REACH · Playbook 04 · 12 min read
Who really decides, and how to reach each of them.
Nobody buys enterprise security software alone. By the time a cybersecurity purchase closes, it has usually passed through the hands of a technical evaluator, an economic approver, a risk-and-compliance voice, the people who will actually run the tool, and often procurement and legal. The single most common demand-generation mistake in this market is building the entire programme around one persona, usually the CISO, and treating everyone else as noise.
The argument:
This is a longer playbook because the subject earns it. Get the committee right and every other play in this library works harder.
Two forces make security purchases unusually collective. First, the stakes are shared. A security decision touches technical operations, business risk, budget, compliance obligations and sometimes the board. No single person is comfortable owning all of that alone, so the decision is deliberately distributed. Second, the scrutiny is high. Security buyers are professionally sceptical, and a new tool often means new access, new data flows and new operational dependencies, each of which invites a different specialist to weigh in.
The result is a buying group that has grown over the years rather than shrunk. Industry research across B2B technology has documented buying groups routinely reaching high single digits or more in the number of people involved in a significant purchase. The precise figure varies by source and by deal size, so treat any specific number you cite as something to verify rather than assert. The direction is not in dispute: cybersecurity purchases are made by groups, and the groups are not small.
The practical consequence is that reach is a coverage problem, not a targeting problem. Reaching the CISO and no one else means your message dies the moment it enters the internal conversation, because the CISO cannot personally answer the practitioner's operational questions or procurement's commercial ones. Coverage of the committee is what keeps you alive through the evaluation.
Every organisation structures this differently, and titles vary, so treat the following as functional roles rather than a fixed org chart. In a given account one person may hold several of these roles, or a role may be shared. What matters is that each function is present in the decision and cares about something different.
The economic decision-maker. Often the CISO, sometimes a CIO, CTO or, for larger commitments, the CFO or board. They own the budget and the outcome. Their question is not "how does this work" but "what risk does this reduce, what will it cost over time, and can I defend this decision to the people above me". They think in terms of business risk, total cost, and opportunity cost against every other thing that budget could buy. They rarely read the technical detail and heavily weight the judgement of people they trust.
The technical evaluator. A security architect, engineering lead or senior analyst tasked with assessing whether the solution is actually sound. Their question is "does this do what it claims, does it integrate with what we already run, and will it create more problems than it solves". They are sceptical by training and allergic to marketing language. They are also frequently the person whose quiet "this is not good enough" kills a deal before it reaches the decision-maker.
The end users and operators. The SOC analysts, engineers and administrators who will live with the tool every day. Their question is "will this make my job better or worse". They are often left out of vendor marketing entirely, which is a mistake, because operational resistance from the people who have to use a tool is one of the most common reasons a technically approved purchase stalls after the fact.
The risk, compliance and governance voice. A GRC lead, risk officer, or in some organisations a data protection or privacy function. Their question is "does this help us meet our obligations, and does it introduce any new exposure of its own". In regulated sectors this voice can be decisive, and it cares about evidence, provenance and defensibility far more than features.
Procurement and legal. They enter later and own the commercial and contractual terms. Their question is "are the terms acceptable and the risk to the business managed". They can slow or stop a deal that everyone else supports, so they should not be a surprise at the end.
The champion. Not a separate role so much as a person, often the technical evaluator or an operator, who becomes convinced and chooses to advocate internally. The champion is the most important individual in the whole group, because they carry your argument into every meeting you are not in. A deal without an internal champion is a deal you are pushing uphill.
Who sits in a cybersecurity buying group
CISO
Risk owner
Cares about risk reduction, board narrative and defensibility.
Security architect
Fit and integration
Cares about how it works with the existing stack.
SecOps lead
Daily operator
Cares about alert volume, tuning and workload.
IT and infrastructure
Deployment
Cares about rollout, performance and support.
Procurement
Commercials
Cares about price, terms and vendor consolidation.
Compliance and legal
Assurance
Cares about data handling, residency and audit evidence.
Because each role asks a different question, each needs a different asset. This is the operational heart of the play. You are not writing one piece of content and changing the tone. You are producing a small set of assets, each of which answers one role's actual question in that role's own language.
For the economic decision-maker, the useful assets are strategic and outcome-focused: how to think about risk in this category, how to structure a programme, how to brief a board, what the real cost and value picture looks like over time. Short, senior, and free of feature detail. They are deciding whether the problem is worth solving and whether you are a credible partner, not evaluating your integration options.
For the technical evaluator, the useful assets are rigorous and specific: architecture explanations, honest capability detail, integration guidance, evaluation criteria, comparisons that do not insult their intelligence. This reader rewards depth and punishes hand-waving. Content that treats them as expert is content that earns their trust, and their trust is what unlocks the decision-maker.
For the operators, the useful assets show daily reality: how the tool fits a workflow, what changes for the person using it, practical guides and honest accounts of what adoption looks like. Reaching this group early turns potential post-purchase resistance into pre-purchase advocacy.
For the risk and compliance voice, the useful assets are about evidence and defensibility: how the solution maps to obligations, what its own data and security posture is, how it stands up to scrutiny. Vague reassurance fails here. Documentation and provenance succeed.
For procurement and legal, the useful material is clarity on terms, commercial models and the answers to the questions they will ask, prepared in advance so they are not a late-stage bottleneck.
Different roles, different evidence
CISO and executive sponsors
Architects and IT
SecOps
Procurement, compliance, legal
Understanding the committee is only half the play. You then have to actually reach each role, and the channels that reach a CISO are not the channels that reach a SOC analyst.
The realistic route is a combination. Own an audience the whole community reads, and you reach many of these roles habitually rather than hunting them one by one; a specialist cybersecurity media relationship does this in a way generic advertising cannot. Targeted content distribution puts the right asset in front of the right role inside your target accounts. And direct, human outreach reaches the specific individuals in a named account when a deal is live, particularly the harder-to-reach senior roles where a relevant phone conversation can open a door that email cannot. No single channel covers the whole committee. The programme has to be built for coverage.
A word on the CISO specifically, since they anchor the committee's name. Senior security leaders are among the most marketed-to people in any enterprise, and they are correspondingly hard to reach with anything generic. What earns their attention is relevance and credibility: content that clearly comes from someone who understands their world, ideally through a source they already trust. This is precisely why owning a respected audience matters more than volume of outreach. The CISO is far more likely to engage with something surfaced through a channel they already read than with another cold approach.
The most leveraged thing you can do in a committee sale happens when you are not there. The vast majority of a buying group's deliberation takes place internally, in meetings and messages no vendor sees. Your champion is your presence in those rooms, and most vendors leave them under-equipped.
Arming the champion means giving them the material to make your case to each of the other roles: the risk framing for the decision-maker, the technical evidence for the evaluator, the answers to the compliance questions, the workflow reassurance for the operators. It also means making that material easy to forward and hard to argue with. A champion who has to reconstruct your argument from memory is a weaker champion than one who can forward a clear, role-specific piece to a colleague. Think of your content library, in a committee sale, as ammunition for your advocate as much as outreach to the buyer.
Cybersecurity evaluations run for months, and the committee's composition and attention shift as they progress. Early in the cycle, the strategic and educational content does the work, establishing that you understand the problem and belong in the consideration set. In the middle, the technical and operational depth carries the evaluation, as the evaluator and operators pressure-test the solution. Later, the compliance evidence and commercial clarity remove the final obstacles, and the champion drives the internal close.
The mistake is to lead with the late-stage material, the demo, the pricing, the commercial push, before the early-stage trust exists. In a committee sale, pushing to the close before the group is ready reads as pressure and can harden the sceptics. Patience, matched to where the committee actually is in its own process, wins more of these deals than urgency.
Committee coverage over time
Reach the whole account
Multiple roles engaged, not a single contact
Identify the champion
The person willing to argue internally
Arm the champion
Material they can forward without editing
Consensus and sign-off
Every objection answered in the right language
Building the whole programme around the CISO. The CISO anchors the group but does not answer the evaluator's or operator's questions, and those unanswered questions kill deals.
One asset for the whole committee. A strategic risk brief and a technical evaluation guide are different documents for different readers. Trying to serve both in one serves neither.
Ignoring the operators. The people who will use the tool can quietly sink an approved purchase. Reach them early.
Leaving procurement and compliance to the end. Surprises there stall deals everyone else supports. Prepare their answers in advance.
Single-threading. One contact per account is one resignation away from a dead deal. Multi-thread deliberately.
Leading with the demo. In a committee sale, trust precedes the close. Push too early and you harden the sceptics.
Reaching the buying committee is a REACH problem, and it is where owning a cybersecurity audience earns its keep. Getting role-specific content in front of the right members of the group, through a channel this market already reads and trusts, is exactly what content syndication into a defined audience is for, and human-led outreach adds the reach into specific senior roles when a deal is live. If your pipeline is single-threaded and CISO-anchored, broadening coverage of the committee is one of the highest-return changes you can make.