Building Cyber Products Customers Love

Ross Haleliuk

BSides NYC 2024 · Day 1 · Entrepreneur

Overview

Ross Haleliuk's talk at BSides NYC, "Building Cyber Products Customers Love," delves into the unique and often challenging landscape of cybersecurity product management. Haleliuk, an author and expert in the field, dissects the fundamental differences that distinguish cybersecurity product development from its counterparts in other industries. He argues that while core product management principles remain consistent, the specific context of cybersecurity introduces complexities that demand tailored approaches, particularly in areas like customer discovery, value proposition, and the intricate buying process.

Watch on YouTube

Visual summary for Building Cyber Products Customers Love by Ross Haleliuk
Visual summary for Building Cyber Products Customers Love by Ross Haleliuk

Key moments

  1. 0:00 Introduction: Unique challenges of cybersecurity products
  2. 1:55 Challenge 1: Difficulties in customer discovery
  3. 3:15 Challenge 2: Traditional B2C PM frameworks fail
  4. 4:05 Overcoming challenges: Understanding ideal customer profiles
  5. 6:05 Difficulty in demonstrating product value and efficacy
  6. 6:40 Buyers prioritize time to value over efficacy

Building Cyber Products Customers Love

Speakers: Ross Haleliuk

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=KC_CzKb_0rQ

Overview

Ross Haleliuk's talk at BSides NYC, "Building Cyber Products Customers Love," delves into the unique and often challenging landscape of cybersecurity product management. Haleliuk, an author and expert in the field, dissects the fundamental differences that distinguish cybersecurity product development from its counterparts in other industries. He argues that while core product management principles remain consistent, the specific context of cybersecurity introduces complexities that demand tailored approaches, particularly in areas like customer discovery, value proposition, and the intricate buying process.

The presentation aims to illuminate these inherent challenges and, more importantly, propose actionable strategies for overcoming them. Haleliuk emphasizes that success in this domain hinges on a deep understanding of the highly specialized user base, the fragmented market, and the unique trust dynamics prevalent in security. This talk is crucial for anyone involved in developing, selling, or even purchasing cybersecurity solutions, offering a pragmatic roadmap for building products that genuinely resonate with security practitioners and decision-makers.

Ultimately, Haleliuk's insights serve as a vital guide for aspiring founders, product managers, and even security leaders who seek to innovate within the cyber domain. By dissecting common pitfalls and offering practical advice, the talk underscores the necessity of moving beyond conventional product management wisdom to address the specific nuances of the cybersecurity market, fostering the creation of truly impactful and customer-centric solutions.

Background

▶ Watch: Introduction: Unique challenges of cybersecurity products (0:00)

The landscape of cybersecurity product development, as Haleliuk explains, presents a distinct set of hurdles that deviate significantly from standard product management practices in other sectors. While the foundational tenets of product management—identifying problems, designing solutions, and bringing them to market—remain universal, their application within cybersecurity is complicated by several inherent characteristics of the industry.

Firstly, the low install base is a critical factor. Unlike consumer-facing applications or general business software, very few cybersecurity products achieve widespread adoption and economies of scale. The market is often fragmented, dominated by a handful of established giants, while the vast majority of companies are startups struggling to gain significant traction. This limits the ability to leverage mass-market growth strategies.

Secondly, cybersecurity products are invariably sold to expert users. Security practitioners possess deep domain knowledge, often understanding the intricacies of the problems better than the product builders themselves. This creates a challenging dynamic where product teams must navigate a highly opinionated user base that demands robust, precise, and often customizable solutions, rather than generic offerings. This also makes traditional customer discovery difficult, as practitioners are often reticent to disclose vulnerabilities or gaps due to their professional responsibilities.

Finally, the industry contends with short release cycles juxtaposed against legacy enterprise environments. Despite the prevalence of cloud-first and cloud-native development, many large enterprises—the primary customers for cybersecurity solutions—do not operate exclusively in SaaS-first models. They grapple with significant legacy infrastructure, complex on-premises deployments, and stringent procurement processes. This necessitates product developers to account for a wide array of deployment models and integration challenges that are often absent in other, more agile industries. These unique market conditions collectively define the environment in which cybersecurity products must be conceived, built, and sold, making traditional, B2C-centric product management frameworks largely ineffective.

Key Findings

▶ Watch: Challenge 2: Traditional B2C PM frameworks fail (3:15)

Ross Haleliuk identifies four primary challenges that confront those building cybersecurity products, each demanding a specialized approach to overcome:

  1. The Challenge of Customer Discovery: This is perhaps the most significant hurdle. Unlike other industries where users are eager to articulate their problems to potential solution providers, security practitioners are professionally obligated to safeguard their organizations and never disclose their remaining security gaps. Approaching a security professional with questions like, "Where are you insecure?" or "What are your gaps?" is inherently difficult due to the lack of a pre-existing trust relationship. Furthermore, cybersecurity teams are typically overloaded, lacking the time to engage with numerous startups making similar inquiries. This "outreach fatigue" makes it incredibly hard for product managers to gather authentic, actionable insights into real-world pain points.
  1. Ineffectiveness of Traditional Product Management Frameworks: Many widely taught product management methodologies originate from fast-growth B2C companies in Silicon Valley (e.g., Facebook, Google, Pinterest). These frameworks often rely on strategies like growth hacking or A/B testing, which are ill-suited for the B2B cybersecurity market. In this sector, buyers are highly informed, possess strong opinions, and require a deep understanding of the problem space and a robust, well-engineered solution. The talk highlights that simply applying B2C tactics to cybersecurity sales is a recipe for failure, emphasizing the need for a more nuanced, problem-centric approach.
  1. Opinionated Products vs. Customizable Needs: A common pattern observed is that founders build cybersecurity products in a very opinionated way, reflecting their specific vision of how a problem should be solved. However, the reality is that the vast majority of buyers have diverse environments, unique operational processes, and differing perspectives on the "right" solution. This creates a mismatch. Haleliuk suggests that the products that ultimately succeed are those built to be highly configurable and customizable, yet sold in a very opinionated manner. This means offering a generalized platform that can adapt to specific customer needs, but presenting it with a clear, compelling narrative that doesn't require the customer to "imagine" its value. The challenge lies in demonstrating value when testing efficacy is incredibly hard, leading customers to prioritize factors like time to value and ease of proof-of-concept (POC).
  1. Oversimplification of the Buying Journey: Many product teams and founders mistakenly believe that securing CISO approval is sufficient for product adoption, or conversely, that a "bottoms-up" approach (convincing individual security engineers) will lead to internal championing and eventual purchase. Haleliuk debunks both myths. CISOs, while influential, will not adopt tools that their teams will sabotage, emphasizing the need for buy-in from practitioners. Simultaneously, a bottoms-up strategy is often ineffective because individual contributors in cybersecurity typically lack the budgetary authority or empowerment to initiate procurement processes. The speaker attributes this to security leaders being personally accountable for outcomes, making them hesitant to delegate critical purchasing decisions. The complex procurement cycles and the lack of discretionary budgets for security practitioners mean that understanding the multi-stakeholder nature of the buying journey—including who the true buyer is, what drives their decisions (e.g., compliance vs. actual security), and potential internal impediments—is paramount.

Technical Deep Dive

▶ Watch: Overcoming challenges: Understanding ideal customer profiles (4:05)

While Ross Haleliuk's talk focuses on product management rather than specific security exploits or code, the "technical deep dive" here refers to the methodologies and strategic frameworks he proposes for effectively navigating the unique challenges of building cyber products. These are the "technical" aspects of product development in a highly specialized domain.

A core tenet of Haleliuk's approach is the meticulous Ideal Customer Profile (ICP) definition. This goes beyond generic labels like "enterprise" to deeply understand the specific type of enterprise (e.g., financial vs. SaaS, 10,000 vs. 20,000 employees, multi-state vs. single-region). It involves identifying who at the company truly cares about the problem, their level of concern, and critically, whether they possess the budget to address it. This granular understanding is vital because, as Haleliuk notes, different industries, company sizes, and even the existing toolsets within an organization profoundly impact their pain points and readiness to adopt new solutions.

The speaker heavily emphasizes the importance of customer discovery as a continuous process. He strongly advises against founders or practitioners assuming they "know" the problem just because they've experienced it themselves. Their experience might be limited to a small segment of the market (e.g., Bay Area companies) that doesn't represent broader needs. To counteract biases and ensure genuine problem identification, Haleliuk recommends specific techniques and resources:

  • Don't just talk to buyers (CISOs): Engage with the actual end-users who will operate the product daily. Their insights are crucial for understanding usability, workflow integration, and the practical challenges that determine a tool's success during a POC.
  • Leverage structured interviewing techniques: Haleliuk recommends books like "The Mom Test" by Rob Fitzpatrick and "Continuous Discovery Habits" by Teresa Torres. "The Mom Test" teaches how to ask open-ended questions that uncover real problems and validate assumptions, rather than leading interviewees to confirm existing biases. "Continuous Discovery Habits" advocates for ongoing, iterative customer research to ensure product development remains aligned with evolving user needs.
  • Challenge assumptions rigorously: Haleliuk outlines a critical chain of validation:
  • Is it a problem? (Just because it is, doesn't mean someone wants to solve it.)
  • Are they interested in solving it? (Doesn't mean they'll pay.)
  • Are they willing to pay? (Doesn't mean it's a product; could be a service.)
  • Is it a product? (Doesn't mean it's a venture-scale business; could be bootstrapped.)

This systematic questioning helps avoid building solutions for non-existent markets or misjudging market potential.

In terms of product development, Haleliuk stresses two key aspects for Minimum Viable Product (MVP) scoping:

  1. Trust and Transparency: Trust is the paramount factor influencing a security leader's willingness to even try a tool. Strategies to build trust include:
  • Open-source development: Releasing components or the entire product as open source allows for peer review and transparency, addressing concerns about hidden functionalities or security vulnerabilities.
  • On-premises deployment options: Offering the ability to deploy solutions within a customer's own environment, under their control, directly addresses data sovereignty and security concerns that cloud-only solutions might raise.
  • Community validation: Leveraging peer testimonials, industry recognition (e.g., from investor groups like SVCI), and angel investors who are respected security leaders can significantly boost a startup's reputation.
  • Free trials/Proof of Value: Providing clear pathways for customers to test the product's efficacy and security in a controlled manner is essential.
  1. Design Partners: Haleliuk unequivocally states, "Don't ever try to build something unless you have design partners." These are early customers willing to deploy the product, provide feedback, and help shape its development. Securing design partners validates that a problem is significant enough for someone to invest time and resources in a nascent solution. It also forces founders to develop sales skills early, proving that they can articulate value and convince others before committing substantial development effort. Building in isolation for six months to a year without external validation is identified as a common, costly mistake.

Finally, Haleliuk touches on the "lend and expand" strategy, a common growth model where a product starts by solving a small niche problem exceptionally well, then expands into related areas. While seemingly logical from a startup's perspective, he highlights how this looks from the buyer's angle: an environment saturated with dozens of point solutions, each attempting to grow their footprint. This creates a "battle of vendors" within every company's environment, making it incredibly challenging for new point solutions to gain lasting adoption, especially when larger vendors like Palo Alto Networks can quickly integrate "good enough" features, leading to existing solutions being "ripped out six months later." This underlines the need for a comprehensive understanding of the competitive landscape and a strong, defensible value proposition beyond just solving a niche problem.

Demo / Proof of Concept

▶ Watch: Difficulty in demonstrating product value and efficacy (6:05)

The talk "Building Cyber Products Customers Love" by Ross Haleliuk is a strategic discussion on product management in cybersecurity and does not include a live demonstration or proof-of-concept of a specific security tool or technology. The focus is entirely on the methodologies, challenges, and best practices for developing and bringing security products to market effectively.

Defensive Implications

▶ Watch: Buyers prioritize time to value over efficacy (6:40)

While Haleliuk's talk is primarily aimed at product builders, its insights carry significant implications for security practitioners and defenders who are on the receiving end of these products. Understanding the challenges faced by product teams can empower defenders to make more informed purchasing decisions and even contribute to the development of better tools.

Firstly, defenders should be aware of the pervasive customer discovery challenge. When approached by vendors, security professionals often face a dilemma between safeguarding information and providing useful feedback. Haleliuk's talk suggests that a more structured, trust-based engagement is necessary. Defenders can help bridge this gap by being more open (within appropriate boundaries) about generic pain points and desired capabilities, rather than specific vulnerabilities. Participating in design partnerships or beta programs, when feasible, is a powerful way to influence product development directly, ensuring tools are built to solve real-world problems and integrate seamlessly into existing workflows.

Secondly, recognizing the limitations of traditional product management frameworks means defenders should look beyond marketing hype or "growth-hacked" features. Instead, prioritize vendors who demonstrate a deep understanding of the security domain, a clear problem statement, and a robust technical foundation. Focus on vendors who can articulate how their solution addresses specific, complex challenges within your environment, rather than generic benefits. The emphasis on time to value and the ease of POC is crucial for defenders; prioritize solutions that offer quick, demonstrable results and minimal operational overhead during evaluation.

Thirdly, the insight into opinionated products versus customizable needs is critical. Defenders should actively seek out tools that offer high configurability and integration capabilities, allowing them to adapt the solution to their unique environment, existing tech stack, and specific security policies. A rigid, "my way or the highway" product might seem efficient initially but can quickly become a bottleneck or create operational friction. During evaluations, defenders should probe how a product handles customization, integration with other security tools (e.g., SIEM, SOAR), and scalability within their specific infrastructure.

Finally, understanding the oversimplified buying journey helps defenders navigate internal procurement processes more effectively. If you're an individual practitioner championing a tool, recognize that a bottoms-up approach is often insufficient. Build a strong business case that resonates with leadership, addressing their concerns about compliance, risk reduction, and return on investment. If you're a CISO, understand that team buy-in is paramount. Involve your practitioners early in the evaluation process to prevent internal sabotage and ensure successful adoption. Be wary of solutions that don't account for the full spectrum of stakeholders—from the technical user to the budget holder—as they are less likely to succeed in a complex enterprise environment.

By internalizing these product management insights, defenders can become more discerning buyers, more effective advocates for their needs, and ultimately, contribute to a cybersecurity ecosystem that produces more relevant, user-friendly, and impactful solutions.

Key Takeaways

  • Cybersecurity product management is unique: It differs significantly from other industries due to a low install base, expert user base, short release cycles, and prevalence of legacy enterprise environments.
  • Customer discovery is paramount and challenging: Security practitioners are incentivized to conceal gaps, making traditional problem-discovery difficult. Engage with both buyers (CISOs) and end-users, and use structured interviewing techniques (e.g., "The Mom Test") to avoid biases.
  • Traditional B2C product frameworks are ineffective: "Growth hacking" and A/B testing don't apply to the B2B cybersecurity market, which requires a deep understanding of specific problems and highly opinionated, yet customizable, solutions.
  • Trust and transparency are critical for adoption: Build trust through open-source options, on-premises deployment, peer validation, and design partners. Early engagement with beta customers is non-negotiable for validating market need and product direction.
  • The buying journey is complex and multi-faceted: Do not oversimplify by only targeting CISOs or attempting a "bottoms-up" approach. Understand the motivations (compliance vs. security), budget authority, and potential internal impediments across all stakeholders.
  • Challenge all assumptions rigorously: Just because a problem exists doesn't mean there's a market, a willingness to pay, or a venture-scale product opportunity. Continuous validation is essential to avoid wasted effort.

About the Speaker(s)

Ross Haleliuk is a recognized expert in cybersecurity product management, known for his deep insights into the unique challenges and opportunities within the industry. He is a passionate advocate for building customer-centric security solutions. As an author, he has contributed significantly to the body of knowledge on the subject, including a book mentioned during his talk, which further establishes his authority and commitment to sharing best practices in cybersecurity product development. His background and experience allow him to speak with authority on the intricacies of bringing security products to market, making his perspectives invaluable to founders, product managers, and security leaders alike.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Haleliuk knows his domain and delivers a coherent, practitioner-informed take on why cybersecurity product management is genuinely harder than adjacent B2B markets. The content is competent and organized, but it's fundamentally a well-structured blog post delivered on stage — nothing here will surprise anyone who's spent time on the vendor or operator side of this industry.

Heather Calloway (CISO) — WEAK

Haleliuk knows his domain and the structural critique of how cyber products get built and bought is legitimate. But this talk is aimed at founders and product managers, not the security leaders and operators who make up the governance and defense audience — and the article's attempt to retrofit 'defensive implications' doesn't close that gap.

→ Top-rated talks at BSides NYC 2024

All talks from BSides NYC 2024