Watched a guy at BSides Raleigh demo a phishing email in 90 seconds, and I scrapped our whole deck that night | Cybersecurity Marketing - Babble Community
Watched a guy at BSides Raleigh demo a phishing email in 90 seconds, and I scrapped our whole deck that night
I was at BSides Raleigh two weeks ago, mostly to hand out stickers and eat the free pizza, and this speaker did something that stuck with me. He pulled up a plain text email on screen, read it out loud, and pointed at the two words in the subject line that he said were doing all the work. Then he timed himself rewriting it for a fake CFO wire request. Ninety seconds, start to finish. Meanwhile my own team's slide deck has 14 slides about our threat intel feed before we ever show a screenshot of an actual attack. I sat in the back row feeling kind of dumb. We rewrote our whole demo that night in the hotel lobby and cut it from 22 minutes down to 7, and the first live call with a prospect after that ran 40 minutes instead of timing out at 20. Now I keep asking myself why we spent so long selling features when buyers just want to see the thing happen. Has anyone else ditched the slide-heavy pitch for a live attack walkthrough, and did your sales team push back on it?
Man, YES. I had almost the exact same thing happen after a local DC group meetup last spring. The guy did a live smish demo on his own phone, screen mirrored, and had half the room wincing in like two minutes because he used a real fake delivery text and walked through exactly which link gave him the creds. Our deck at the time had this huge lead-in about our "platform" before we ever showed a payload, and our AE fought me HARD when I said we were cutting it. She was sure buyers needed the whole story first. We compromised on a 3 slide setup and then straight into a live phish, and the very first call after that, the guy stopped us mid walkthrough and said "can you back up, I want to see the header again." Nobody ever asked to see a header during a slide. That was the moment I knew.