I'm Not Your Enemy: How Practitioners Can Empower Content
Kali Fencl (Senior Content Marketing Manager and Security Researcher and Training · DomainTools)
ShmooCon XX (Final) · Day 2 · Belay It
Overview
In her ShmooCon talk, "I'm Not Your Enemy: How Practitioners Can Empower Content," Kali Fencl, a Senior Content Marketing Manager and Security Researcher at DomainTools, addresses a perennial challenge within the cybersecurity industry: the perceived chasm between technical security practitioners and marketing teams. Fencl, drawing from her unique background as a marketer who transitioned into InfoSec, argues that this divide is not only unproductive but actively detrimental to an organization's ability to communicate its value, educate its audience, and ultimately drive business success.

Key moments
- 0:00 Speaker intro and common marketing misconceptions
- 2:00 Why content is essential and practitioner's role
- 3:10 Defining Ideal Customer Profile (ICP) and avoiding fluff
- 4:15 Introducing 'Method Marketing' for content creation
- 5:15 Case study: American Girl doll subreddit and suspicious website
- 6:00 Initial domain analysis and red flags identified
- 6:40 Overcoming self-doubt and colleague validation of research
I'm Not Your Enemy: How Practitioners Can Empower Content
Speakers: Kali Fencl, Senior Content Marketing Manager and Security Researcher and Training, DomainTools
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=5YHcw-qj094
Overview
In her ShmooCon talk, "I'm Not Your Enemy: How Practitioners Can Empower Content," Kali Fencl, a Senior Content Marketing Manager and Security Researcher at DomainTools, addresses a perennial challenge within the cybersecurity industry: the perceived chasm between technical security practitioners and marketing teams. Fencl, drawing from her unique background as a marketer who transitioned into InfoSec, argues that this divide is not only unproductive but actively detrimental to an organization's ability to communicate its value, educate its audience, and ultimately drive business success.
Fencl's core message champions a collaborative approach she terms "method marketing." This strategy empowers marketing professionals to conduct their own foundational security research, thereby filling the content gap often left by time-constrained practitioners. By stepping into the shoes of a researcher, marketers can generate authentic, data-driven content that resonates with both technical and non-technical audiences. The talk underscores the critical importance of this shift, particularly in an era where generic, AI-generated content is becoming ubiquitous, emphasizing that bespoke, credible research is essential for maintaining trust and relevance.
This talk is particularly significant because it offers a pragmatic solution to a widespread industry problem. Many organizations struggle to translate complex technical work into accessible, engaging narratives. Fencl demonstrates that by equipping marketers with the right tools and fostering a culture of collaboration, companies can unlock a powerful new stream of content that not only educates and informs but also directly contributes to revenue and builds stronger relationships with customers and prospects. Her presentation serves as a compelling call to action for both practitioners to embrace marketing as an ally and for marketers to proactively engage with the technical realities of their field.
Background
▶ Watch: Speaker intro and common marketing misconceptions (0:00)
Kali Fencl began her ShmooCon talk by recounting her professional journey, which started in traditional marketing roles for diverse industries, including a fastener distributor and a drone manufacturer, before landing in information security three years prior. This varied background provided her with a unique perspective on the common misconceptions and challenges faced by marketing professionals, especially when interacting with highly technical subject matter experts (SMEs). Fencl frequently encountered sentiments from practitioners such as, "All you do is play on Facebook all day," or "We don't really need marketing because the product should really stand for itself." These anecdotes highlight a pervasive issue: a lack of understanding and appreciation for marketing's role in conveying value, particularly in an industry as complex as cybersecurity.
Fencl argues that this perspective is fundamentally flawed. A product, no matter how technically superior, is an inanimate object; it cannot speak for itself (at least, not "until AI products gain sentience," she quipped). Effective content is crucial for any product or service to reach its intended audience, explain its benefits, and establish its relevance. While security practitioners are an invaluable source of deep technical knowledge and research, their daily responsibilities often leave little time for content creation. They are typically engaged in critical tasks such as customer interactions, incident response, product development, and core research, making content development a low priority.
This creates a dangerous void. When practitioners are unavailable, marketers are often forced to "cobble together" information from generic online sources, leading to what Fencl describes as "fluff" – content that is superficial, lacks genuine insight, and fails to resonate meaningfully with an audience. Such content, while perhaps optimized for search engines in the past, is rapidly losing its efficacy in an evolving digital landscape, particularly with the rise of advanced AI content generation tools.
To counteract this, Fencl introduced the concept of the Ideal Customer Profile (ICP). Understanding who the content is for – their pain points, goals, and existing knowledge – is paramount. Practitioners, through their direct engagement with customers and prospects, possess invaluable insights into these ICPs. However, if this information isn't shared with marketing, the content risks missing its mark entirely. This foundational context underpins Fencl's proposed solution: method marketing, a strategic approach where marketers actively engage in their own research, bridging the knowledge gap and producing authentic, impactful content. This idea is inspired by a growing trend of practitioners like Jason Haddix and Clint Gibler transitioning into marketing roles, but Fencl's method marketing reverses this, empowering marketers to adopt a researcher's mindset.
Key Findings
▶ Watch: Defining Ideal Customer Profile (ICP) and avoiding fluff (3:10)
Kali Fencl's talk unveiled several critical findings regarding the intersection of marketing and cybersecurity, centered around her concept of "method marketing." The primary discovery is the demonstrable efficacy and necessity of marketers engaging in their own security research to produce authentic and impactful content. This approach directly combats the "fluff" often generated when marketers lack deep subject matter expertise or direct input from busy practitioners.
A significant finding from Fencl's personal experience was that even seemingly rudimentary security investigations conducted by marketers can uncover substantial real-world threats and align with larger, more technical ongoing investigations. Her case study involving the American Girl doll subreddit query, which led to the discovery of a widespread e-commerce domain fraud scheme, perfectly illustrates this. What began as a simple consumer concern quickly escalated into uncovering a sophisticated brand impersonation operation.
Furthermore, Fencl highlighted that content derived from this method marketing approach can effectively cater to a broader, often overlooked, audience beyond just technical practitioners. While practitioners might benefit from highly detailed technical analyses, non-technical stakeholders such as legal teams, finance departments, and senior management also need to understand the why and impact of security issues. Fencl's research, initially perceived as potentially "too rudimentary" for the InfoSec community, proved ideal for these decision-makers, helping them grasp the importance of domain intelligence and security investments.
Internally, Fencl found that this collaborative research process significantly builds trust and strengthens relationships between marketing, security practitioners, sales teams, and product development. By actively participating in research and demonstrating a commitment to understanding the technical landscape, marketing sheds its "enemy" perception and becomes a valued partner.
Finally, the talk underscored the direct, tangible benefits of this approach, revealing a clear material impact on revenue and client acquisition. Fencl shared a compelling anecdote of how a blog post generated from her research directly influenced a client's decision to purchase DomainTools' product, legitimizing the investment for their legal team. This demonstrates that authentic, research-backed content isn't just about brand awareness; it's a powerful tool for driving conversions and supporting an organization's bottom line. In the face of increasingly sophisticated AI content generation, Fencl posits that "bespoke research pieces" are becoming indispensable for establishing credibility and distinguishing genuine expertise from generic output.
Technical Deep Dive
▶ Watch: Introducing 'Method Marketing' for content creation (4:15)
The technical core of Kali Fencl's "method marketing" approach is best exemplified through her detailed case study, which began with a seemingly innocuous query on the American Girl doll subreddit. A user posted, "Is this website legit?", seeking discontinued merchandise at an attractive price point. The domain in question was usirshop.com.
Fencl, leveraging her dual perspective as a marketer and a security researcher in training, immediately identified initial red flags from a non-technical vantage point. The screenshot shared by the user revealed an old American Girl logo and a "funky font," visual cues that often accompany phishing attempts or illegitimate sites. These seemingly minor details are critical for a general audience, indicating a lack of authenticity and professionalism.
To delve deeper, Fencl utilized DomainTools Iris Investigate, a powerful domain intelligence platform. This tool allowed her to move beyond superficial observations and uncover deeper, more technical indicators of suspicious activity. Key findings from Iris Investigate included:
- Proximity Score: The domain
usirshop.comhad a proximity score of 100. This score indicates that the domain had already been reported to a reputable blocklist, immediately signaling its malicious nature. - Phishing and Malware Scores: While the proximity score was definitive, the domain also registered in the "yellow" warning territory for both phishing score and malware score. This suggests that while it might not have been actively distributing malware, it exhibited characteristics commonly associated with phishing campaigns, further solidifying the suspicion.
- Registrant Country: A crucial piece of intelligence was the registrant country listed as China. As a super fan of American Girl, Fencl knew the company originated in Madison, Wisconsin, USA. A discrepancy in the registrant country for a brand-impersonating site is a strong indicator of fraud.
- Frequent SSL Certificate Changes: Iris Investigate also revealed frequent SSL certificate changes associated with the domain. Malicious actors often cycle through SSL certificates to evade detection, re-establish credibility after being flagged, or simply due to the ephemeral nature of their infrastructure. This rapid turnover is a common tactic in fast-flux or quickly evolving fraudulent operations.
Despite these clear indicators, Fencl initially harbored doubts, questioning if her findings were "too rudimentary" for experienced security practitioners or if the crossover between American Girl and InfoSec was too niche to be impactful. However, her colleagues at DomainTools quickly validated her efforts. Several researchers recognized usirshop.com and confirmed it was part of a much larger, parallel investigation they were conducting into e-commerce domain fraud and brand impersonation schemes.
This larger scheme involved bad actors "turning over domains on a daily basis," rapidly creating and discarding domains to impersonate popular brands like American Girl, GameStop, and Steve Madden. This tactic makes it challenging for traditional blocklists to keep up and for consumers to distinguish legitimate sites from fraudulent ones. The objective was to defraud unsuspecting consumers, often by offering discontinued or discounted merchandise, then failing to deliver or stealing payment information.
Fencl's research, while focused on initial indicators, proved invaluable for a specific audience: non-technical decision-makers within organizations, such as finance or legal teams. These groups need to understand the importance of DNS and domain intelligence and the risk of brand impersonation, even if they don't require the granular technical details of the larger fraud scheme. Her work provided the perfect bridge, translating complex threats into actionable insights for those involved in purchasing decisions and budget allocation. This case study powerfully demonstrated how a marketer, equipped with the right tools and a collaborative mindset, can contribute significantly to uncovering and explaining real-world security threats.
Demo / Proof of Concept
▶ Watch: Initial domain analysis and red flags identified (6:00)
While Kali Fencl's ShmooCon talk did not feature a live software demonstration in the traditional sense, her detailed narrative of the American Girl doll scam investigation served as a compelling proof of concept for her "method marketing" approach. This real-world case study effectively demonstrated how a marketing professional, even without a deep practitioner background, can initiate and conduct meaningful security research to generate valuable content.
The demonstration unfolded through the logical progression of Fencl's investigation:
- Initial Spark: The process began with a genuine user query on the American Girl doll subreddit, highlighting a real-world problem: "Is this website legit?" This showed how marketing can be responsive to consumer concerns and turn them into research opportunities.
- Initial Assessment (Marketer's Eye): Fencl first applied her marketer's intuition and knowledge as an American Girl fan, identifying visual cues like an old logo and funky font as immediate red flags. This showcased the value of diverse perspectives in threat detection.
- Tool Application: The core of the "demo" involved Fencl using DomainTools Iris Investigate. She walked the audience through the types of data points the tool provided:
- A proximity score of 100, indicating the domain was already blocklisted.
- Warning-level phishing and malware scores.
- The discrepancy in registrant country (China vs. USA for American Girl).
- Evidence of frequent SSL certificate changes.
This segment effectively demonstrated how a marketer, trained on specific tools, can extract actionable intelligence.
- Validation and Expansion: Crucially, Fencl's findings were validated and expanded upon by DomainTools' internal security researchers. They recognized
usirshop.comas part of a broader e-commerce domain fraud and brand impersonation scheme affecting multiple major brands. This highlighted the power of collaboration between marketing and practitioners, where initial findings can lead to uncovering larger threats. - Content Outcome: The ultimate proof of concept was the resulting content piece. Fencl explained how her research, while perhaps less technically granular than a practitioner's, was perfectly suited for non-technical audiences like legal and finance teams. This demonstrated the ability of "method marketing" to create content that addresses the specific needs of different Ideal Customer Profiles (ICPs) and directly contributes to the sales cycle.
Through this detailed account, Fencl effectively "demonstrated" that marketers can proactively engage in security research, uncover legitimate threats, and produce content that not only educates but also directly impacts business outcomes, thereby legitimizing the "method marketing" approach.
Defensive Implications
▶ Watch: Overcoming self-doubt and colleague validation of research (6:40)
Kali Fencl's talk carries significant defensive implications for organizations, urging a paradigm shift in how security practitioners and marketing teams interact and contribute to an organization's overall security posture and market positioning.
For Security Practitioners:
The primary implication is a call to re-evaluate the role of marketing as an indispensable ally, not an "enemy" or a peripheral function. Practitioners should actively seek to educate marketing teams, sharing insights into customer pain points, common attack vectors, and the strategic importance of various security controls. By doing so, they empower marketers to create more accurate and impactful content. Furthermore, practitioners should recognize that content serves diverse audiences; while they might value deep technical dives, non-technical stakeholders (like legal, finance, or HR) require simplified explanations of why security matters. Collaborating with marketing to tailor these messages can legitimize security investments and foster broader organizational buy-in. Tools like DomainTools Iris Investigate, while technical, can be taught to marketers for initial threat intelligence gathering, extending the defensive reach of the security team.
For Marketing Teams:
The central defensive implication is the urgent need to adopt "method marketing" as a standard practice. Marketers must move beyond generic content creation and commit to conducting their own foundational security research. This requires investing in basic cybersecurity education for marketing staff and, where appropriate, providing access to and training on security tools like DomainTools Iris Investigate. By doing so, marketers can proactively identify emerging threats, such as brand impersonation and e-commerce fraud, as demonstrated by the usirshop.com case study. In the era of AI, producing "bespoke research pieces" that offer genuine, data-backed insights will be crucial for maintaining credibility and distinguishing an organization from the deluge of AI-generated "fluff." This authentic content acts as a strong defensive measure against misinformation and builds trust with the audience.
For Organizations as a Whole:
The talk underscores the importance of fostering a culture of cross-functional collaboration. Breaking down silos between security, marketing, sales, and product teams leads to a more robust defensive posture. When marketing understands security challenges, they can create content that educates the broader public about threats like phishing, domain fraud, and brand impersonation, effectively turning content into a public awareness campaign. Proactive use of domain intelligence tools for brand protection and fraud detection becomes not just a security team's responsibility but a shared organizational imperative, with marketing playing a vital role in communicating findings and their implications. By demonstrating the direct revenue impact of authentic security content, organizations can justify greater investment in both security tools and the training of their marketing teams, ultimately leading to enhanced credibility, stronger customer relationships, and a more resilient defense against evolving cyber threats.
Key Takeaways
- Collaboration is Key: Marketing and security practitioners are allies, not adversaries. Bridging this gap leads to more effective communication and stronger organizational outcomes.
- Embrace "Method Marketing": Marketers should proactively engage in their own foundational security research, using tools and collaborating with practitioners, to create authentic, data-driven content.
- Authenticity Over Fluff: In the age of AI, "bespoke research pieces" are critical for establishing credibility, building trust, and standing out from generic content.
- Diverse Audiences Matter: Even seemingly "rudimentary" security investigations can uncover significant threats and generate content perfectly suited for non-technical decision-makers (e.g., legal, finance), who are crucial to the buying process.
- Content Drives Revenue: High-quality, research-backed content directly impacts client acquisition, legitimizes product investments, and contributes materially to an organization's financial success.
- Domain Intelligence is Essential: Tools like DomainTools Iris Investigate are vital for identifying and understanding threats like e-commerce fraud and brand impersonation, providing actionable intelligence for both security and marketing efforts.
About the Speaker(s)
Kali Fencl is the Senior Content Marketing Manager and Security Researcher and Training at DomainTools. Her unique background blends extensive experience in marketing across various industries, including a fastener distributor and a drone manufacturer, with a recent transition into the information security space, where she has been for approximately three years. Fencl is also a co-host of the "Breaking Badness" security podcast, further demonstrating her engagement and expertise within the cybersecurity community. Her talk at ShmooCon marked her very first appearance at the conference, highlighting her emerging voice in advocating for stronger collaboration between technical practitioners and marketing professionals. She champions the "method marketing" approach, striving to empower marketers to conduct their own security research and create impactful, credible content.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
This session, while well-intentioned and competently delivered, is fundamentally a marketing talk disguised as a security presentation. The 'research' showcased is a rudimentary application of a commercial tool to identify basic e-commerce fraud, offering zero novel technical insight for a seasoned security audience. Its true value lies in internal corporate strategy for content generation and sales, not advancing the field of cybersecurity.
Heather Calloway (CISO) — STRONG ACCEPT
This session by Kali Fencl tackles a critical and often-overlooked governance challenge: the chasm between technical security practitioners and marketing teams. Fencl's "method marketing" approach provides a clear, actionable framework for empowering marketers to conduct foundational security research, thereby generating authentic content that directly supports business objectives, enhances brand protection, and informs critical stakeholders. It's a pragmatic solution to an institutional problem, demonstrating how collaboration can turn a perceived organizational friction point into a significant strategic advantage.