← Back to Playbook
Playbook Cyber and Data

Proof Engine

Security and data buyers are trained skeptics. They run credibility checks before a first call and they are looking for receipts, not opinions. This playbook is the receipts system: the audit to run on your own site, the proof pyramid, and the publishing cadence that keeps receipts in public view.

The buyer credibility audit

Most cyber and data firm websites fail a specific set of credibility checks that buyers run, usually without the firm ever knowing it happened. Open your own site and run these:

  1. Is there one named client visible, with context, anywhere on the site?
  2. Is there a number anywhere on the site that a buyer could verify independently?
  3. Does the services page describe outcomes, or only capabilities?
  4. Does the "about" section name the humans doing the work, or only the company?
  5. Is there a public artifact (writeup, advisory, post, talk) from the last 90 days?
  6. If the site says "we are trusted by X", is there anything next to that claim proving it?

Firms we audit typically fail three or more of these at once, which is enough to lose a deal silently, because the buyer had no way to verify and had to decide on gut feeling against a firm that had receipts.

The proof pyramid as content

Proof has four levels. Each level has a publishable form:

Level 1 badges

SOC 2, ISO, HIPAA, or a named audit firm. Lowest value on its own, but it must be visible on the page where the primary services sit, not on a subpage.

Level 2 before/after metrics

Full draft, metric-ledWe stopped a client's access-graph sprawl last month. 41 service accounts with standing production access went down to 4, with just-in-time access for the rest. Their audit prep went from three weeks of scramble to a two-hour review. No new tool bought. The fix was a policy engine, not a product.

Level 3 named clients

Full draft, named-client structureWorking with [named health system] this quarter on their identity access review. One of two named wins we just added. The other is a fintech where we found 631 credential items that regressed past the baseline. Both are on our site now. Saying numbers in public is a choice. Most firms never make it.

Level 4 owning the miss

Full draft, self-critiqueA fix we shipped in July did not hold. We wrote the post-mortem anyway. Told the client first. The regression that slipped back through was a permissions scope we configured too broadly on day one. Rebuilt it smaller, documented the boundary, shipped the fix in 3 days. What buyers trust is not the absence of misses. It is that the miss did not hide underground.

Publishing cadence for proof

What needs to exist: one standing artifact (a technical writeup or short advisory), one named case study, one research or findings post per month. Exact rhythm: technical writeup first Tuesday, case study second Tuesday, findings post last Tuesday. Each of these gets one LinkedIn post pointing at it from the founder's profile, one week after the artifact ships.

What actually kills it

Proof accumulates in proposal decks because the deck is where someone asked for it. Meanwhile the professional surface where buyers actually look (the site, the founder profile) still reads like capabilities. Proof that only exists in decks is proof a stranger will never see. Publishing, not writing, is the gap.

The weekly engine

The $500/month system includes proof harvesting as part of the monthly angle refresh. What it covers for a security or data firm:

Book a 15-minute pipeline call, or reply "run it".