How to sell your soul, err, your security program
Jenn Gile (Co-founder · Open Source Malware)
BSidesSF 2026 · Day 2 · AMC Theatre 12
Overview
In "How to sell your soul, err, your security program" at BSides SF, Jenn Gile, co-founder of Open Source Malware, tackles a pervasive challenge faced by security professionals: securing buy-in and resources from internal stakeholders who often prioritize different metrics. Gile argues that the traditional approach of trying to convince others to care about security for its own sake is fundamentally flawed. Instead, she champions the adoption of product marketing principles to reframe security initiatives in terms that resonate with an organization's diverse internal "customers."
Key moments
- 0:30 Core principle: Talk about what stakeholders care about
- 4:00 The security messaging problem: stakeholder priorities vs. security KPIs
- 5:06 What product marketing is and why it's valuable for security
- 6:40 Overview of the 5-step framework for communicating value
- 7:30 Step 1: Identify your internal buying committee and key groups
How to sell your soul, err, your security program
Speakers: Jenn Gile
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=dNrNUt1Bj50
Overview
In "How to sell your soul, err, your security program" at BSides SF, Jenn Gile, co-founder of Open Source Malware, tackles a pervasive challenge faced by security professionals: securing buy-in and resources from internal stakeholders who often prioritize different metrics. Gile argues that the traditional approach of trying to convince others to care about security for its own sake is fundamentally flawed. Instead, she champions the adoption of product marketing principles to reframe security initiatives in terms that resonate with an organization's diverse internal "customers."
This talk is not about technical vulnerabilities or new attack vectors, but rather a crucial meta-skill for security leaders and practitioners. It provides a structured methodology, borrowed directly from the world of product marketing, to understand stakeholder motivations, craft compelling messages, and ultimately achieve a resounding "hell yes" for security programs. Gile’s insights are vital for any security professional struggling with budget approvals, developer friction, or a general lack of perceived value for their critical work.
The core premise is that if security teams can articulate their value in terms of developer productivity, uptime, release velocity, revenue generation, or cost reduction – rather than MTR (Mean Time to Remediation) or vulnerability counts – they will unlock greater collaboration and support. By treating the security program as a "product" and internal stakeholders as "customers," security professionals can leverage proven communication strategies to bridge the gap between technical security concerns and broader business objectives.
Background
▶ Watch: Core principle: Talk about what stakeholders care about (0:30)
The genesis of this problem lies in a fundamental disconnect between what security teams are typically measured on and what other business units prioritize. Security professionals often focus on metrics like Mean Time to Remediation (MTR), total new vulnerabilities, or compliance scores. While these are critical for assessing security posture, they rarely align with the Key Performance Indicators (KPIs) that drive engineering, finance, or product teams. Developers, for instance, are often incentivized by release velocity and shipping features, while finance is concerned with cost reduction and revenue. When security initiatives are presented solely through a security lens, they are often perceived as blockers, cost centers, or sources of friction, leading to resistance and a lack of organizational support.
Jenn Gile, drawing from her extensive experience in both technology and product marketing, highlights that this isn't a unique issue. In the broader tech industry, sales and marketing often face skepticism, yet they consistently succeed in convincing people to buy software. This success, she posits, is largely due to the application of product marketing principles: understanding customer pain points and aligning product messaging to clearly communicate value in terms the customer understands and cares about.
Prior work in internal security advocacy has often focused on basic communication skills or translating technical jargon into business terms. However, Gile's approach delves deeper, suggesting a systemic adoption of a professional discipline. She argues that just as a product marketer figures out how to sell a complex technical product to someone who has never built it, security professionals can learn to "sell" their internal programs to non-security stakeholders. The challenge isn't making people care about security, but rather making security relevant to what they already care about – a critical distinction that forms the bedrock of her methodology.
Key Findings
▶ Watch: The security messaging problem: stakeholder priorities vs. security KPIs (4:00)
The central finding of Jenn Gile's talk is that the principles and methodologies of product marketing are directly transferable and highly effective for internal security teams seeking to gain stakeholder buy-in. She identifies a five-step process that security professionals can adopt to reframe their programs and messaging:
- Identify Your Buying Committee: Recognizing that different stakeholders (technical champions, budget holders, influencers) require tailored communication.
- Research the Buying Committee: Moving beyond assumptions to gather qualitative (hopes, dreams, pain points) and quantitative (data, trends) insights into what truly matters to each group.
- Develop Personas: Creating detailed, work-bound descriptions of stakeholder groups, focusing on their motivators, attitudes towards security, responsibilities, key metrics, and pain points. This is distinct from generic, non-work-related personas.
- Write Messaging Guides: Crafting persuasive communication frameworks for specific security initiatives, detailing the problem statement, its impact on the persona, business value, technical value, evidence, and a clear call to action.
- Validate Messaging: Actively testing the developed messages through interviews, trusted advisors, and small-scale project rollouts to ensure accuracy and effectiveness.
Gile emphasizes that this isn't about manipulation, but about empathy and effective communication. By understanding the "market" of internal stakeholders and aligning security's "product" (the program) with their perceived value, security teams can transform resistance into enthusiastic support. A significant secondary finding is the role of Artificial Intelligence (AI), particularly Large Language Models (LLMs) like Claude, in accelerating and scaling certain aspects of this process, especially for synthesizing research and generating tailored communication drafts, once the foundational human-centric work is done.
Technical Deep Dive
▶ Watch: What product marketing is and why it's valuable for security (5:06)
The core of Jenn Gile's methodology involves a structured, five-step process borrowed directly from product marketing. This approach is designed to systematically understand internal stakeholders and craft compelling messages that resonate with their priorities.
Step 1: Identifying Your Buying Committee
The first crucial step is to recognize that not all stakeholders are equal, and different roles require different communication strategies. Gile categorizes internal stakeholders into three primary groups:
- Technical Champions: These are the individuals most likely to understand the technical aspects of your security program and directly engage with it. For an application security (AppSec) team, this might include developers, engineering managers, and architects. These are the people who triage findings, implement fixes, and use security tools daily.
- Budget Holders: As the name suggests, these are the individuals with the authority to approve or deny funding. This typically includes senior leadership such as the CISO (Chief Information Security Officer), CTO (Chief Technology Officer), or CIO (Chief Information Officer). Depending on the organization, a Head of Infosec or even a Head of Product Security might also hold significant budgetary power.
- Influencers: These stakeholders may not directly use your tools or hold the budget, but they have the power to "kill your deal" or significantly impede your program. Examples often include Legal, Trust & Compliance, Procurement, and sometimes even Operations or other department managers whose teams are indirectly affected by security initiatives.
Gile stresses that mapping these groups to your specific program (e.g., SecOps, Incident Response, Threat Hunting) is essential, as the exact roles will vary by organization.
Step 2: Researching Your Buying Committee
Once the buying committee is identified, the next step is to gather information without bias or assumption. This involves both qualitative and quantitative research:
- Qualitative Research (Interviews): This is the most critical component. Conduct interviews to understand stakeholders' hopes, dreams, and what keeps them up at night. Key questions should cover:
- Role: "Tell me what you do." "Why does your role/program exist?"
- Goals: "What are you trying to achieve this year/in the next few years?"
- Pain Points: Start generic, then gradually ask about pain specific to your program. The goal is to listen, not to troubleshoot or offer solutions yet.
- Tips for Interviews: Interview a set of people (3-5 per focus area), record interviews (with consent) for later synthesis, take notes, practice active listening, and maintain empathy, even when receiving negative feedback.
- Quantitative Research: Look at existing data. For engineering stakeholders, this means examining engineering data for trends and patterns related to productivity, release cycles, bug fixes, or uptime.
Step 3: Developing Personas
Unlike generic marketing personas that might include personal details, Gile advocates for work-bound personas – research-based descriptions of a group of people, not a specific individual. These personas should capture five key areas:
- Motivators: What are they trying to achieve at work and in their career?
- Attitudes: How do they feel about your security function? (e.g., friendly, spicy, negative due to past friction)
- Responsibilities: What are their core duties?
- Metrics: How do they measure success? How do they get their bonus? (e.g., Dora metrics, uptime, performance, retention)
- Pain Points: Not just security-related, but broad pain points (e.g., for a developer, "I didn't ship a thing").
Gile provides an example of an Engineering Leader persona, highlighting that it should be a narrative description, not just bullet points. The persona for an engineering leader might describe them as an influencer, responsible for human teams, advocating for tools and budget, but also capable of killing initiatives that create friction or slow releases. Their attitude towards AppSec might be negative due to past noisy tooling, and their key metrics could include Dora metrics, uptime, and team retention.
Step 4: Writing Messaging Guides
A messaging guide acts as a framework or "script" for persuasive communication, customized for a specific persona and a particular security initiative (e.g., implementing a new SCA tool, not the entire security program). It should include:
- Problem Statement: Clearly articulate the specific problem your security initiative solves for this persona. Example: "Our current SCA tool doesn't align with our software development practices; it's disruptive and inaccurate."
- Impact: Explain the consequences of the problem for the persona. Example: "It delays releases, causes developer friction, increases MTR, and slows innovation."
- Value (Business & Technical): This is crucial.
- Business Value: What senior leaders care about. Example: "Reduces time developers spend on security issues, increases confidence in findings, catches risk early."
- Technical Value (Features): The "bells and whistles" for technical audiences. Example: "Program analysis, reachability, fix recommendations."
- Evidence: Data, testing results, industry benchmarks, or even promises from vendors (with due diligence). Example: "Limited internal testing showed X, industry reports suggest Y, vendor promises Z."
- Call to Action (CTA): What do you want them to do? Be specific. Example: "Support a POV (Proof of Value) for a new tool," "Advocate on my behalf," "Support the transition to a new tool."
Step 5: Validating Messaging
Before rolling out new communication strategies at scale, validation is key. This is akin to testing a technical solution before deployment:
- Conduct Interviews (Again): Go back to the core group of stakeholders you initially interviewed. Share your refined understanding and ask, "Am I understanding you correctly?" This builds credibility.
- Trusted Advisors: Share rough drafts of your messaging guides with trusted colleagues or mentors for feedback.
- Small Project POV: Try out your new messaging on a small, contained project before implementing it broadly. Observe the reactions and adjust accordingly.
Gile advises against publishing these internal documents widely, as they can be misinterpreted out of context. They are primarily internal cheat sheets for the security team.
Demo / Proof of Concept
▶ Watch: Overview of the 5-step framework for communicating value (6:40)
While Jenn Gile's talk does not feature a traditional technical security demonstration involving code or exploits, it provides a compelling "proof of concept" for how Artificial Intelligence (AI), specifically Large Language Models (LLMs), can be leveraged to scale and enhance the product marketing methodology for internal security programs. Gile explicitly states that AI cannot replace the human element of building trust and understanding nuance through interviews, but it can significantly augment the process.
The demonstration of AI's utility focuses on three key areas:
- Synthesizing Interviews: After conducting numerous stakeholder interviews, the raw transcripts can be fed into an LLM. Gile notes that AI is "really great" at identifying trends and patterns across responses, especially for specific questions like "What are your pain points?" This capability helps security professionals quickly extract actionable insights from large volumes of qualitative data, saving significant manual effort.
- Challenging Assumptions: If a security professional develops a persona or messaging guide, they can use an LLM to "challenge their assumptions." By prompting the AI with their draft and asking, "What might I be missing here?" or "What are potential counterarguments?", they can gain an external perspective and refine their work.
- Making Skills (Custom AI Agents): This is where AI truly shines for scalability. Gile describes building "skills" (custom instructions or agents, like those in Claude) based on the developed personas and messaging guides. For example, a skill could encapsulate the details of the "Engineering Leader" persona and the "SCA Tool Implementation" messaging guide.
Gile provides a concrete example of a prompt used with a Claude skill: "I am trying to improve my communication with engineering leaders at my company. We have very different metrics and sometimes it seems like they don't complement each other. Can you make a matrix for me that explains each of my key metrics, maps them to a metric that engineering tracks, and explains how they relate? Here are the AppSec metrics list of metrics."
The AI, referencing the pre-trained persona and messaging guide skills, generates an "incredible result" – a table with:
- An AppSec metric (e.g., Mean Time to Remediation).
- A corresponding engineering metric (e.g., release velocity, developer productivity).
- The relationship between them (e.g., faster MTR contributes to smoother release cycles by reducing critical bug backlogs).
- A narrative explanation of this relationship.
This AI-generated matrix allows security professionals to quickly generate tailored communication artifacts that bridge the metric gap between AppSec and engineering, without having to manually craft each explanation. It enables them to "think about somebody else's point of view without having to have actually run a program that relied on these metrics," making the entire process highly scalable and impactful. The AI acts as an intelligent assistant, ensuring consistent, persona-aligned messaging across various communication channels once the foundational human research and persona development are complete.
Defensive Implications
▶ Watch: Step 1: Identify your internal buying committee and key groups (7:30)
The defensive implications of Jenn Gile's talk are profound, though they pertain to the "defense" of a security program itself rather than traditional network or system defense. By adopting these product marketing principles, security teams can significantly strengthen their internal position and effectiveness:
- Enhanced Buy-in and Budget Allocation: The primary defensive benefit is the ability to secure necessary resources. By articulating security needs in terms of business value (revenue, productivity, uptime), security leaders can overcome budget friction and gain executive approval for tools, personnel, and initiatives that might otherwise be dismissed as cost centers. This directly translates to a stronger overall security posture.
- Reduced Developer Friction: A common challenge for AppSec teams is the perception of being a blocker. By understanding developer personas, their metrics (like Dora metrics), and pain points (e.g., noisy tooling), security can reframe its programs to be enablers. Implementing less disruptive tools, providing clearer remediation guidance, or focusing on early-stage risk detection (as opposed to late-stage blocking) can significantly improve the relationship with engineering, leading to faster adoption of secure coding practices and fewer vulnerabilities.
- Improved Compliance and Risk Management: When security is understood and valued by all stakeholders, compliance initiatives become less of a burden and more of a shared responsibility. Legal and compliance teams, acting as influencers, are more likely to support security efforts when they see how these efforts reduce legal exposure and uphold brand trust – metrics they deeply care about.
- Proactive Problem Solving: By actively researching stakeholder pain points, security teams can move from a reactive "fix this vulnerability" mindset to a proactive "how can we solve this broader business problem with security?" approach. This allows for the implementation of security controls that seamlessly integrate into existing workflows, minimizing disruption and maximizing adoption.
- Strategic Alignment: The methodology fosters a deeper understanding of organizational goals beyond security. This strategic alignment ensures that security initiatives are not isolated but are integral to achieving broader business objectives, making the security team a valuable partner rather than an overhead.
- Scalable Communication: Leveraging AI for synthesizing interviews and generating tailored communication drafts means security teams can maintain consistent, persuasive messaging across a large and diverse organization without overwhelming individual team members. This allows a smaller security team to have a disproportionately larger impact on organizational security culture.
Ultimately, by mastering the art of internal communication through product marketing, security professionals can build stronger alliances, dismantle internal blockers, and cultivate a culture where security is seen as a shared investment in business success, rather than a necessary evil.
Key Takeaways
- Shift Focus from Security Metrics to Business Value: Stop trying to make people care about security for its own sake. Instead, articulate your security program's value in terms of stakeholder priorities like developer productivity, uptime, release velocity, revenue, and cost reduction.
- Adopt a Product Marketing Mindset: Treat your security program as a "product" and your internal stakeholders (engineering, finance, legal) as "customers." Understand their needs and tailor your "product's" messaging accordingly.
- Systematic Stakeholder Understanding is Critical: Follow a structured process: identify your "buying committee" (technical champions, budget holders, influencers), research their motivations and pain points, and develop work-bound personas.
- Craft Tailored Messaging Guides: For each specific security initiative, create a messaging guide that outlines the problem, its impact on the persona, clear business and technical value, supporting evidence, and a specific call to action.
- Validate Your Communication: Don't assume your message will land. Test it through follow-up interviews, feedback from trusted advisors, and small-scale project rollouts to ensure it resonates and achieves the desired outcome.
- Leverage AI for Scalability, Not Replacement: AI tools like LLMs can synthesize interview data, challenge assumptions, and generate customized communication drafts based on your personas and messaging guides, but they cannot replace the human empathy and trust-building required for initial research and validation.
About the Speaker(s)
Jenn Gile is a seasoned professional with over 20 years of experience in the technology sector and federal government. Her career has consistently revolved around the challenging task of motivating individuals to undertake tasks they might not initially want to do. She is currently one of the co-founders of opensourcemalware.com, a threat intelligence database specializing in malicious open source software. Her background includes significant experience in product marketing, a discipline she champions for its effectiveness in understanding customer needs and crafting compelling, value-driven communication, which forms the core of her talk's methodology.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent BSides-tier talk on a real problem — security teams that can't communicate value are a genuine organizational liability. The product marketing framework is structured and sensible, and the AI-augmentation angle is a practical if unsurprising addition. Nothing here is groundbreaking, but it's honest, actionable work that fills a gap most technical conferences ignore.
Heather Calloway (CISO) — SOLID
Gile delivers a clean, practical framework for internal security advocacy — translating product marketing discipline into a repeatable process for securing stakeholder buy-in. Competent and useful for practitioners who are struggling with this specific problem, but it doesn't reach the institutional or governance level where the real leverage lives.