When Build vs Buy Is Rigged: Selling to Enterprises That Prefer Building In-House

Amir Kavousian

BSides NYC 2025 (0x05) · Day 1 · Entrepreneur

Overview

In the competitive landscape of cybersecurity startups, a founder's most formidable adversary often isn't another vendor, but rather the deeply ingrained "build in-house" culture prevalent within many enterprise security teams. Amir Kavousian, a seasoned second-time founder, delves into this critical challenge, offering a candid exploration of the psychological and strategic hurdles faced by early-stage security companies attempting to sell their solutions. His talk, "When Build vs Buy Is Rigged," posits that the decision-making process within these large organizations is far from purely technical or financial; it is fundamentally human-driven, influenced by individual motivations, career aspirations, and internal political dynamics.

Watch on YouTube

Visual summary for When Build vs Buy Is Rigged: Selling to Enterprises That Prefer Building In-House by Amir Kavousian
Visual summary for When Build vs Buy Is Rigged: Selling to Enterprises That Prefer Building In-House by Amir Kavousian

Key moments

  1. 0:00 Introduction: Competing against in-house build culture
  2. 1:30 Core lesson: Sell to a human, not an organization
  3. 2:15 Introducing three customer personas: Pragmatist, Hero, Strategist
  4. 4:30 Strategy for Pragmatists: Show delay and waiting is costly
  5. 6:30 Introducing the Hero persona: Valuing flexibility, visibility, ownership
  6. 8:00 Strategy for Heroes: Free them from grunt work for cool tech

When Build vs Buy Is Rigged: Selling to Enterprises That Prefer Building In-House

Speakers: Amir Kavousian

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=gBGIK5w8Kk4

Overview

In the competitive landscape of cybersecurity startups, a founder's most formidable adversary often isn't another vendor, but rather the deeply ingrained "build in-house" culture prevalent within many enterprise security teams. Amir Kavousian, a seasoned second-time founder, delves into this critical challenge, offering a candid exploration of the psychological and strategic hurdles faced by early-stage security companies attempting to sell their solutions. His talk, "When Build vs Buy Is Rigged," posits that the decision-making process within these large organizations is far from purely technical or financial; it is fundamentally human-driven, influenced by individual motivations, career aspirations, and internal political dynamics.

Kavousian asserts that to succeed, founders must shift their focus from selling to an abstract "organization" to understanding and engaging with the specific "human" personas involved in the buying journey—be it a CISO, a security engineer, or a CTO. He introduces three distinct archetypes he's encountered: the Pragmatist, the Hero, and the Strategist, each with unique priorities and concerns that dictate their approach to external solutions versus internal development. The core message is that by dissecting these human elements, startups can craft tailored messaging and collaboration strategies that effectively dismantle the "build-first" mentality and position their products as indispensable partners rather than mere alternatives.

This talk is particularly relevant for security founders navigating the complex sales cycles of large enterprises, but it also offers valuable insights for anyone involved in B2B sales within a technical domain. Kavousian's "battle scars" from selling to Fortune 100 companies and government organizations provide a practical, experience-backed framework for understanding why "build vs. buy" often feels "rigged" and, more importantly, how to level the playing field by appealing to the deeper, often unstated, motivations of key decision-makers.

Background

▶ Watch: Introduction: Competing against in-house build culture (0:00)

The "build vs. buy" dilemma is a long-standing challenge in enterprise technology, but it takes on a unique dimension within cybersecurity. Many large organizations, particularly those with mature security programs, have fostered a strong culture of developing internal tools and solutions. This tendency stems from several factors: a belief that their problems are bespoke and unique, a desire for maximum control and flexibility, a sense of technical pride among engineering teams, and historical inertia from years of custom development. Often, the "competitor" for a new security startup isn't another commercial product, but rather an internal script or tool built years ago by an engineer who may have since moved on, leaving behind a legacy system that the organization continues to maintain.

This internal build culture creates significant headwinds for external vendors. Security teams, especially those with substantial in-house engineering capabilities, often default to asking, "Can we build this ourselves?" before considering a third-party solution. This question immediately reframes the sales conversation, shifting the burden onto the vendor to prove not just superiority, but necessity, often against a perceived "free" or already-owned internal alternative. The challenge is compounded by the fact that internal tools, while potentially meeting specific immediate needs, often come with hidden costs: ongoing maintenance, scalability issues, lack of dedicated support, and the opportunity cost of diverting engineering resources from core business initiatives.

Amir Kavousian's talk addresses this fundamental problem by acknowledging that these "build-first" organizations are not monolithic entities driven purely by objective metrics. Instead, the decision-making process is a complex interplay of individual motivations. He notes that the Gartner B2B buying journey, while comprehensive, can be condensed into specific considerations for these personas. The background of this problem is rooted in human nature: the desire for control, recognition, and minimizing disruption, all of which contribute to the preference for internal solutions, even when external options might be more efficient or robust.

Key Findings

▶ Watch: Introducing three customer personas: Pragmatist, Hero, Strategist (2:15)

The central and most critical finding of Kavousian's talk is that successful engagement with enterprises that favor building in-house hinges entirely on recognizing and appealing to the human motivations of the individuals involved in the buying process, rather than treating the organization as a faceless entity. He emphasizes, "You are not selling to an organization or a company. You're selling to a human." This fundamental shift in perspective allows founders to navigate the complex internal dynamics that often masquerade as purely technical or financial objections.

Kavousian identifies three primary personas that founders are likely to encounter in build-in-house organizations, each with distinct priorities and a corresponding "buying journey" in their minds:

  1. The Pragmatist: Their paramount concern is maintaining operational flow with minimal risk. Change is viewed as disruption. They prioritize low onboarding disruption, workflow disruption, and integration degradation. Their initial question is always, "Can we technically build this in-house?" followed by, "Do we have the headcount and resources?" For them, the key is to demonstrate that delay is not neutral, exposing them to revenue blocks, compliance risks, security risks, and significant engineering opportunity costs.
  2. The Hero: These individuals derive significant pride from their technical leadership and ability to build innovative solutions. They value flexibility, visibility, and ownership. Their primary questions revolve around whether a third-party solution is technically superior, and crucially, if it frees them up to work on "more interesting stuff" like AI or LLMs, rather than "toil and grunt work" such as uptime and integrations. Their buying journey often starts with "Is this a fun problem to solve?"
  3. The Strategist: Operating at a higher organizational level, Strategists are concerned with business risk, compliance, and internal influence. They think several steps ahead, focusing on building alliances and accumulating political capital. Their questions center on whether buying gives up control, whether relying on a third party puts them "in a corner," and the long-term viability of an early-stage startup. They seek high-visibility problems that can enhance their team, organization, and career, and they prioritize vendors who can deliver not just now, but years into the future.

By understanding these personas, founders can move beyond generic sales pitches and craft targeted messaging and collaborative strategies that resonate deeply with the individual's core motivations, effectively transforming potential competitors (internal builders) into collaborators or champions for an external solution.

Technical Deep Dive

▶ Watch: Strategy for Pragmatists: Show delay and waiting is costly (4:30)

While Kavousian's talk isn't about traditional security exploits or protocols, it offers a "technical deep dive" into the architecture of effective sales strategies for build-culture enterprises. It outlines specific, almost algorithmic, playbooks and messaging strategies tailored to each human persona, treating the sales process as a form of psychological engineering.

For the Pragmatist, the "technical" approach is rooted in quantifiable ROI analysis and risk mitigation. Founders must actively help the Pragmatist conduct an ROI analysis specific to their organization's metrics. This involves demonstrating how the vendor's solution saves time without adding complexity, explicitly highlighting the cost of internal development—not just monetary, but also engineering opportunity cost, revenue growth issues, and compliance/audit risks incurred by delay. The messaging emphasizes minimal disruption: "low onboarding disruption, low workflow disruption, and low integration degradation." The goal is to show that the cost of trying the product is minimal, and the cost of not buying is substantial due to ongoing maintenance, potential service disruptions (e.g., an internal tool for 4 engineers scaling to 400 and breaking), and the need for dedicated on-call resources.

Engaging the Hero requires a different technical architecture, focusing on empowerment and collaboration. The strategy is to acknowledge and respect their technical prowess. Instead of challenging their ability to build, the messaging highlights how the vendor's solution automates the "grunt work" (e.g., uptime, integrations, API maintenance), freeing the Hero to focus on the "10% cool stuff" like advanced AI/LLM development, which is more résumé-building. The "technical" playbook here involves becoming a collaborator, not just a vendor. Founders are encouraged to exchange notes on common problems (e.g., LLM hallucination, uptime challenges), fostering a dialogue about shared challenges rather than a direct sales pitch. A key tactical mechanism is to integrate deeply with their existing tech stack. This means offering APIs they can use, scripts they can write against the application, and being flexible enough to provide building blocks that enhance their current environment without forcing a workflow change. The speaker's example of working with a public social media company involved regular meetings, sharing "war stories" about integration breaks and platform fixes, which eventually built trust and demonstrated the complexity of maintaining a robust solution.

For the Strategist, the "technical" sales strategy involves understanding and leveraging their need for influence, visibility, and risk transfer. The core messaging is: "You own the outcome, we own the risk." This means the Strategist gets the recognition and political capital for bringing in a successful solution, while the vendor bears the burden if it fails, or if the internal engineer leaves, creating an "orphan tool." The playbook for Strategists includes:

  • Giving them control of the narrative: Helping them present at conferences, featuring them in podcasts or newsletters to amplify their visibility and thought leadership.
  • Quantifying risk reduction: Providing dashboards and metrics that clearly show identified or prevented risks, allowing them to hit internal KPIs and use these as "ammunition" to justify continued product use and their own influence.
  • De-risking the vendor relationship: Especially for early-stage startups, addressing concerns about long-term viability. This might involve clear contractual terms with "time bombs" (e.g., a 3-month evaluation period with specific metrics) to build initial trust without open-ended commitments.

Across all personas, Kavousian stresses the importance of understanding the underlying motivations beyond surface-level objections like cost. Sometimes, internal conflicts or personal agendas drive the "build vs. buy" conversation, necessitating the ability to "move on" or "pause" a deal until deeper understanding is achieved. This "technical" understanding of human psychology, rather than product features alone, is the true engine of sales success in these challenging environments.

Demo / Proof of Concept

▶ Watch: Introducing the Hero persona: Valuing flexibility, visibility, ownership (6:30)

While Amir Kavousian's talk does not feature a live software demonstration or a traditional proof of concept for a security product, his entire presentation serves as a conceptual demonstration and experiential proof of concept for his sales methodology. He validates his strategies through compelling anecdotes and real-world scenarios drawn from his extensive experience as a second-time founder, having successfully sold to Fortune 100 companies and government organizations.

A particularly illustrative example, shared by Kavousian, involves a data security product and a lead from a large public social media company known for its strong "build culture." This company believed their problems were "specific and bespoke," requiring custom solutions. Instead of immediately pushing metrics or dashboards, Kavousian and his team adopted a collaborative approach over several months. They engaged in regular, often monthly or bi-monthly, meetings where Kavousian shared "war stories" from his own experiences—for instance, an integration breaking without prior notification and how his platform quickly detected and fixed it.

These discussions served as the "proof" for the social media company. They began to acknowledge, "Yes, we are seeing the same thing," and recounted their own internal struggles, like an integration breaking two weeks prior and causing significant internal issues. This collaborative sharing of challenges and solutions, rather than a direct sales pitch, gradually built trust and demonstrated the complexities of maintaining a robust, scalable security product. After almost a year of this collaborative engagement, the company, despite having built a similar tool internally, ultimately signed up with Kavousian's platform. This protracted but successful engagement stands as a powerful testament to the efficacy of understanding specific persona motivations (in this case, likely a blend of Hero's technical pride and Pragmatist's need for stability) and leading with help and shared experience rather than aggressive sales tactics. It's a "proof of concept" of the human-centric sales approach itself.

Defensive Implications

▶ Watch: Strategy for Heroes: Free them from grunt work for cool tech (8:00)

Amir Kavousian's talk, primarily aimed at founders selling into enterprises, offers a unique lens for defenders within those organizations. While it doesn't provide traditional "defensive implications" in terms of new security controls or threat mitigation strategies, it offers invaluable insight into the psychology and tactics of vendors attempting to sell them solutions. For security professionals on the "buy" side, understanding these dynamics can significantly empower them in their decision-making process.

Firstly, defenders can recognize the sales personas (Pragmatist, Hero, Strategist) within their own teams and among their stakeholders. This self-awareness can help them anticipate internal objections, understand underlying motivations for favoring a "build" approach, and better articulate the true costs and benefits of external solutions. For instance, a security engineer with a "Hero" mentality might indeed be more interested in working on "cool stuff" like LLM-based tools, and a CISO with a "Strategist" mindset might be more concerned with demonstrating risk reduction to the board than with the minutiae of a product's features. Recognizing these motivations allows defenders to frame their own evaluations and internal proposals more effectively.

Secondly, the talk reveals how vendors are trained to dismantle the "build-first" argument. Defenders can use this knowledge to critically evaluate vendor claims. When a vendor emphasizes ROI analysis, quantifying opportunity cost, or minimizing disruption, defenders can scrutinize these claims more thoroughly, asking pointed questions about the methodology, hidden costs, and potential integration challenges that might still arise. They can also be wary of vendors attempting to "collaborate" by sharing "war stories" if the intent isn't genuine partnership but a subtle sales maneuver.

Thirdly, understanding the vendor's strategy of risk transfer ("You own the outcome, we own the risk") can be a powerful tool for defenders. It highlights that a commercial product, particularly from a reputable vendor, inherently carries a different risk profile than an internally developed tool that might become an "orphan" if key personnel leave. Defenders can leverage this argument internally to justify "buying" solutions for critical functions, especially when internal resources are stretched or the problem requires dedicated, specialized support.

Finally, Kavousian's emphasis on leading with help, not hype, suggests that defenders should seek out vendors who genuinely understand their unique challenges and are willing to integrate seamlessly into existing workflows, offering APIs and building blocks rather than forcing radical changes. This perspective can guide defenders in identifying truly valuable partners who prioritize long-term collaboration over a quick sale, ultimately leading to more effective and sustainable security outcomes for the enterprise.

Key Takeaways

  • Sell to Humans, Not Companies: The most crucial insight is that enterprise buying decisions are driven by individual motivations, career aspirations, and internal politics, not just objective organizational needs. Understanding these human elements is paramount.
  • Identify and Engage Personas: Tailor your messaging and strategy to three core personas: the Pragmatist (minimize disruption, quantify ROI), the Hero (free them from grunt work to do "cool" tech, offer collaboration), and the Strategist (transfer risk, provide influence, enable narrative control).
  • Delay is Not Neutral: Clearly demonstrate the hidden costs and risks of building in-house or delaying a purchase, including engineering opportunity costs, revenue blocks, compliance risks, and the burden of ongoing maintenance and scalability.
  • Lead with Help and Collaboration: Approach potential customers as collaborators, not just vendors. Exchange notes on shared challenges, offer to co-present case studies, and integrate deeply with their existing tech stack through APIs and scripts, rather than forcing workflow changes.
  • Own the Risk, Share the Recognition: Position your product as a de-risking mechanism. The vendor owns the operational risk and maintenance burden, while the internal champion (the Strategist) gets the recognition and political capital for the successful outcome.
  • Quantify Value and Provide Ammunition: Equip internal champions with dashboards, metrics, and data points that quantify risk reduction and value delivered, allowing them to hit KPIs and justify continued use and investment internally.

About the Speaker(s)

Amir Kavousian is a highly experienced and insightful entrepreneur in the cybersecurity space, currently serving as a second-time founder. His talk at BSides NYC draws heavily from his personal journey and the "battle scars" acquired through years of successfully selling security solutions to a diverse range of clients, including Fortune 100 companies, government organizations, and other security firms. Kavousian's expertise lies not just in product development, but crucially, in understanding the complex human and organizational dynamics that govern technology adoption within large enterprises. His practical wisdom, shared candidly in this presentation, is forged from direct experience in navigating the challenging "build vs. buy" landscape, making him a credible and valuable voice for fellow founders.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent BSides talk aimed squarely at security founders navigating enterprise sales cycles, not a security research session. Kavousian's three-persona framework is practical and clearly battle-tested, but the content is essentially a well-organized sales psychology primer that any SaaS founder blog or go-to-market consultant could have delivered. No novel frameworks, no data, no surprises for anyone who has spent time on either side of enterprise procurement.

Heather Calloway (CISO) — WEAK

Kavousian has real experience and the core observation — that build-vs-buy decisions are driven by human politics, not technical merit — is legitimate. But this is a founder sales playbook dressed up as security insight, and it doesn't cross into territory that matters to operators, defenders, or governance leaders.

→ Top-rated talks at BSides NYC 2025 (0x05)

All talks from BSides NYC 2025 (0x05)