This website uses cookies

Read our Privacy policy and Terms of use for more information.

What you'll learn

  • Diana Jovin's position is that "attribution is stupid" — no single webinar, booth, or podcast moves an enterprise deal, so the marketing question is whether the whole mix is working, not which touchpoint gets credit.

  • AFK is pulling customer success teams apart at her clients, moving non-technical CSMs into sales and technical ones into product, and ran a test where identical job descriptions labeled "FDE" instead of "CSM" drew far more and far better applicants.

  • The buying cycle hasn't gotten shorter, it's gotten invisible: most of it now happens outside the vendor's view, which means the SDR who cold-calls asking about your priorities and the CSM who opens a kickoff asking what your goals are have both already lost.

Description

Diana Jovin is Chief Marketing Officer at Teleport and has spent three decades building categories in enterprise software. Amelia Forrest Kaye — AFK — is a fractional Chief Customer Officer who ran customer experience at Tanium, Salt Security, and Expel, now runs her own consulting practice advising Series A through C companies, and recently co-authored a thought piece with Bain colleagues arguing for merging product and customer orgs. Stuart Mitchell, CEO of Hampton North, co-hosts. We recorded this on the floor at Black Hat, and it's a different episode for Zero Signal: instead of a CISO talking about risk or a VC talking about bets, this is a long-form conversation about how cybersecurity vendors actually get to market — and why so much of what they do annoys the people they're selling to.

The core argument runs like this. The buyer now shows up already researched, already holding a hypothesis, and already halfway to a decision. That kills the funnel as a planning model, breaks attribution as a measurement model, and exposes every role that exists to "educate" a buyer who is better informed than the person calling them. From there the conversation goes into what Black Hat is actually for (relationships and customer retention, not booth-driven discovery), why AFK is dissolving CS teams and rebranding roles as forward deployed engineers, how marketing budgets are splitting between search for humans and search for agents, why token-based pricing is "fuzzy math" that post-sales has to clean up, and why Diana spent ten hours thinking before writing a single word of her last white paper. This one is for founders and GTM leaders in security who want to hear what a CISO buyer actually experiences, and for CISOs who want to understand the machine on the other side of the table — including the part where, as AFK points out, you're selling all day too.

What we cover

  • "I think attribution is stupid." — Diana on why no single marketing touch closes an enterprise security deal, and what she measures instead.

  • "Every conversation that you start now, is a bottom-of-funnel conversation." — Why the funnel was a paper-era construct and what replaces it now that LinkedIn publishes everyone's title.

  • "What flavor of CISO are you?" — AFK on why treating every CISO as one persona is ridiculous, and why personal liability makes the vendor call harder.

  • "everyone is allergic to pitches" — What Black Hat is actually good for: HallCon, customer retention, and the Andy Ellis rule for CISO dinners.

  • "don't show up to the kickoff call and ask them what their goals are" — The SDR who hasn't earned the conversation, and the post-sales sin that deserves a slammed door.

  • "we exit the full CS team and split folks up between sales and product" — AFK's org model, the case for forward deployed engineers, and the job-title experiment that changed her mind.

  • "SEO traditionally has been very much a demand generation investment. GEO, I think, is a brand management investment." — Marketing to agents, and how frontier model choice is quietly deciding who sees your brand.

  • "We make up a number." — Value-based pricing in practice, token cost black boxes, and why buying from your golf buddy shows up as churn.

Thank you to our Sponsors:

RISC Point is security & compliance consulting tailored to your business. Talk to RISC Point.

Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North.

Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending.

The conversation

The funnel died when the buyer started doing the research

Diana's first move is to reject the premise that security buyers are uniquely hard. The change she's describing happened across every market: people research on their own, form a hypothesis, and arrive at the vendor having already done most of the work. Her line is that "anybody who uses top of funnel in their marketing speak, I think is in the wrong place in the marketing landscape." The job isn't to educate someone who doesn't know they have a problem. It's to meet a person who already knows, and speak to their specific problem in the first conversation instead of forcing them through the vendor's process.

She traces the funnel back to its origin: paper. You needed leads because you didn't know who worked at a company. You brought people to a room, counted who showed up, and guessed who was in a buying cycle. None of those constraints exist. "We know who all the people are," she says. The other thing the industry learned the hard way is that "you can't force a company into a buying cycle, like you can't make them have a problem that they that they don't have." What you can do is publish content in the language the buyer uses while researching, read the signals, and be ready for the moment they want to talk. The cycle may be the same length. Most of it just happens where you can't see it.

That's where attribution falls apart. Stu asked how a marketing leader claims credit for a podcast or an ad, and Diana didn't hedge.

❝

"There is no world in which a webinar or a event, or or this or that is going to be the single thing that moved a customer engagement over the line."

— Diana Jovin

If a buying team ran a proof of value, the deal belongs to the proof of value, not to a discrete marketing asset. What she wants to know is whether the overall mix of ways a customer can engage is performing, and whether changing the mix or the content improves it. From the buyer's chair, this is the first vendor take on marketing I've heard that matches how I actually buy.

What Black Hat is actually for

Stu put the ROI question to AFK directly, and she answered by rerouting to the buyer first. Before you can sell to a CISO you have to know which one you're talking to. Legal CISO, compliance CISO, the Microsoft-and-Air-Force government type, the comp-sci lifer, the developer who drifted into security, the MBA who decided to become one. "Trying to target you all like you're all the same, is ridiculous." She's built profile types for exactly this reason. Then there's the pressure: personal liability now lands on the CISO, which makes every vendor decision feel like "everything is on me if I make this bad vendor call." Her read on Vegas is that it's partly an escape from that.

Diana turned the question on me, and my honest answer is that I come for three things, and the booth isn't one of them. The people I respect are in the same building, and the speed of information sharing is nothing like Zoom — a hallway conversation with a guest yesterday turned into coffee with his head of product security tomorrow. Vendor discovery happens, but it's downstream of that: peers tell me the three companies worth talking to, and then I find a human and give them thirty seconds. And because I'm the CISO at a product company, I get the second half too — sitting in a room with customers and design partners for 45 minutes hearing what's working and what isn't. Diana's own list is the same shape: executive meetings, product people getting feedback on unannounced demos, media, and the community. "It is the specific meetings that occur, not at the booth, but in a meeting room or in a private conversation. Those are extremely valuable."

Stu made the point that Black Hat is far better for retention than prospecting, because you're competing with 30,000 people for a prospect's attention but your existing customers will make time. AFK went further and said her best conversations here were planning for engagements elsewhere.

❝

"I don't want to talk to them about any of that stuff. I want to invite them to an intimate dinner in in their city, close to a place that they like, and and tell them that they're just going to meet their peers, and they're going to be able to bitch and moan to their peers."

— Amelia Forrest Kaye

That connects to the Andy Ellis rule from an earlier episode: if you host a CISO dinner, half the table should be current customers, so prospects can ignore the sales team and ask what it's really like. AFK's addition is that customers talking to each other is the fastest way to surface use cases nobody bothered to explain — "we don't even use it for that, we use it for this other thing" — which is where expansion actually comes from.

The SDR who hasn't earned the conversation, and the CSM who hasn't either

Stu asked whether the SDR role has any future when buyers arrive informed, and Diana split it into two people. The first calls without making clear who they work for and asks, "Tell me about your marketing priorities for the year." Her response: "Why should I tell you about the marketing priorities for the year, right? Like there's you haven't earned the right to have a conversation, or trust, or showed that you understand anything about why you're having the conversation." The second knows what engagement your company has had, has a specific reason to reach out, and offers something that moves your thinking forward. That person has a job. The question is whether the company has built the tooling to make the second version the default.

Stu named Clay as an example of that tooling, and made the broader point that buyers now leave far more breadcrumbs — the content we publish, the podcasts we sit on — than they used to, which is what makes go-to-market engineering a real skill. The expectation has flipped. When a human finally gets on the phone, they'd better be almost uncomfortably well informed, and if they ask something the research already answered, respect drops immediately.

AFK carried the same logic across the sale into post-sales, where she sees the identical failure.

❝

"My favorite bad one that I advise every post-sales person against is don't show up to the kickoff call and ask them what their goals are. They will slam the door in your face, or they should! You deserve that! Because guess what, there was this whole buying process before. If you don't know what their goals are, what have you been doing?!"

— Amelia Forrest Kaye

She was blunt that both SDRs and CSMs are a diminishing breed for the same reason: they show up and ask questions the buying process already answered.

Exit the CS team

The org design AFK is running at several clients is the sharpest thing in the episode. She's dissolving customer success as a standalone function and splitting it: the relationship-oriented generalists go to sales, the technical people go to product. Her diagnosis is that the gap between product and customers got so wide that companies hired a whole layer of people to stand in it, "rather than humans as crutches." Pull product closer to customers and you build things that match real use cases and get into the roadmap faster. The Bain piece she co-authored proposes a blended customer-product org — she concedes "chief customer and product officer is a mouthful" — and she doesn't insist on the title, only on closing the gap.

Her sharper complaint about security vendors specifically is that most aren't even hiring technical people to serve technical buyers. You get "a lovely generalist who's good at asking questions and building relationships, but they can't actually help you solve your very technical use cases." Stu's aside — "Talking to a red team. Great." — is the whole problem in four words. That's why CISOs hang up. Her three options are: move the non-technical people to sales, move the technical people to product, or hire forward deployed engineers who can do custom deployments, communicate, and solve problems on the fly.

The only thing I care about as a buyer is whether any of this gets me an outcome faster. AFK's answer has two parts: the buying process should have already proven the tool solves the problem before I ever meet post-sales, and post-sales needs the power and skill to actually change something rather than "I'll submit a ticket on your behalf, and we're going to wait." I'm allergic to that answer. I do not care that my problem is on the product board.

Diana reframed the FDE question as a marketing question, which I didn't expect and think is right. You're not solving a point problem and leaving; you're starting a relationship that delivers more over time, so the post-sale experience is still part of how the brand gets built.

❝

"How you show up for the customer is how you build your brand. Your brand is that experience, right?"

— Diana Jovin

AFK's own about-face on FDEs is the evidence. She admits she thought the title was "lipstick on a pig" a year ago. Then she ran identical job descriptions with different labels — CSM or TAM on one, FDE on the other — and the FDE posting drew dramatically more applicants from better-known schools and companies with broader skills. She's now telling clients to relabel post-sales roles for that reason alone. Marry that with putting engineers inside the sales cycle and next to product, and you have something a CISO would actually want on the other end of the phone.

Marketing to humans and marketing to agents are different budgets

Diana's framing of AI's impact on GTM is that it's changing the market, the buyer's experience, and how marketing operates, all at once. The buyer piece is the one to watch: agents doing your research today, possibly installing your products in two years. So she's now interrogating the AI tools she uses — where did you get this, how did you arrive at that conclusion — and learning things like "my tokens consumption was kind of low, so I only read like the first third of the page and I didn't read the rest, and I just relied on my training data." The surface area you have to manage just got much bigger, because agents learn about your company from places that aren't your website.

Her split of SEO and GEO is the cleanest I've heard. SEO is about people finding your content through search — a demand generation investment. GEO is about how agents consume your content, where offsite they learn about you, and whether they're guiding people "in a confidently wrong way." That's brand management. Stu added the third piece: the first place a CISO goes with a problem now isn't Google or a peer, it's Claude, so dollars are flowing to being surfaced by the LLMs themselves. Click-through as an ROI metric is breaking under all of this.

AFK brought a concrete failure. A partner discovered they'd been optimizing against Claude, while OpenAI's agents were determining brand credibility from an obscure, "human-disrespected" website nobody would take seriously. They weren't reaching the right people or the right agents because of which frontier model they'd picked to test with. Three-ish frontier models plus harnesses on top means information isn't evenly distributed, and brands are being quietly pigeonholed in places they can't see. Stu's caution is that SEO has a known playbook and GEO is a dice roll. Diana's response is what a security leader should hear too.

❝

"I want someone to wake up thinking about it every day."

— Diana Jovin

If GEO is tacked onto an existing playbook, you're underinvesting. But she pulled it back to fundamentals: authority comes from having something worth saying that delivers real value, and if AI just accelerates what everyone else is already saying, "you're just adding to the noise that is AI slop out there."

"We make up a number"

I wanted to talk about pricing because I can't figure out how to buy AI-powered security tools. AFK's answer is that founders can't either. When she asks about pricing and packaging, they say "value-based pricing." When she asks what that means: "We make up a number." Fuzzy math happens in pre-sales, post-sales has to deliver on it or clean up after it, and now there's no clean way to tie tokens per prompt to an outcome. The CFOs she works with at Series A through C tell her they have no idea what to tell the board because usage swings every quarter.

The model she likes comes from a couple of security founders who built a warning into the product: you're about to ask something expensive, here's a cheaper way to ask it. She wants that everywhere — "give me a numerator and a denominator" — so the buyer knows what they've spent relative to what they're getting. My cynical read is that with most fixed-price contracts the vendor eats the token risk, so they're saving their own money. But teaching the buyer to be a smarter user of the product is real value either way. AFK's bigger point is that the old ROI calculators were nonsense, but the need behind them is back: CISOs are now business strategists who have to tell a board the stack is saving money and reducing risk. Diana's addition is to look for places where AI does something you couldn't do at all before, because that lands an order of magnitude harder than efficiency gains.

Her myth-busters session produced the other pricing-adjacent point. True or false: buy from people you know and trust. Everyone says true. She says false, because founders funded by the same investor buy each other's products at the bar, and it lands on her teams as churn with no outcomes ever defined. "Listen to people you know and trust, talk to people you know and trust, don't buy from them." Stu's honest reply is that a high percentage of US transactions happen exactly that way.

The episode closes on what's changed since RSA. Diana's white paper, "From Zero Trust to Agent Trust," was written the old way — ten hours thinking about the core argument before writing, because the argument didn't exist in the literature. AI's role: "It should be an assist, it should not replace." AFK's is that clients used to want to hear about her AI workflows and now light up that she writes her own emails and builds her own decks. Stu's is that his team's instinct to reach for Claude first made some of them less productive, and that CISOs feel calmer because three years into this mess we at least know what we're dealing with. AFK's parting shot is the one I'll keep: CISOs sell all day — to the board, to engineers who won't follow policy — so "CISOs have more in common with the go-to-market community than they think." They'll never admit it.

Show notes

Guests — Diana Jovin, Chief Marketing Officer at Teleport, category builder in enterprise software for three decades; Amelia Forrest Kaye (AFK), fractional Chief Customer Officer, formerly ran customer experience at Tanium, Salt Security, and Expel, runs her own consulting practice launched just under two years ago, co-author of a Bain thought piece on blended customer-product orgs. Co-host: Stuart Mitchell, CEO of Hampton North.

Books mentioned — None named in the conversation.

Frameworks / models / tools named — The funnel / top-of-funnel; bottom-of-funnel; attribution; proof of value; buying cycle vs. sales cycle; CISO profile types; HallCon; the Andy Ellis rule (half the dinner table should be current customers); blended customer-product org; forward deployed engineer (FDE); CSM / TAM roles; go-to-market engineering; SEO; GEO / AEO; Clay; LinkedIn; Claude; OpenAI / ChatGPT; Bing; Superhuman; Claude design; Gamma; Figma; value-based pricing; token-based pricing; ROI calculators; myth-busters session; zero trust; "From Zero Trust to Agent Trust" (Teleport white paper); vibe hunting (Damian Lewke).

Other people / shows / resources referenced — Andy Ellis (prior Zero Signal episode); Mike Ferrari (RSA conversation); Damian Lewke, Nebulok; Palantir (origin of the FDE role); Bain; Black Hat briefings; RSA Conference; DEF CON; Tesla; Microsoft; Sysdig; Tanium; Salt Security; Expel; Teleport; Hampton North.

Hosted by Conor Sherman and Stuart Mitchell.