Brian Sims
Editor

Research reveals impact of AI cyber attacks on cyber security buying

GLOBAL B2B tech PR and marketing agency The Hoffman Agency has published the results of research revealing the impact of Artificial Intelligence (AI) cyber attacks on the cyber security buying landscape and what now influences vendor selection.

The report, released under the heading ‘Fast Decisions, High Stakes’, highlights the fact that, despite many organisations planning to invest in securing their AI models in the next year, there’s also a focus on the cyber security ‘basics’.

Conducted by Coleman Parkes Research among 500 cyber security decision-makers in the UK, the US, France and Germany, the study finds that 67% of organisations have plans to increase the level of their cyber security investment in the next 12 months, while 62% are either looking for a new provider or to switch their current provider.

The foremost solutions for new investment are AI security, security operations and identity access management, while network security, endpoint security and security analytics are those most likely to be replaced.

While reducing costs and coping with talent shortages are driving some to invest in new solutions, the most common reason is simple: 55% of respondents state that they’re investing due to “the need to respond to threats.” Such threats include phishing, malware, ransomware and social engineering.

The “need to secure AI systems” is the second biggest investment reason for 38% of respondents globally, jumping to 48% here in the UK.

“Like many, the cyber security industry has had to adapt to AI adoption and advancements, geopolitical tensions and economic uncertainty over the past year,” explained Florie Lhuillier, head of cyber security and senior vice-president at The Hoffman Agency. “Naturally, this is having implications in terms of how organisations address their cyber security investments, but not how we thought it might. The market remains buoyant for all types of cyber security solutions and services.”

Buying journey

Clearly, organisations view the next 12 months as a period of changing priorities, which is good news for vendors. However, the key to making the most of this market and being selected for RFP processes is to better understand the buyer journey.

Cyber security buyers are making their purchasing decisions quickly. On average, cyber security purchases take seven months from need identification to vendor selection across all countries surveyed. However, most (55%) take less than six months. Given the level of investment, these are fast decisions.

Vendor engagement occurs early in the buying process. 65% of potential buyers make contact with their vendors before the shortlisting stage. Only 9% wait until they are making a final decision to engage in direct contact. 

Buyers are relying on Large Language Models (LLMs) for both initial research and final selection, along with various sources and channels. The top four sources/channels of information for initial awareness are direct peers (35%), industry analysts (32%), industry events (28%) and industry trade media (26%).

For final selection, the top sources are similar: industry analysts (23%), industry events (23%), direct peers (22%) and management consultants (22%). One-fifth of respondents are also using LLMs for both awareness and selection and even more so in the US (24%).

All content types, both short and long-form, are influential. The top four content types for final selection are industry analyst reports featuring the vendor (39%), a conference panel from a vendor (32%), Case Studies (29%) and LLMs (29%). LLMs feature again here and are higher than popular marketing techniques such as e-mail marketing, but below Case Studies and webinars.

It’s even higher for the US (30%) and the Uk markets (34%). This complicates matters for marketers, who need to provide the materials that feed LLMs, not just the material that buyers are engaging with on a direct basis.

Biggest impact 

Easy integration and value for money have the biggest impact on vendor selection. 89% of respondents agree that value for money and a simple and easy integration will drive decision-making the most, yet evidence of delivering for similar businesses follows closely behind (87%).

However, it’s particularly important to note that ‘value for money’ is more important than ‘cost-effectiveness’, showing that buyers are happy to spend if they feel doing so is going to be worth it.

“The usual process of awareness, longlisting, shortlisting and decision being streamlined to make a decision quickly and imparting messages has never been more important for marketing teams’” concluded Florie Lhuillier. “However, as we’ve seen from the research, there’s no marketing ‘silver bullet’. From opinion articles and podcasts to industry analyst reports, buyers are influenced by everything. Cyber security marketers should therefore design an integrated marketing strategy that uses a mix of different channels and content types to reach their target audiences, even more so as LLMs become more important and pull in information from all different sources.”

*Read the full report and learn more about the channels and content types cyber security vendors should be prioritising

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up