While I’m on marketing, let’s talk about Cybersecurity Awareness Month. You may have noticed that I haven’t done anything at all about this. That’s intentional – I cover this story regularly anyway, so I don’t need more.
That said, Axios Markets said what I was thinking – that the marketing efforts could drown out the educational impact of the messaging.
The core premise of the month – the idea is that every October, the Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance host Cybersecurity Awareness Month to educate individuals about basic cyber hygiene practices and encourage security professionals to re-evaluate their organizations’ cyber strategies.
Sales pitches have now become linked to that – plugging products as part of the messaging. Multiple companies have done this – and Axios even says, “IT management software company Kaseya published a blog post right before the month started titled, “How to Win More Business During Cybersecurity Awareness Month.”
The piece quotes some experts saying there is certainly space to break through the noise, and “consultants who advise companies to establish their own cyber awareness and training programs say having a dedicated month-long campaign actually does help.” This includes C-level execs more inclined to lead efforts and organizations investing.
So I’ll also observe that Gartner has coverage in CRN on their new report that spending on cybersecurity is expected to remain robust in 2023 despite fears of a downturn. They estimate that security spending will rise by 11.3% in 2023, compared to the 7.2% increase this year.
It would be really easy jump on the Kaseya bandwagon here – and I’m self aware enough to note this piece got further attention by their mention. However, there’s two reasons. First, let’s observe that the entire services space takes the heat for that headline, and second, that major outlets like Axios are watching the IT services space now because of Kaseya… and not because they made headlines for good reasons. That breach resonates.
I’ve been pushing back on cybersecurity opportunism because it’s gross… but it’s also damaging. If everything becomes a sales pitch, customers will tune it out. Your takeaways are two fold – first, be aware of how your messaging comes across, and avoid that “here’s a scary thing so buy my product” approach. And second, push back on vendors making education less effective who do that same thing.
