Field notes on competitive cybersecurity sales: what the data says, what the buyer is actually doing, and what separates the reps who hit.
Gartner Says AI Enablement Will Move Deals 40% Faster by 2029. In Cybersecurity, the Enablement Content Is Wrong Before the Quarter Ends.2026-09-07Gartner predicts that by 2029, sales organizations with AI-driven enablement functions will achieve 40 percent faster sales stage velocity than the ones running traditional enablement. The survey behind it went to 227 chief sales officers, and the number underneath the headline matters more than the headline does: those organizations absorbed an average of four transformations in the previous twelve months, which is more change than a single cybersecurity enterprise cycle can even fit. Stage velocity is the right thing to measure in this category, because cyber deals mostly do not lose to a competitor, they stop moving. Gartner's own analyst describes traditional enablement as a reactive support function rather than a system engineered to drive seller performance, and that description is accurate. Content libraries, quarterly kickoffs, and a deal review on Thursday all sit downstream of the moment that decides the deal. Cybersecurity breaks static enablement faster than any other category, because 108 acquisitions closed in Q1 2026 alone and a battlecard written in January is describing a company that no longer exists in April. This piece takes apart what in-workflow guidance actually has to do to earn the 40 percent, and makes the case for what we built KillChain Overwatch to be.
Cybersecurity Reps Were Never Taught Discovery. Neither Were the People Managing Them.2026-09-04Asking people in cybersecurity sales whether AEs ever had to develop real discovery skill turns up an answer that isn't about the reps. The ones who have spent time at established companies say the same thing: nobody taught them discovery, and in more than one case the leadership above them could not have taught it either. Those are two different problems. A junior AE who never learned discovery has a training gap, and training gaps close. A sales organization where nobody above the rep can define what good discovery looks like has something structural, and that does not resolve itself with a new methodology presentation. Discovery is the most visible piece, but it isn't the only one missing. Deal management is in the same condition, and so is technical scoping, which costs more in cyber than almost anywhere else. All of it is one skill showing up at different points in the deal: finding out what is actually true and then acting on it. A decade of expanding security budgets hid the gap, because when categories were uncontested and money was moving you could take orders and call it selling. Budget growth is slowing and consolidation intent has passed expansion intent for the first time. The skill nobody taught them is the one the job now requires.
For a Decade, the Market Ran Discovery for Cybersecurity AEs. Free Work Never Built the Muscle.2026-08-17A friend said something last week I haven't been able to shake. Cybersecurity AEs have never had to develop the parts of selling that every other category forces you to learn. For about a decade the market ran discovery for them. A breach hit the news and the board asked a question. An auditor put a date on the calendar. The insurance renewal came up and the carrier wanted proof of controls. A peer got hit and the CISO's phone rang before the rep's did. The compelling event kept showing up on its own, and the job was to be in the room when it did. Compare that to a rep selling something nobody is required to buy, who has to find the pain, quantify it, and build the business case or the deal never starts. In cyber, a lot of that got done for free, and free work doesn't build the muscle. Now the free part is drying up. Consolidation intent just passed expansion intent for the first time, budget growth is slowing, and cyber closed 2025 dead last on quota attainment. The reps hitting number are building the compelling event instead of waiting for one.
Everyone I Talked to at Black Hat Already Has Enough Tools. Almost None of Them Have Something That Helps Mid-Call.2026-08-10A CRO told me the last real-time tool they tried was distracting. A VP of Sales told me they already had enough tools and weren't sure another one would help. I spent last week walking the Black Hat business hall talking to AEs, SEs, VPs, and CROs about what's actually on their stack, and almost everyone already owns call recording, deal intelligence, forecasting, and a half dozen dashboards that report what happened last week or predict what might happen next quarter. Almost nobody could point to something that helps a rep in the middle of the call, while the deal is actually moving. Gartner's own research backs the skepticism up: AI is saving sellers nearly five hours a week, but 72 percent of sales organizations fail to reinvest that time into higher-value work. The organizations that are actually seeing growth from AI are not the ones with the most tools. They are the ones putting the right next action in front of a seller at the moment it matters, and that is a coaching problem, not a reporting problem.
Next Week, 400 Booths Will Make the Same Three Promises. That's the Real Reason Cyber Has the Lowest Quota Attainment in Software.2026-07-28CrowdStrike grew revenue 26 percent last quarter and beat estimates. Palo Alto Networks grew 31 percent and beat too, though a chunk of that came from the CyberArk and Chronosphere acquisitions. AI is pulling a fresh wave of budget into cybersecurity. And yet cyber has the lowest quota attainment of anything RepVue tracks. The broader cloud-software average has climbed back to its highest level in about two years, and cyber has barely moved, still dead last with only around 37 percent of reps hitting number. Record demand, more budget, and most reps still miss. Next week more than 400 vendors set up in the Black Hat business hall and about 20,000 people walk it, and the buyer sees the same three promises at most of the booths, half from companies that just got folded into somebody's platform. The real problem behind the quota number is not demand and not leads. It is sameness. The reps who hit in a market like this are the ones who can take a specific buyer's situation and make the risk real, right there in the conversation, so the buyer feels they have to move. A crowded floor just makes it impossible to hide from.
The First Half of 2026 Was the Biggest Consolidation Stretch in Cybersecurity History. The Buyer Is the Part Nobody Is Pricing In.2026-06-29Google closed its $32 billion acquisition of Wiz in March. Palo Alto Networks closed a $25 billion deal for CyberArk in February, the largest acquisition in its own history. At the same time CrowdStrike grew revenue 26 percent last quarter, SentinelOne crossed $1.1 billion in ARR, and cybersecurity stayed the only major tech sector still hiring above pre-pandemic levels with more than 514,000 open roles. The story everyone is telling about H1 is that the platforms won and you should bet on the survivors. Nobody is talking about what all of it does to the buyer. Every one of those deals detonates inside someone's stack: overlapping tools, a renewal nobody planned for, a rep relationship that just got reassigned, and a category that had four players in January and two in June. The buyer walking into your H2 deal is more confused and more stretched than they were six months ago, not less. The back half gets decided by which rep can walk into that mess and make the buyer's actual exposure legible, not by which platform has the most momentum.
You Can't Outpitch a Category Your Buyer Can't Define. Selling AI Security Before the Vocabulary Exists.2026-06-15AI companies made up roughly half of every cybersecurity venture deal in 2025, but the segment actually built to secure AI itself, the startups stopping prompt injection, data poisoning, and model risk, is tiny and new: about a dozen pure-play companies and a few hundred million dollars. The category got funded, and labeled, faster than anyone built the language to evaluate it. So the buyer walking your booth at Black Hat is not comparing features. They are trying to figure out which kind of AI security they even need, and they cannot tell prompt injection from data poisoning from model risk. Most reps read that confusion as a pitching problem and sharpen the deck. That is the wrong move. The rep who wins this is not the one with the best AI security pitch. It is the one who can diagnose the buyer's actual exposure and map it to what that specific buyer is on the hook for. That is a different skill than selling endpoint or network ever was, and the vocabulary did not exist on a sales floor eighteen months ago.
Cybersecurity Vendors Used to Promote Practitioners Into Sales. Now They Hire Sellers and Outsource the Security Part.2026-06-08Cybersecurity sales teams were once staffed from the practitioner bench, the engineers and operators who already spoke the buyer's language. That pipeline has narrowed, and the shortage behind it is a closed loop: the reps who know the space already have jobs, and ISC2's 2025 workforce study still finds 59 percent of organizations citing critical or significant skills needs. So vendors increasingly hire enterprise sellers from outside security and pay outside firms to teach them the domain, even as average AE ramp climbs to 5.7 months and quota attainment slips from 66 to 51 percent. That is not enablement. It is a different operating model, and its hidden cost is domain knowledge that never compounds on your own team.
You Can't Outpitch an Acquisition. What the AI Security Land Grab Did to the Cybersecurity AE's Pitch.2026-06-04Between August 2024 and September 2025, six pure-play AI application security companies were absorbed into larger platforms, four of them inside a single two-week stretch in September 2025. Cisco took Robust Intelligence, Palo Alto Networks paid a reported $700 million for Protect AI, and SentinelOne, F5, Check Point, and Cato Networks each bought a category leader of their own. The booths at Black Hat USA 2026 will look like a healthy, competitive category, but they are really a map of who got acquired and who is left. For cybersecurity AEs, that rewrites the pitch: if you sell AI security you are being compared to a logo that now lives inside Cisco, and if you sell endpoint, network, or identity, the buyer's confusion about the category is a lever you can pull.
Everyone Tells You Not to Send the One-Pager. Send It, Then Build It Around the Objections.2026-05-18The standard advice when a prospect asks for a one-pager is to refuse and qualify harder. But a cybersecurity deal is decided by a buying group of six to ten people, over months, mostly without the rep in the room, and some document will represent the product whether the rep likes it or not. The move is not to withhold the one-pager. It is to stop building it as a feature brochure and build it around the objections the committee will raise, like tool overlap, fully-loaded cost, and deployment, so circulation does the rep's discovery instead of quietly killing the deal.
Your Cybersecurity Buyer Asked ChatGPT About Your Product Before the Call. The AE's New Job Is Fact-Checking the Answer.2026-05-126Sense's 2025 buyer research found that 94 percent of B2B buyers use LLMs during their buying process, and 83 percent define their requirements before speaking to sales. In cybersecurity, where vendor product pages change quarterly, acquisition activity rewrites product lines every month, and the model's training data lags by months, the answer the buyer's LLM returned about your product is often wrong. The AE's new job in discovery is detecting and correcting that drift in real time, without making the buyer feel embarrassed about the source they trusted.
Most Lost Cybersecurity Deals Don't Go to a Competitor. Here's Where They Actually Go.2026-05-05Matt Dixon's analysis of 2.5 million sales conversations found that 40 to 60 percent of forecasted B2B deals end in no-decision, and 56 percent of those losses come down to buyer indecision rather than the customer preferring the status quo. In cybersecurity, where enterprise buying groups regularly exceed 10 stakeholders and sales cycles run 12 to 18 months, the no-decision loss has become the silent majority of every loss column, and almost no team is tracking it separately. This article examines what that costs, what causes it, and the signals that predict it.
108 Cybersecurity Acquisitions Closed in Q1 2026. Here's What That Does to the AEs Underneath.2026-04-27Q1 2026 closed 108 cybersecurity M&A deals worth roughly $47 billion, the second-highest quarterly count in the sector's history. CrowdStrike acquired SGNL for $740 million. Palo Alto Networks closed its $400 million acquisition of Koi. Google completed its $32 billion deal for Wiz. Every one of these transactions reassigns territory, rewrites comp plans, and adds new objections to every in-flight deal. This article examines what an acquisition actually costs the AEs underneath.
Cybersecurity CROs Don't Last Long. Here's What Breaks for the AEs Underneath Them.2026-04-20The median tenure of a SaaS Chief Revenue Officer is 18 to 22 months. Okta's Steve Rowland left after less than two years. Palo Alto Networks reshuffled its President and GTM leadership in 2021. Every one of these transitions quietly rewrites the quota, the territory, the comp plan, and the methodology AEs are measured against. This article examines what a CRO change actually costs the reps underneath.
The "Do More With Less" Era Is Breaking Cybersecurity Sales Teams. Here's What the Data Shows.2026-04-12CrowdStrike cut 500 people and said AI would flatten the hiring curve. Palo Alto laid off hundreds of CyberArk employees the day after closing a $25 billion acquisition. Nearly 245,000 tech jobs were cut across the industry in 2025. The cybersecurity sales profession is being squeezed from both sides: fewer people carrying bigger numbers in a market that has never been more complex to sell into.
Cybersecurity AEs Are Missing Quota at Record Rates. The Product Isn't the Problem.2026-04-06CrowdStrike, Varonis, Armis, Palo Alto Networks — some of the biggest names in cybersecurity, and their AEs are still missing quota. RepVue data paints a consistent picture across the industry: the problem isn't the product. It's the complexity of the sale itself.
RSA Conference 2026 Just Proved It: AI Security Is Rewriting the Playbook for Cybersecurity AEs2026-03-29RSA Conference 2026 made one thing clear: AI security is no longer an emerging category. It is the category. For cybersecurity AEs, this means the knowledge required to sell effectively just expanded again — and the pace is accelerating faster than any training program can match.
Every Sales Org Measures Outcomes. Almost None Measure What Causes Them.2026-03-26Quota attainment, win rate, pipeline coverage — these are lagging indicators. By the time they turn red, the behaviors that caused them happened weeks ago. The gap between knowing your number and knowing what drives your number is where most sales coaching falls apart.
Your Best Rep's Brain Doesn't Scale. That's the Problem.2026-03-23Every top cybersecurity AE builds a personal operating system for navigating deals. That knowledge is extraordinarily valuable, and trapped inside one person's head. Here's why that's the biggest unsolved problem in cybersecurity sales.
How AI Copilots Are Changing Cybersecurity Sales Calls2026-03-10Cybersecurity AEs face unique challenges: compliance questions, competitive objections, and technical deep-dives, all in real time. Here's how AI copilots are shifting the balance.