM team.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why the Legacy Analyst Model is Misaligned with Cybersecurity Buyer and Vendor Needs14 Mar 202500:31:42

In this episode of Risk & Real, host Jeffrey Wheatman sits down with Dani Woolf, co-founder of CyberSynapse and CEO of Audience 1st, to discuss a major shift happening in the cybersecurity industry: the decline of the traditional analyst model and the rise of direct buyer engagement.


Cybersecurity vendors that engage directly with their buyers gain faster, more actionable insights than those relying solely on traditional analyst firms.


Tune in as we discuss:



  • The flaws in the traditional analyst model and why it’s no longer aligned with today’s fast-moving cybersecurity landscape.

  • Why analyst reports take too long to produce and how they filter buyer insights.

  • The power of direct buyer engagement and how vendors can gather real-time, unfiltered insights.

  • Why cybersecurity vendors are cutting back on analyst firm budgets and shifting to a hybrid research model.

  • How CyberSynapse enables vendors to talk directly to security practitioners, CISOs, and IT leaders.


Resources & Links:


Learn more about CyberSynapse: https://www.cybersynapse.io
Follow Dani Woolf on LinkedIn: https://www.linkedin.com/in/daniwoolf
Check out Audience 1st Podcast: https://audience1st.fm


 


Subscribe & Stay Connected!


Follow Risk & Real on Apple Podcasts, Spotify, or your favorite podcast app.


Connect with host Jeffrey Wheatman on LinkedIn: https://www.linkedin.com/in/jeffreywheatman


Don’t forget to leave a review if you enjoyed the episode! 



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Cloud Security Starts with Applications & How to Protect Them at Scale07 Mar 202500:27:10

Cloud security didn’t make life easier—it made it exponentially harder.

Security teams are stuck in legacy network security models while trying to secure cloud-native applications, security groups, IAM policies, and ephemeral workloads.

The result? Confusion, misalignment, and a security posture that can’t keep up with cloud speed.

In this episode of Audience 1st Podcast, I chatted with Kyle Wickert from AlgoSec about:



  • Why network security teams struggle with cloud security models

  • The hidden complexity of securing applications across multi-cloud environments

  • Why firewalls and network segmentation don’t translate well to the cloud

  • How security teams can gain visibility and control over cloud security policies

  • The role of automation in bridging the gap between network security and cloud security


If you want to secure application connectivity across your hybrid environment, visit algosec.com.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
The Kid Who Googled "How to Become a Hacker" and Ended Up Wrecking Real Ones01 Mar 202600:36:57

John Hammond was a kid who Googled "how to become a hacker" and took it seriously. He learned Python, found his way into the Coast Guard Academy, and remembers squaring down a stairwell at two in the morning - rigid military posture, full indoctrination protocol - vibrating with excitement because he was about to sit next to smart people and solve security problems for a living.

That visceral, middle-of-the-night certainty became the foundation of everything that followed.

Today he's a principal security researcher on the Adversary Tactics team at Huntress, employee number twenty-eight at a company that's now over six hundred people.

He's also one of the most recognized cybersecurity educators on the internet, producing hour-long exploit deep dives on YouTube that get more genuine engagement than most vendors' entire content budgets combined.

In this episode, John talks about why the cybersecurity industry is stuck on a treadmill it may never get off and whether the business model actually depends on that treadmill keeping pace.

He explains why Huntress is deliberately slow about integrating AI into their human-led SOC and why that uncertainty is more credible than the confident claims coming from thousands of other cybersecurity vendors in the space.

We also get into territory that most cybersecurity conversations gloss over.

John makes the case that the security awareness gap isn't informational - the information exists, he's made it free on YouTube - it's motivational, and most training programs are built around what the security team thinks is important rather than what the end user actually cares about.

He talks about why checklists function as a ceiling on curiosity, and why the discoveries that actually matter are the ones that never make it onto the procedure document.

And he gets real about burnout - the arc from obsessive passion to unsustainable output that the industry celebrates in keynotes and ignores in its operational expectations.

There's a moment near the end where I asked him to describe Huntress in three words and he gave me an internal mantra - ethical badasses - that says more about how the company thinks about culture as a competitive weapon than any mission statement ever could.

This is a conversation about what happens when someone who never optimized for credibility becomes one of the most credible voices in the room.

Listen and enjoy.

A special thanks to our friends at Huntress for partnering with us to tell this story.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Mobile Security is Dangerously Overlooked (And What To Do About It)28 Feb 202500:34:33

What happens when you meet a cybersecurity founder over dinner and 12 hours later, they’re on your podcast?

You get one of the most brutally honest conversations about mobile security.

In this episode, Rocky Cole, co-founder of iVerify, lays out why mobile security is dangerously behind—and why businesses are in denial about the scale of the threat.

We dive into:



  • The biggest myth in mobile security—why MDM (Mobile Device Management) is not a security tool and never was.

  • Why enterprise security leaders are still ignoring mobile security (even when businesses are now prime targets).

  • How attackers have outpaced traditional mobile security measures—and what needs to change.

  • The operational bottlenecks holding CISOs back from fixing the problem—and how to work around them.



Rocky shares raw insights from the frontlines of mobile security, including how his team uncovered new Pegasus infections, why BYOD security is broken, and what companies should be doing NOW.

If you're still treating mobile devices differently than desktops, this episode will change your perspective—fast.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How to Accelerate Speed to Buyer Insights to Gain a Competitive Edge | The Confident Cyber Marketer Series27 Feb 202500:45:13

Welcome to the first episode of The Confident Cyber Marketer, a monthly series hosted by CyberSynapse.io!


In this special in-person episode from New York City, I'm joined by Ben Siegel to break down how cybersecurity marketers and sales teams can accelerate speed to buyer insights to gain a competitive edge.


In this tactical, no-BS conversation, we reveal why traditional analyst models fail, why most cybersecurity vendors get it wrong, and how real-time insights from buyers—not just customers—can drive better messaging, faster sales cycles, and higher conversion rates.


Key Takeaways and Topics Covered:



  • Why cybersecurity marketing is broken—and how to fix it

  • The myth of proprietary data in cybersecurity marketing

  • Why most data doesn’t tell you the full buyer story

  • The Rapid Buyer Insight Loop (RBIL) framework for gathering and applying insights in less than two weeks

  • The difference between customer research vs. buyer research—and why both matter

  • How traditional analyst models hold cybersecurity vendors back

  • Real-world stories from Dani & Ben on how shifting to direct buyer insights changed everything

  • How to operationalize fast, actionable insights across marketing, sales, and product

  • Metrics that matter: Time to Insight, Time to Decision, Time to Value

  • The high cost of getting your target audience wrong—and how to avoid it.


Resources & Links:

🔗 CyberSynapse – Ready to ditch the traditional analyst model and get real insights from real key decision-makers? Visit CyberSynapse.io to schedule a quick call.
🔗 Connect with Dani & Ben – Let’s keep the conversation going! Find us on LinkedIn:



Don’t forget to subscribe, share, and leave a review if you found this episode valuable.


More deep dives into cybersecurity marketing that actually works coming soon!



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Human-Centric Security is the Next Frontier in Data Privacy (and Why It Matters Now More Than Ever)21 Feb 202500:45:19

In this episode of Audience 1st, I'm joined by Rob Shavell, co-founder of DeleteMe, to explore the data privacy space and the growing importance of human-centric security.

Rob will share his journey from Silicon Valley venture capitalist to privacy entrepreneur and how being a contrarian led him to build one of the leading services in the data removal space.

We'll dive into:



  • Why privacy is no longer just a noun but an active set of actions.

  • How AI and automation have transformed cybercrime into a “creative industry” and what it means for security teams.

  • Why it’s difficult to quantify the impact of continuous data removal and how security leaders can build a better ROI story.

  • How to overcome employee skepticism and drive adoption of security tools through simplicity and clear communication.


We will also discusses the future of privacy, emerging threats like AI-generated deepfakes, and what security practitioners need to do to protect their people in an increasingly hostile digital world.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
What a Modern, Buyer-Centric Approach to Software Market Intelligence Looks Like06 Feb 202500:36:48

Early in my career as a tech marketer, I was told that securing a top-right position in an analyst report was the way to gain credibility.


It didn’t take long before I started questioning the whole system.


In this episode of Audience 1st, I sat down with Chase Cunningham, VP of Security Market Research at G2 and Co-Founder of Demo-Force, to dig into a hot topic:


The flaws in the legacy analyst model and what a modern, buyer-centric approach to market intelligence looks like.


We explored how the legacy analyst firms operate, the influence of vendor dollars on rankings, and why many CMOs are quietly walking away from the old system.


Chase shared eye-opening insights into how buyers actually evaluate security solutions—hint: they’re relying more on peer reviews and real-world data than on Magic Quadrants.


Key takeaways from this episode:



  • Why vendors are overpaying for analyst influence instead of listening to buyers.

  • How data-driven insights from G2 are reshaping go-to-market strategies.

  • The most overlooked buyer signals that vendors should start paying attention to.

  • The shift from C-suite-targeted sales to winning over the “lieutenants” who make buying decisions.

  • The real truth about security software pricing, discounts, and contract lengths.


If you're in cybersecurity marketing, product, or sales and looking for smarter ways to understand and reach your buyers, this episode is a must-listen.


Get free access to more than 100 million people researching, comparing, and buying software on G2 every year: https://sell.g2.com/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
The Hidden Cost of Demo Friction: Why the Software Sales Model Is Failing & How to Fix It30 Jan 202500:36:47

The way cybersecurity and IT software is sold today is fundamentally broken.


In this episode of Audience 1st, Chase Cunningham pulls no punches as we dive into why the traditional software demo and sales model is riddled with friction, killing deals, and frustrating buyers.


We unpack the biggest flaws in go-to-market strategies, including:



  • Why buyers expect seamless, self-service access to software—and how vendors are failing them.

  • How manual, high-friction demos slow down sales cycles and lose deals.

  • Why vendor fear of transparency is outdated—and actually hurting revenue.

  • How behavioral data and automation can transform demo-to-close rates.


Chase shares eye-opening stats on demo conversion rates, real-world examples of deals lost due to friction, and practical strategies for automating and optimizing the buyer experience.


If you're in marketing, sales, or product and tired of watching your pipeline stall due to outdated sales motions, this episode is a must-listen.


Learn how to ditch the friction, close more deals, and give buyers what they actually want here: https://www.demo-force.com/



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Business Information Security Officers Are Strategic Cybersecurity Translators13 Dec 202400:41:32

The challenge is clear:


BISOs must bridge the widening gap between security priorities and business demands, often dealing with a space that is fraught with competing interests and high stakes.


But how do BISOs balance the demands of risk mitigation with the realities of operational goals?


How can they make meaningful connections with vendors who often fail to understand the nuances of their role?


These are the questions that Rob Dalzell, a Business Information Security Officer (BISO) at a major financial institution, grapples with regularly.


In this episode of Audience 1st, I had a candid conversation with Rob, where we unearthed invaluable insights into what drives buying decisions and operational realities for BISOs.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How One Customer Interview Completely Transformed This Startup's Trajectory06 Dec 202400:57:26

The art of successful startups isn't just in building the right product—it's in listening, pivoting, and solving real problems.


In this episode of Audience 1st Podcast, I sat down with James Farrow, co-founder of Cyft, to explore the intricate dance of startup growth, MSP market demands, and the mindset shifts required for success.


We covered everything from Cyft’s pivot from the MDR market to MSPs, to how a single user interview transformed the company’s trajectory.


James opened up about the emotional and operational challenges of building a startup, including how personal relationships fuel professional growth.


He also shared his mental models for approaching complex decisions, including first-principles thinking and inversion, and gave a glimpse into what’s next for Cyft as they scale their offerings.


This conversation is one of the more raw episodes I've had with a special guest, insightful, and packed with actionable advice for anyone building a business, especially in B2B tech.


Whether you’re pivoting, scaling, or just trying to stay true to your mission, James’ journey is a blueprint for thoughtful growth.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Risk Leadership Redefined: Why Chief Risk Officers Must Think Beyond Compliance29 Nov 202400:48:08

The biggest threats in cybersecurity don’t come from outside attackers—they come from within.


From toxic personal agendas to a lack of cross-functional collaboration, the real risk lies in how people operate, not just the systems they use.


It’s a hard truth for many leaders, but one that can transform organizations if embraced.


In this episode of Audience 1st Podcast, I had a real, raw conversation with Amy Chaney about what’s truly broken in cybersecurity leadership—and how to fix it.


We dove into the pervasive issue of personal agendas, the saturation of cybersecurity communities that often fail to deliver, and what separates good vendors from bad ones.


Amy also shared her insights on what it really takes to thrive as a Chief Risk Officer, her approach to balancing technical and human risks, and why collaboration—not ego—is the key to solving the industry’s toughest challenges.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Malware Researchers Are More Than Just Analysts: Recognizing Their Strategic Role in Cybersecurity21 Nov 202400:39:34

We love to glamorize the adversary-chasing, midnight-oil-burning cybersecurity lifestyle.


I’ll admit, even I do it sometimes.


But the reality of malware research—the intense mental fortitude, the relentless strategic thinking—is often far less romantic and far more essential than we give it credit for.


Malware researchers aren’t just fighting sophisticated adversaries.


They’re engaged in a high-stakes, invisible chess game where each move reveals a little more of a hidden enemy.


The most significant challenge, however, isn’t the malware itself.


It’s likely the disconnect between the critical work of these researchers and the perception—and support—they receive from leadership.


That gap isn’t just unfortunate; it’s a vulnerability that leaves companies exposed in ways many don’t even realize.


Despite its impact, malware research remains one of the most misunderstood and demanding roles in cybersecurity.


In this episode, Dani Woolf, host of Audience 1st Podcast spoke with Michael Gorelik, CTO of Morphisec, and his insights offered a rare glimpse into a job that’s less about reacting to the latest threats and more about building a proactive defense—a foundation that keeps companies several steps ahead.


From firefighting immediate threats to pioneering innovative defense strategies, Michael’s work underscores the essential, often-overlooked nature of malware research.


He emphasizes the critical need for passion and motivation among malware researchers, details the daily responsibilities of malware analysts and incident responders, and explores the ethical challenges faced in the field. 


Michael also outlines how Morphisec innovates in the ransomware protection space by leveraging Moving Target Defense and proactive visibility, as well as his philosophy on breaking routines to manage stress and maintain team morale. 


The episode also highlights the importance of effective communication between different organizational levels and offers advice to both researchers and executives for enhancing mutual understanding and appreciation.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Why Traditional Analyst Models Are Failing Your Cybersecurity GTM Strategy14 Nov 202400:47:48

When was the last time you took a hard look at how disconnected your “customer insights” really are from the people you’re aiming to serve?


For years, companies have banked on traditional research firms and analyst reports, hoping these broad-stroke insights will guide their GTM strategies.


These methods serve a general narrative – not the nuanced truths that drive real connection and real value.


I fell into the same trap myself once.


I’d rely on this filtered, “aggregate” data and call it good.


But the more I engage directly with the people who matter – the end users, the practitioners – the more I realize:


The traditional analyst model is fundamentally broken.


And no one’s ready to admit it.


In the SEASON 3 kickoff of Audience 1st Podcast, I'm sitting down with Ben Siegel, GTM expert, former Gartner exec, CEO and Founder of The CyberNest, and partner in crime, to dive into a major shift in how cybersecurity companies connect with their buyers.


We’re challenging the old-school analyst model, pushing past generic reports and stale data to champion DIRECT relationships with the people who matter—security practitioners.


We’ll explore why hands-on research like interviews, focus groups, and community-led conversations are game-changers for your GTM strategies.


This conversation might very well be the wake-up call we ALL need.


Are you ready to break out of the echo chamber?



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
The PhD Cryptographer Who Bet His Career on a Lukewarm Idea and Succeeded28 Feb 202600:45:58

Aleksandr Yampolskiy was doing everything right. He had the tools, the budget, the processes - the full security stack humming along at the e-commerce company where he served as CISO.

Then one routine vendor integration blew the whole thing open. Unencrypted credit card data from other customers, just sitting there, inside a platform that had been rubber-stamped by a Big Four firm.

In that moment, he realized something most security leaders spend their careers trying not to think about: you can do everything right and still lose your job because someone else didn't.

That scar became SecurityScorecard.

But here's where the story gets interesting. When Aleksandr, or AY - as he introduced himself when joining me in my studio, started telling people in 2013 that he wanted to quantify cyber risk the same way credit scores quantify financial risk, nobody was excited.

The reactions ranged from "that's impossible" to a polite shrug. Most founders would have taken that as a signal to pivot. Alex took it as proof he was early enough to matter.

In this episode, we go deep. We talk about why the status quo, not a named competitor, is the most dangerous thing your sales team will ever face.

AY tells the story of twenty buyers who all said "I love it, I'll buy it" and then every single one of them disappeared when he came back with the finished product. (Oh, how I resonate deeply with this pain.)

He explains how a pediatrician named Dr. Virginia Apgar, who saved tens of thousands of newborns with a simple scoring system, became the intellectual blueprint for how Security Scorecard thinks about risk.

And he gets honest about hiring decisions that went wrong because he ignored a gut feeling he couldn't quite articulate at the time.

We also get into territory that most cybersecurity podcasts don't touch. AY talks about boards adopting AI to impress Wall Street while CISOs scramble to secure shadow deployments nobody authorized.

He walks through why 150 companies control ninety percent of the global attack surface and what that means for everyone else.

He makes the case that quantum computing will be a Y2K-scale migration problem much sooner than the industry wants to admit.

And he shares a question from his company advisor that I think every GTM leader needs to sit with: Who do you want your customers to become?

This is a conversation about how a scientist thinks about risk, why the language gap between the SOC and the boardroom is an actual vulnerability, and what it really takes to build something that changes how an industry operates.

Listen in and enjoy.

A special thanks to our friends at SecurityScorecard for partnering with us to tell this story.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Black Hat vs. RSA CISO Perceptions: Which Do They Prefer and Why?16 Aug 202400:48:12
In this episode of Audience First, Dani Woolf welcomes cybersecurity expert and CISO of CYE, Ira Winkler. They delve into vendor practices, inclusion in cybersecurity events, and the need for meaningful content from marketers. Winkler highlights his initiative, CruiseCon, designed to be inclusive for all levels of professionals, and shares advice on building genuine relationships in the field. The conversation also touches on the challenges and dynamics of cybersecurity conferences like Black Hat and RSA.

Key Takeaways:

  • Ensure that events provide access not only to executives but also to practitioners at all levels, enabling broader networking and learning opportunities.




  • Push for an end to the tiered experiences at events like Black Hat and RSA, advocating for equal opportunities and benefits for all attendees, regardless of status.




  • If you're in sales or marketing, do thorough research on your targets. Avoid aggressive, impersonal tactics like cold-calling and spamming LinkedIn. Instead, personalize your outreach.




  • If you're a small cybersecurity startup, target mid-sized companies to build credibility and grow sustainably, rather than immediately chasing large enterprises.




  • Invest in creating thought leadership content that addresses real problems and delivers value to practitioners, rather than just promoting products.




  • As a conference attendee or organizer, push for sessions that offer substantial research and insights, avoiding vendor pitches disguised as informative talks.




  • Advocate for a balance between commercialization and the original mission of conferences like Black Hat, ensuring that they continue to offer valuable content.




  • Whether interacting with current executives or former leaders, always treat individuals with respect and tailor your approach to their unique experiences and needs.




  • Encourage conference organizers to reassess and reallocate session content to maintain high-quality and relevant tracks, ensuring that attendees receive maximum value.




Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Securing the Healthcare Industry: Insights from the Frontlines of Change Healthcare Attack and More08 Aug 202401:02:11

In this episode of Audience 1st, Cecil Pineda, CISO of R1 RCM, and Yuval Wollman, President of CyberProof, delve into the cybersecurity in the healthcare industry. They discuss the impact of recent cyber attacks on healthcare organizations, specifically the Change Healthcare attack, the importance of vision in cybersecurity, and the challenges faced by CISOs in aligning security practices with organizational goals. The conversation highlights the need for speed, preparedness, and strong communication in managing cybersecurity incidents effectively.


Key Takeaways:
  • Rapid response and speed are crucial in managing cybersecurity incidents effectively.

  • Healthcare organizations must prioritize data protection and establish robust security measures due to the complex web of connectivity in the industry.

  • Collaborative partnerships with vendors and community engagement are essential in enhancing cybersecurity resilience.

  • Balancing consolidation versus layered approach in cybersecurity tools requires considering organizational risk and complexity.

  • Cultivating a culture of openness, trust, and clear communication is vital for effective cybersecurity practices.


Subscribe to Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
B2B Marketing Shifts: Insights from the Lens of a Marketer and a CISO01 Aug 202400:47:51

In this episode, Dani Woolf, CEO and Founder of Audience 1st, brings her 15 years of experience in tech marketing to the table. She shares her journey from working in-house as a marketer to running a qualitative customer research agency, driven by her frustrations and burnout in understanding the audience. 


Anthony Johnson, CEO and Founder of Delve Risk, with his 25 years in cybersecurity, contributes his insights on the shifts in sales and marketing, including changes in content consumption, the rise of personal branding, understanding of buying behaviors, and the increasing role of AI in B2B sales and marketing.


Throughout the episode, Dani and AJ delve into various aspects of the industry, from the significance of brand visibility and trust in the evaluation process when choosing security solutions to the challenges faced by marketing teams in adapting to new tools and technologies. They also discuss the impact of the COVID-19 pandemic on events and the shift towards creating more memorable and impactful experiences for targeted audiences.


Key Takeaways:

  • Content remains king, with a shift towards short-form videos, podcasts, and community-driven content creation.




  • Personal branding plays a significant role in establishing trust with buyers in the cybersecurity industry.




  • Marketers and sales professionals are adapting to the changing buying behaviors of customers, emphasizing empathy and personalization.




  • The integration of AI in sales and marketing processes enhances automation and efficiency but requires a human touch.




  • There is a growing trend towards unique and personalized experiences in regional events, focusing on quality interactions over quantity.




Subscribe to Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Bridging Security and Business: Insights from Onyxia’s 2024 CISO Research25 Jul 202400:37:20

In this episode of Audience 1st Podcast, host Dani Woolf and Sivan Tehila, Founder and CEO of Onyxia Cyber, discuss the role of CISOs and the importance of aligning security initiatives with business objectives. Sivan emphasizes the need for a strategic approach in managing security programs and highlights the significance of leveraging data to optimize security stack capabilities. Through Onyxia, Sivan aims to empower CISOs with a platform that provides insights, predictions, and actionable recommendations to enhance security operations effectively.


Key Takeaways:

  • The role of CISOs is evolving to include a stronger focus on bridging security teams with business operations and aligning security strategies with overarching business goals.




  • Onyxia Cyber offers a platform that integrates with existing security tools to provide CISOs with actionable insights, predictions, and optimizations for their security programs.




  • There is a growing need for CISOs to adapt to evolving cybersecurity regulations and leverage data-driven approaches to improve security posture and demonstrate compliance.




  • Continuous engagement with customers, sharing knowledge, and integrating feedback are crucial for developing impactful products and services that address the evolving needs of the cybersecurity community.




  • Collaborative efforts, community engagement, and a commitment to ongoing learning and adaptation are vital for advancing cybersecurity practices and fostering a culture of innovation in the industry.








Take a Tour of the Onyxia Platform: https://www.onyxia.io/book-a-demo


Subscribe to Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Breaking Silos: Why (and How) True Peer-Led Communities Help Attract and Retain Security Talent24 Jul 202400:53:07

In this episode of Audience 1st Podcast, host Dani Woolf welcomes Ben Siegel, Founder and CEO of The CyberNest. They delve into the importance of peer-led, community-driven research for cybersecurity professionals. Ben outlines The CyberNest’s growth from a free community to launching a specialized platform security teams aimed at facilitating better information sharing and collaboration within organizations. They discuss the limitations of traditional analyst firms and the rise of firsthand, trusted insights from security practitioners. The conversation emphasizes the value of making learning an integral part of security roles and explores the future of peer-led communities in the cybersecurity industry.


Key Takeaways:



  • Overwhelmed security professionals can benefit from streamlined access to relevant information through peer-led communities.




  • The Cyber Nest has evolved to offer a Teams platform that fosters collaboration and knowledge sharing among security teams within organizations.




  • Trust and quality are key factors in peer-led information sharing, enabling practitioners to make informed decisions and streamline projects effectively.




  • Bridging the gap between security vendors and buyers through expert insights helps improve product offerings and enhance customer relationships.




  • Cultivating a community of trust within the cybersecurity space is essential for promoting collaboration, knowledge sharing, and professional development.




Apply to become a member of The CyberNest today: https://thecybernest.com/


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How Security Practitioners Should Think About and Approach Double Layered Cloud Security11 Jul 202400:47:32

In this episode of Audience 1st Podcast, Avishai Wool, CTO of AlgoSec and Joshua Copeland, Director of Managed Security Services at Quadrant Information Security and professor at Tulane University, join host, Dani Woolf, to discuss the complexities of cloud security and the challenges practitioners face when migrating to the cloud.


They delve into the shift towards cloud-based infrastructure and the unique security human-centric, business, and technical considerations that come with it.


Avishai and Josh highlight the significance of understanding the interconnected nature of cloud and on-premise environments and provide practical steps to approaching a comprehensive, double layered approach to cloud security.


Key Takeaways:
  • The shift to the cloud brings about challenges in understanding what needs to be protected and how to address security risks effectively.

  • A successful cloud security strategy involves starting with visibility to identify misconfigurations and then focusing on network security to ensure connectivity between cloud and on-premise environments is secure.

  • To achieve good cloud security, organizations must align their security measures with business requirements and identify key stakeholders to make informed decisions.

  • The importance of having the right tooling in place for cloud security cannot be emphasized enough, as it helps in making informed decisions and managing thousands of security groups efficiently.

  • Assessing a brownfield cloud environment involves onboarding all accounts into a Cloud Security Posture Management solution to identify critical findings and assess the need for public IP addresses.

  • Understanding the nuances of cloud security requires a combination of knowledge, tools, and a thoughtful approach to addressing risks effectively in both greenfield and brownfield environments.


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Value Selling Tips: Aligning Cybersecurity Products with Security Buyer Business Priorities05 Jul 202400:50:10

In this episode of Audience 1st Podcast, Andrew Monaghan, Founder of Unstoppable.do and Host of Cyber GTM Talk. joins host, Dani Woolf, to discuss the power of value selling to drive success in the tech industry. With real-world examples and practical insights, Andrew and Dani dig into into the importance of understanding customer needs, engaging in ethical sales practices, and transforming the go-to-market approach to achieve sustainable growth.


Key Takeaways:
  • The key to successful sales is aligning your product with the biggest initiatives of your prospects. Show how you can help make their big goals a reality.

  • Value selling is not just about features and benefits, but about attaching your solution to the major business initiatives of your prospects. It's about impact and relevance.

  • Zscaler is a prime example of rigorous value selling, leading to substantial growth. It's about embedding the value sales mindset in leadership and translating messaging to focus on value, not just product features.

  • To shift to a value selling approach, sales professionals should lead by example, showcasing results before evangelizing the approach to stakeholders. Actions speak louder than words.

  • One of the worst practices Andrew has seen in security firms is fraudulently inflating numbers and channel stuffing for short-term gains. Ethics must be at the core of every go-to-market strategy.

  • Ethical go-to-market strategies are centered on truthfulness, transparency, and alignment with customer needs. Being ethical is not a choice, it's a must for building long-term customer relationships.

  • Value selling is about finding the why behind your prospects' actions, aligning your solution with their big initiatives, and driving impact. It's not just about selling a product, but about creating real value for your customers.

  • To excel in ethical go-to-market strategies, focus on being a good human being, portraying your company in the right light, and always staying true to your values. Ethics is not a compromise, it's a standard that must be upheld.


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Human Connection and Customer Advocacy as Differentiators in Cybersecurity | CyberMAYnia Podcast14 Jun 202400:41:08

In this episode of CyberMAYnia, Dani Woolf shares insights on the challenges faced while applying traditional marketing strategies in cybersecurity, Dani emphasizes the importance of customer research for business growth and customer retention. The discussion also explores the role of generative AI in marketing and how marketing in the cybersecurity space will evolve in the upcoming years.


Key Takeaways:



  • Patience and resilience are essential for marketers in the cybersecurity industry, as rejection and setbacks are common.




  • Collaboration between marketers and security practitioners is crucial for mutual success and innovation within the cybersecurity space.




  • Effective marketing strategies in cybersecurity require a deep understanding of the industry and its people, and a focus on community and advocacy.




  • Utilizing AI in marketing can enhance efficiency but must be approached with caution to avoid laziness and maintain quality.




  • Networking, curiosity, and asking questions are key for individuals entering the cybersecurity field, facilitating learning and growth.




Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
CISO Chronicles Unfiltered: The Pros - LIVE from CISO XC Conference31 May 202400:38:40

In this live episode from the CISO XC Conference in Dallas Fort Worth, Texas, cybersecurity professionals engage in a candid discussion on the challenges, frustrations, and human aspects of the cybersecurity industry.


Dani Woolf, Host of Audience 1st Podcast, and Allan Alford, Host of The Cyber Ranch Podcast, uncover the top aspects of cybersecurity that has CISOs hopeful, among them:


  • Increased Diversity of Thought and Background: One CISO expresses hope for the future of cybersecurity due to the increasing diversity of thought and background in the industry, which leads to a richer and more effective approach to security.

  • Passionate and AI-Equipped Generation: Another CISO is hopeful about the passionate and AI-equipped younger generation entering the field, highlighting their willingness to serve and collaborate.

  • Continuous Learning and Collaboration: The emphasis on continual learning and collaboration within the industry is a significant source of hope, as it fosters innovation and resilience.

  • Purpose and Fulfillment in Making a Difference: The fulfillment and noble purpose of making a difference and affecting change in the security industry drive many CISOs to stay hopeful and passionate about their roles.

  • Advancements in AI: While there are concerns, the advancements in AI are seen as a force multiplier that can significantly enhance cybersecurity capabilities when adopted effectively.


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
CISO Chronicles Unfiltered: The Cons - LIVE from CISO XC Conference23 May 202400:28:57

In this live episode from the CISO XC Conference in Dallas Fort Worth, Texas, cybersecurity professionals engage in a candid discussion on the challenges, frustrations, and human aspects of the cybersecurity industry.


Dani Woolf, Host of Audience 1st Podcast, and Allan Alford, Host of The Cyber Ranch Podcast, uncover the top frustrations of CISOs, among them:


  • The Need to Balance Empathy: Emphasize human connection, empathy, and treating employees like family to effectively engage in cybersecurity efforts.

  • Risk Acceptance: Encourage taking calculated risks with cutting-edge technologies rather than strictly adhering to outdated regulatory frameworks.

  • Authorizing Advanced Tech: Streamline technology authorization processes in defense sectors to keep pace with adversaries' advancements.

  • Sole Focus Marketing Tech Making Business Cases: Avoid focusing solely on technological capabilities, instead align purchases with organization-wide security strategies.

  • Expensive Dinners Over Transparent Communication and Relationship Building: Promote transparency and open conversations over incentivizing through expensive dinners, fostering genuine vendor-client relationships. 

  • Lack of Industry Collaboration: Highlight the importance of collaborative events for rapid maturity of cybersecurity practices and fostering a sense of community.

  • Negative Vendor Relations: Practice reciprocation and appreciation with vendors to cultivate strong support without manipulation.

  • Investment in Costly Sales Tools at the Expense of Security Tools: Advocate for a balanced financial approach where affordable cybersecurity investments are prioritized over costly sales tools.

  • Echo Chambers Over Open Discussions: Encourage CISOs to share both successes and failures openly for collective improvement and robust decision-making.


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How to Stop Falling for Fake Cyber Threat Exposure Management (CTEM) Claims19 Dec 202500:43:34

Every vendor in exposure management now says they do CTEM. Nick Lantuh's response: "You don't even know what you're talking about."

This episode with Nick Lantuh (CyberProof) and Amy Chaney (Citibank) breaks down how a methodology became a meaningless marketing term and how buyers can fight back.

The reality check:

CTEM requires connecting vuln scanning, endpoint, SIEM, cloud, email, network—not just one of them

Adding CAASM or external attack surface management doesn't make you a CTEM vendor

Most organizations doing "CTEM" are actually using spreadsheets and manual threat intel fusion

Why services-led beats platform-first (60x revenue growth proved it)

The disingenuity problem: vendors spray the term, buyers have to unpack it

Amy's evaluated these claims at the world's largest banks. Nick built the solution that actually connects the pieces. Together, they arm you with the filter.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
RSA Conference Post-Mortem: The Good, Bad, & The "Oh Hell No They Didn't"17 May 202400:48:14

Join Dr. Chase Cunningham, Elliot Volkman, Clark Barron, George Kamide and me for what may likely be the most brutally honest RSA POST-Conference Recap you'll get from real security practitioners AND cybersecurity marketers.

Whether you're a regular attendee, a first-timer, or someone who's always wanted to go but couldn't make it, this is your chance to hear it straight from the insiders.

Here's how it's going down:

→ We're going to kick it off with expectations vs. reality: Did the actual experience live up to the hype?

→ We're adding to the Audience 1st sh*t list to uncover the glaring misses or underwhelming moments at the conference that we think deserve a spotlight for improvement.

→ We'll share our thoughts on new technologies and trends that emerged from the conference.

→ We'll give you key insights and examples from various vendors and sessions that knocked it out of the park.

→ Are we heading back to RSA next year? YUP! We're going to talk about what might we do differently based on this year’s learnings.

→ And for our honorary guest who didn’t attend, we'll dig into perceptions of the RSA Conference through social media and second-hand accounts.


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Know Before You Go: Brutally Honest RSA Conference Truths02 May 202400:47:31

Join us for what may likely be the most brutally honest RSA Conference Truths you'll get from real security practitioners AND cybersecurity marketers. Whether you're a regular attendee, a first-timer, or someone who's always wanted to go but couldn't make it, this is your chance to hear it straight from the insiders.

Here's how it's going down:

→ We're going to kick things off by diving into the motivations behind our involvement in cybersecurity.

→ For those who have always wanted to attend RSA or are gearing up for this year, we've got seasoned advice tailored just for you. Learn how to make the most of the conference, what to prioritize, and how to navigate the show.

→ Ever wanted to just scream out your frustrations about RSA or cybersecurity events in general? Well, we're doing just that in a no-holds-barred segment where our guests and I let loose on everything from overhyped trends to the under-addressed issues that plague our field.

→ There are things often left unsaid in the cybersecurity space—flaws and all. We're breaking the silence on these topics, discussing what's wrong and why it’s rarely addressed openly.

→ Despite the challenges, there's always something to be hopeful for. We explore what's currently inspiring optimism in the world of cybersecurity and at the RSA Conference this year.


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Navigating the Trust Barrier: Effective Marketing Strategies for Skeptical IT Buyers11 Apr 202400:57:41

In this episode, Dani Woolf shares her journey from being a digital and demand gen marketer to founding an agency focused on helping cybersecurity companies understand their buyers.


Dani discusses the importance of building trust with IT buyers and provides insights into why they are skeptical. She emphasizes the need for marketers and sales professionals to shift their mindset from profits over people to people over profits.


Dani also presents a framework for building trust with IT buyers, including nurturing curiosity, empathy, and likability, as well as delivering value.


She shares valuable experiences and insights from conversations with IT practitioners and offers practical tips for acquiring and retaining customers.


Key Takeaways

  • IT buyers are skeptical due to the complexity of B2B buying processes, the abundance of information and products, and negative experiences with aggressive or outdated marketing and sales tactics.




  • Building trust with IT buyers is crucial for reducing risk, establishing lasting relationships, and providing peace of mind.




  • To build trust, marketers and sales professionals should nurture curiosity, empathy, and likability, and be transparent, reliable, accountable, and resourceful.




  • Active listening, understanding, and authentic connection are essential for acquiring customers and delivering value that aligns with their goals and business outcomes.




  • Avoiding buzzwords, focusing on customer stories and industry trends, and providing clear and concise information can enhance messaging and resonate with IT buyers.




  • Retaining customers and turning them into loyal advocates requires consistent support, responsiveness, and engagement throughout the customer journey.




  • Taking feedback to heart and continuously improving based on customer insights can lead to second chances and long-term relationships with skeptical IT buyers.




Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How MSPs Can Increase Sales Efficiency by Understanding Buyers at Scale04 Apr 202400:56:29

In this episode, Dani Woolf interviews James Farrow, co-founder of Cyft, about his journey from cybersecurity sales to building a solution that TRULY helps IT buyers and MSPs. James shares his change moment when he realized the importance of understanding customers as people and the challenges they face in the buying process. He discusses the insights he gained from conducting customer research and how Cyft is evolving to better serve the IT community. James also highlights the role of AI in enhancing the sales process and the importance of transparency in vendor-buyer interactions.


Key Takeaways:

  • Understanding customers as people and approaching sales conversations with empathy can lead to better outcomes and stronger relationships.




  • The gap between the way cybersecurity products are sold and how IT buyers want to buy creates challenges and confusion in the market.




  • Cyft is focused on helping MSPs and value-added resellers serve their customers by providing tools that streamline the sales process and enable better communication and collaboration.




  • AI can be a powerful tool for sales professionals, allowing them to capture and access important information quickly and easily.




  • Transparency and accessibility are key factors in building trust and improving the vendor-buyer relationship.




Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Turning B2B Marketing Anxiety into Action | Demand Gen Therapy18 Jan 202400:52:04

In this episode, Clark Barron, host of Demand Gen Therapy, interviews Dani Woolf about the challenges and disillusionment faced by B2B marketers today. They discuss the importance of deep introspection and understanding customers on a qualitative level. Dani shares her experience of circumventing obstacles to gather the necessary information to improve her marketing efforts. They also explore the mindset of marketers and the need for a sense of purpose in the industry. The conversation highlights the importance of moving away from generic personas and focusing on individual human beings.


Key Takeaways:


  • B2B marketers often face disillusionment due to being measured on metrics that don't make sense and working with limited resources.

  • Deep introspection and understanding customers on a qualitative level are crucial for solving the existential crisis in B2B marketing.

  • Circumventing obstacles and conducting research can provide valuable insights to improve marketing efforts.

  • Marketers in the security industry are often driven by a sense of purpose and a desire to affect meaningful change.

  • Marketers should be selective about the organizations they work for and focus on understanding their audience on a deep level.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
Mission Before Money: Refocusing Cybersecurity on What Matters11 Jan 202400:49:18

In an industry whose goal is to protect people, purely profit-driven marketing makes no sense - and certainly doesn’t work.


After over a decade of running digital marketing for high-growth B2B technology startups, my guest, Dani Woolf, realized marketing is wildly different in information security. 


It took her four years after joining the cybersecurity industry in 2018 to create Audience 1st, a customer research agency built on four pillars: 



  • curiosity to truly understand audiences




  • empathy to listen first and identify cybersecurity buyers' pain points




  • dedication to provide insights that promote growth




  • and honest connection to establish authentic relationships with buyers. 




 


Dani Woolf continues to do meaningful work for people who care as the Creator and Host of the Audience 1st podcast and the WTF Did I Just Read? Tech Sales and Marketing Edition Podcast


Throughout this conversation, Dani shares her thoughts on marketers' role in cybersecurity, her "mission before money” mindset, and why repetition and messaging consistency are crucial in this space. 


You'll also hear why we need leaders who choose peaceful and kind ways of communicating and why Dani believes the creative tension between old-school and modern marketers in cybersecurity is a good thing. 


Additionally, Dani explains how she uses honesty to get real, deep insights from tech and IT pros, why she doubles down on being pragmatic and practical, and more ways to create positive change.


Listen to this episode to learn:



  • Why Dani advocates for slowing down and opening our hearts in cybersecurity (3:00)




  • How to avoid leaving people out through black-and-white approaches in communication (7:50)




  • Why having creative tension is a good thing (14:40)




  • How marketers can make a meaningful contribution to cybersecurity (18:30)




  • How to set expectations to have in-depth conversations with tech and security leaders (27:00)




  • Why it’s crucial to connecting with audiences beyond data (34:00)




  • Which benefits come from being pragmatic, practical, and prescriptive (41:20)




Listen to the original episode at Cyber Empathy.



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
The Cyber Market’s Harsh Truth: A Vendor Vs. Buyer Reality Check | Ross Haleliuk11 Jan 202400:51:03

Ross Haleliuk joins the Audience 1st Podcast to discuss his background and his work in the cybersecurity industry. He shares his motivation for creating his blog, Venture in Security, and explains how he aims to simplify complex cybersecurity concepts for readers. Ross also discusses the challenges and opportunities in the industry, including the need for better evaluation methods for security tools. He highlights the importance of building relationships with security practitioners and the need for more diversity of experiences in the industry. Ross concludes by introducing his new book, "Cyber for Builders," which provides insights and guidance for building cybersecurity companies.


Key Takeaways:



  • Ross Haleliuk's Diverse Roles: Ross discussed his multifaceted involvement in the cybersecurity world, including his positions at Lima Charlie, Venture in Security, and an angel syndicate for security practitioners. His diverse experiences provide a well-rounded perspective on the industry.




  • Cybersecurity's Complexity: Ross shared his initial hesitations about entering the cybersecurity field due to its complexity. He eventually embraced the challenge, finding a passion for demystifying cybersecurity concepts for broader audiences.




  • Creation of Venture in Security: Motivated by a desire to simplify cybersecurity knowledge, Ross started Venture in Security. He aims to make complex topics accessible to various stakeholders in the industry, including founders, marketers, salespeople, and practitioners.




  • Breaking Down Complexity: Ross emphasized the importance of simplifying cybersecurity topics. He believes in making the industry understandable to those new to the field and those from different professional backgrounds.




  • Vendor-Practitioner Dynamics: The conversation touched on the challenges between cybersecurity vendors and practitioners, highlighting issues like stigma, accessibility, and the one-sided nature of many vendor-practitioner interactions.




  • Asymmetry of Information: Ross pointed out the significant information asymmetry in cybersecurity, where buyers struggle to assess the value and effectiveness of security tools, and sellers often make unverified claims.




  • Bridging Industry Gaps: Ross suggested ways to bridge the gap between vendors and practitioners, emphasizing the need for building authentic relationships, and better understanding the needs of practitioners.




  • Evaluating Cybersecurity Tools: The interview discussed the necessity for improved methods to evaluate cybersecurity tools, highlighting the challenge in assessing the effectiveness and value of these tools.




  • Cyber for Builders Book: Ross announced his book, "Cyber for Builders," which serves as a comprehensive guide to building cybersecurity companies. The book covers industry understanding, trend evaluation, team assembly, fundraising, and go-to-market strategies.




Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
How Security Practitioners Master API Security in the Regulatory Landscape04 Jan 202400:48:31

In this episode, host Dani Woolf is joined by Sue Bergamo, James Azar, and Chuck Herrin to discuss the challenges of API security in the context of digital transformation. They highlight the lack of visibility, tools, and control in organizations when it comes to API security. The panel emphasizes the importance of understanding the data flowing through APIs, having a clear ownership structure, and implementing secure development practices. They also discuss the impact of regulations and compliance on API security and the need for organizations to educate themselves and align their language with developers and application owners. In addition, the guests stress the importance of communication, collaboration, and education in addressing API security challenges.


Guests at a Glance:



  • Sue Bergamo: Sue Bergamo is a longtime CIO and CISO who currently works as an executive advisor for BTE Partners. She advises innovative CEOs on cybersecurity and is passionate about protecting and securing data.




  • James Azar: James Azar is the CTO and CSO of AP4 Group, a critical infrastructure company. He is responsible for the internal technology and security practices of the company and works with power plants, oil and gas companies, and aviation organizations.




  • Chuck Herrin: Chuck Herrin is the CTO of an API security company called Wib. He has decades of experience as an attacker and defender and has served as a CISO multiple times. He is passionate about API security and helping organizations protect their data.




Key Takeaways:


  • Lack of visibility, tools, and control are major challenges in API security.

  • Organizations need to understand the data flowing through APIs and implement secure development practices.

  • Ownership and accountability for API security should be clearly defined within organizations.

  • Regulations and compliance frameworks are starting to specifically address API security.

  • Security vendors should focus on eliminating false positives and providing guidance on addressing API vulnerabilities.

  • Communication and collaboration between security teams and application owners are crucial for effective API security.


Join Audience 1st Newsletter Today


Join 1700+ cybersecurity marketers and sellers mastering security buyer research to better understand their audience and turn them into loyal customers: https://www.audience1st.fm/newsletter



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit audience1st.substack.com
© My Podcast Data · Projet indépendant · Données issues d'Apple & Spotify