← Back to blog
cybersecurity sales discovery compelling event quota attainment RepVue JOLT effect buyer indecision vendor consolidation sales coaching AE performance

For a Decade, the Market Ran Discovery for Cybersecurity AEs. Free Work Never Built the Muscle.

2026-08-17 Jonathan

A friend said something to me last week that I haven't been able to shake. Cybersecurity AEs have never had to develop the parts of selling that every other category forces you to learn. He wasn't being unkind about it and he wasn't talking about effort. He was talking about which muscles the job actually required, and which ones it let you skip.

For about a decade, the market ran discovery for them. A breach hit the news and the board asked a question. An auditor put a date on the calendar. The cyber insurance renewal came up and the carrier wanted proof of controls. A peer got hit and the CISO's phone rang before the rep's did. The compelling event kept showing up on its own, and the job was to be in the room when it did.

That was a real job and the people who did it well made a lot of money. But it was a different job than the one most software reps have, and the difference is starting to matter. This piece covers what a rep learns when nothing external creates urgency for them, why a decade of free compelling events left a gap that shows up in the quota numbers, what's changing in the cyber buyer's behavior right now, and what it actually takes to build the compelling event yourself.


Compare It to a Rep Selling Something Nobody Is Required to Buy

Think about a rep selling into a category with no auditor, no headline, and no mandate. Nothing about their buyer's world says they have to act this quarter, or ever. If that rep can't find the pain, quantify it in the buyer's own numbers, and build the business case themselves, the deal never starts. And the one they do manage to start dies the moment they stop driving it, because there is no external force keeping it alive when they go quiet.

So they learn discovery. Not the version where you run a question list and fill in a CRM field, but the version where you leave the call knowing what this specific problem costs, who feels it, and what happens on a date certain if nothing changes. They learn deal management the same way, because a deal with no external clock only moves when the rep manufactures the reason it has to. There is no version of that job where any of it gets skipped.

This is not a knock on cybersecurity reps. The work in cyber was real, and in some ways harder: more technical depth, more stakeholders, longer security reviews, buyers who have already read everything about you before the first call. But one specific piece of it, the part where somebody establishes that this problem is urgent and expensive right now, arrived pre-qualified more often than not. Nobody skipped it on purpose. It just kept getting handled by something other than the rep.

Free Work Doesn't Build the Muscle

The problem with work you get for free is that you don't develop the capability to do it yourself. A rep who has spent five years walking into rooms where the urgency was already established has thousands of reps of one skill, positioning against alternatives once the buyer is already moving, and very few of another, creating the reason to move in the first place. Both look like selling from the outside. Only one of them still works when the headline stops arriving on schedule.

You can see the gap in the outcome data. RepVue's Cloud Sales Index, which aggregates quota attainment across hundreds of software companies and tens of thousands of reps, closed 2025 with cybersecurity at 37.9 percent quota attainment, last among every sub-vertical it tracks and well under the 43.83 percent the overall index posted that same quarter. I've written before about why the product isn't what's causing cyber AEs to miss quota at record rates. This is the piece underneath that one. It isn't that the reps are worse. It's that the category asked less of them in one specific place for a long time, and now it's asking.

One honest update, because it cuts against the easy version of this argument. RepVue's Q2 2026 index has cybersecurity finally showing signs of breaking out of that hole, the first real move after years at the bottom. The gap is narrowing and that's worth saying plainly. But it started narrowing during the exact stretch when the free compelling events stopped arriving, which is the opposite of what you'd see if the market were still doing the work for people. Somebody is creating that urgency now, and it isn't the headline.

The Free Part Is Drying Up

Everyone already owns tools. Budget is consolidating into platforms rather than expanding into new line items. Futurum's 1H 2026 survey of 929 global enterprise cybersecurity buyers found consolidation intent rose to 42.0 percent while expansion intent fell to 35.8 percent, the first period in that series where consolidation clearly outpaced expansion. The same survey found the share of organizations expecting a budget increase over the next twelve months dropped to 67.2 percent from 73.2 percent six months earlier. The money hasn't disappeared. It has stopped arriving automatically, and it's harder to attach a new vendor to.

The buyer's fear changed too. It used to be picking the wrong vendor. Now it's owning the decision at all, in an environment where half the vendors on the shortlist might belong to someone else by renewal. Matt Dixon and Ted McKenna's analysis of more than 2.5 million recorded sales conversations found between 40 and 60 percent of forecasted B2B deals end in no decision rather than going to a competitor, and that 56 percent of those no-decision losses come from the buyer's own indecision and fear of getting it wrong, not from a preference for the status quo. Those are two different failure modes and they need two different responses. I broke down what that looks like in cyber specifically in where lost cybersecurity deals actually go.

Put those together and the shape of the problem is clear. Demand is still there. Attention is still there. What's gone is the external force that used to convert attention into a funded, dated decision without the rep having to do anything but show up prepared. That force is not coming back on the same schedule, and the reps who are hitting number right now are the ones already doing the work it used to do for them.

How You Build the Compelling Event Instead of Waiting for One

Building a compelling event is not manufacturing fake urgency, and buyers can tell the difference instantly. It's finding the change that has already happened in this buyer's environment and making them see what it costs. The raw material is almost always there. A vendor in their stack just got acquired and the roadmap they bought against no longer exists. A renewal is coming up that's going to reprice in a direction nobody has told them about yet. A tool they already own is reporting a gap their team has been quietly working around. A company in their vertical, with their architecture, got hit two weeks ago and it never made the national news.

The work is turning one of those into a number and a date. What does this exposure cost them per month it stays open, in their terms, using their own reporting rather than a vendor benchmark. Who inside their organization already knows about it and what have they been told. What is the specific thing that happens on a specific date if nobody acts. That's the part the auditor used to supply. Without one, a rep has to construct it, name it out loud in the room, and then get the buyer to say it back in their own words, because a compelling event the buyer can't articulate to their own CFO isn't one.

If you run a cyber team, this is inspectable. Stop asking reps whether the deal is qualified and start asking what changed in that account, when they learned it, and what it costs the buyer per month. A rep who can answer all three is building the event. A rep who answers with budget, authority, and a timeline the buyer volunteered is describing one that arrived on its own, which is fine when it happens and useless as a plan.

The hard part is that this work is time-sensitive and the facts move constantly. Who just got acquired, what the acquirer's roadmap actually covers, where a renewal is about to get repriced, which option on the buyer's shortlist just lost independence. A rep who reconstructs that after the call has the right answer and no room left to use it. That's exactly what we built KillChain Overwatch for: real-time competitive intelligence and sales coaching delivered at the moment of the call, built for cybersecurity AEs, so the change in the buyer's world becomes a named, quantified event while they're still on the phone. It's an unfair informational advantage in competitive deals and a force multiplier for strong reps, not a replacement for the skill. If you carry a number in cyber, or you run the team that does, book a demo.

The market spent a decade doing part of the job for cybersecurity reps, and it was easy to mistake that for the job being easier. It wasn't easier. It was subsidized. The subsidy is running out, the reps who already know how to create urgency are pulling away from the ones who learned to catch it, and the gap between them is going to keep widening. If you run a cyber team, the question isn't whether your reps work hard. It's whether they can start a deal when nothing external starts it for them.


FAQ

Why do cybersecurity AEs struggle with discovery?

Because for roughly a decade the market supplied the urgency for them. Breach headlines, audit deadlines, cyber insurance renewals, and peer incidents generated compelling events on their own, so the rep's job was to be in the room when one arrived rather than to construct it. That's a real skill, but it's a different one than finding latent pain, quantifying it in the buyer's numbers, and building the business case from nothing. Reps in categories with no mandate learn the second skill because there's no version of their job without it.

What is a compelling event in cybersecurity sales?

A compelling event is a specific change in the buyer's environment, tied to a cost and a date, that makes inaction more expensive than action. In cyber it has historically arrived externally: an auditor's deadline, a carrier's control requirement, a board question after a breach in the news. A built compelling event uses the same structure but starts from something already true in the account, such as an acquired vendor, a repricing renewal, or a gap the buyer's own tooling is already reporting, and turns it into a quantified consequence the buyer can defend internally.

What is cybersecurity's quota attainment rate right now?

RepVue's Cloud Sales Index measured cybersecurity quota attainment at 37.9 percent in the fourth quarter of 2025, the lowest of any sub-vertical it tracks and well under the 43.83 percent the overall index posted that quarter. Cybersecurity is also the largest sub-vertical in the index by survey sample size, and it has trailed the rest of the index on both quota attainment and inbound lead flow sentiment, so the gap is not a small-sample artifact and is not explained by a shortage of demand. RepVue's Q2 2026 index reports cybersecurity finally showing signs of breaking out, so the gap appears to be narrowing after several years at the bottom.

How do you create urgency when there is no breach headline or audit deadline?

Start from a change that has already happened in that specific account rather than from category-level risk. An acquisition inside their stack, a renewal about to reprice, a control gap their existing tooling already reports, or an incident at a peer with the same architecture. Then do the quantification work an auditor used to do: what it costs per month while it stays open, in their own reporting, who internally already knows, and what happens on a named date if nobody acts. Get the buyer to restate it in their own words before you call it real.


References

  1. RepVue. Cloud Sales Index, Q4 2025. Cybersecurity recorded 37.90% quota attainment, the lowest of any sub-vertical tracked, ahead of Finance & ERP at 40.43%, while the overall index closed the quarter at 43.83%, its highest level since Q2 2023. Cybersecurity is the largest sub-vertical in the index by survey sample size and has trailed the rest of the index on both quota attainment and inbound leadflow sentiment. RepVue
  2. RepVue. Cloud Sales Index, Q2 2026. The most recent quarterly index at the time of writing, reporting cybersecurity finally showing signs of breaking out of its multi-year position at the bottom of the index, alongside a record low in inbound leadflow sentiment across the index overall. RepVue
  3. The Futurum Group. Cybersecurity Market to Reach $521B by 2031; Buyer Budget Growth Slows (June 1, 2026). Based on the 1H 2026 Cybersecurity Decision Maker Survey of 929 global enterprise buyers. Consolidation intent rose to 42.0% from 34.6% in 2H 2025 while expansion intent fell to 35.8% from 43.0%; 67.2% of organizations anticipate budget increases over the next twelve months, down from 73.2%. Futurum Group
  4. Matthew Dixon and Ted McKenna. Stop Losing Sales to Customer Indecision, Harvard Business Review (June 24, 2022), and The JOLT Effect: How High Performers Overcome Customer Indecision, Portfolio (2022). Based on analysis of more than 2.5 million recorded sales conversations. Anywhere between 40% and 60% of deals end up lost to customers who express intent to purchase but ultimately fail to act; of those no-decision losses, 56% stem from customer indecision rather than the 44% attributable to a preference for the status quo. Harvard Business Review

*Written by Jonathan, co-founder of KillChain Sales. Former offensive security operator, now leading go-to-market for an AI competitive intelligence platform built for cybersecurity AEs. If you run a cyber team and the headline is no longer creating urgency for your reps, book a demo or connect on LinkedIn.*

Sign Up for a Demo