Brand has been waiting for this moment
Maria Velasquez on what B2C has known for 100+ years

October 8, 2026

Joe Pettit

Joe P is the Managing Director of Bora. He has 15 years in the cybersecurity industry, helping security vendors with brand marketing, thought leadership, lead generation, and strategy.

Maria Velasquez stumbled into cybersecurity marketing and never left. After building her foundations in marketing operations at an event tech company, she fell into cyber by applying for a role she wasn’t sure she was qualified for. In 2020, she co-founded the Cybersecurity Marketing Society with her partner Gianna out of a personal need for peer support during a difficult startup stint. It now has over 4,000 global members and runs the annual CyberMarketingCon conference.

Maria is Director of Growth Marketing at Brinqa. We spoke about how buyers are making decisions, why ‘brand’ is having its long-overdue B2B moment, and why too many cybersecurity marketers are still avoiding the one thing that would make them better at their jobs. 


You didn’t plan a career in marketing. How did you end up in cybersecurity?

Marketing itself happened by chance, and cybersecurity happened by even more chance. 

I studied political science as an undergrad and planned to go to law school. I took the LSATs, failed miserably, and had one of those moments where you realize you need a different plan. I ended up working at my university in an administrative role, and one of the benefits as a full-time employee was being able to do my master’s degree in PR & Communications for free. That became my entry point into marketing. 

From there, I joined an event technology company and fell in love with marketing operations. I loved the geeky side of marketing. Lead measuring, campaign setup, customer journeys, HubSpot, Salesforce, all the systems and processes behind the scenes. It was the height of inbound marketing, and I was obsessed with understanding how everything connected together. 

The cybersecurity move came when I saw a marketing role at a company in Connecticut. I didn’t know cybersecurity, but I knew marketing operations well, so I applied anyway. 

The funny part is that during the interview, they asked me what I would do in the first six months. I told them I’d rebrand the website. Their response was, “We just redid the website.” Somehow, I still got the job, and eventually we did redo the website (again). 

That company became my cybersecurity education. The product was used by intelligence agencies, government organizations, and critical infrastructure operators. It created a one-way flow of data between environments, preventing attackers from coming back the other way. It was probably the most technical product I’ve worked on to this day. 

When you spend years learning OT, IT, air gaps, one-way data flows, national grids, and critical infrastructure security, everything else feels a little less intimidating. I always joke that it was my MBA in cybersecurity. 

I did leave the industry once. I spent about 18 months in EdTech selling a student engagement platform. It was a great company, but I got bored quickly. Selling a chat tool to universities is very different from talking about cybercriminals and cyber warfare. I had to come back!

You co-founded the Cybersecurity Marketing Society during what sounds like a genuinely difficult moment. What was going on?

I had just left that first cybersecurity company and joined my first startup as the first marketing hire. 

I was turning on the lights for everything. Building a go-to-market strategy, building a team, figuring out systems, creating programs, doing all of it at once. Looking back, I was probably too young in my career for something that big. But I was ambitious and optimistic enough to say yes anyway. 

I realized quickly I needed help from people who had already done it before. 

I had stayed in touch with Gianna after we met years earlier when I interviewed for a role she was leaving. One day, I called her crying. I told her it was really hard, that I wasn’t jiving with my boss, that expectations felt unrealistic, and that I had no idea what I was doing at that scale. 

She told me she’d been thinking about starting a group for cybersecurity marketers to come together and help each other. I said yes immediately.

“We started it selfishly. We needed somewhere as marketers ourselves to connect with four-time CMOs who’d made the mistakes already.”

We opened a Slack workspace, built a website, created a logo in Canva, and started DMing CMOs and marketing leaders to ask if they wanted to join. 

For the first few years, we both worked on it while still holding full-time jobs. Gianna moved into the community full-time before I did, but for a long time, it was nights, weekends, and whatever spare hours we could find. 

What’s still amazing to me is that it grew almost entirely organically. We didn’t run acquisition campaigns. We didn’t have some huge growth strategy. People found value in it and told other people. 

Today, we’re more than 4,000 members globally, which still feels surreal when I think about where it started. 

CyberMarketingCon started as a virtual conference during COVID and became something much bigger than you expected. What happened?

The first conferences were virtual because that’s what the world looked like in 2020. 

We were shipping conference boxes from my house. My kids were helping pack t-shirts, stickers, and swag bags in the dining room. We’d print labels, load everything into the car, and take it to the post office ourselves. 

It was very much a family operation. Then, in 2022, we decided to take the conference in-person in Arlington, Virginia.

”We thought 80 people maximum would show up. 220 people bought tickets.”

We were completely unprepared for that level of demand. The venue was packed, for some sessions were standing room only. Food lines were longer than expected. We were bringing in extra solutions at the last minute because we simply hadn’t anticipated that many people. 

It was messy and scrappy, but it was probably my favorite conference we’ve ever done. 

That was the moment when we realised we had something real. People didn’t want another event where they were being pitched to all day. They wanted a place where cybersecurity marketers could learn from each other, compare notes, and have honest conversations about what was working and what wasn’t. 

One thing we noticed early on was that security buyers genuinely want to tell marketers how to do better marketing. They’re overwhelmed by emails, ads, cold calls, and outreach. They have opinions about it. 

CyberMarketingCon became a place where those conversations could happen directly. That felt important. 

You’ve been watching cybersecurity marketing from multiple angles for years. How has buying behavior shifted?

I love that brand in B2B is getting its moment and finally, recognition. For years it felt like everything was demand generation. Hire more demand generation people, build more pipeline, attribute every dollar, measure every click. 

Then companies started realizing something important. If nobody knows who you are, demand generation has very little to work with. You can’t generate clicks forever without investing in the thing that makes people remember you. 

The other thing I think marketers are finally becoming more comfortable admitting is that buying decisions aren’t nearly as predictable as we’d like them to be. 

A deal might come from a webinar somebody attended six months ago. It might come from seeing you at RSA. It might come from a salesperson calling at the right moment. It might come from a piece of research somebody used in a presentation that helped them get promoted. 

All of those things contribute. The CRM will usually credit one touchpoint and ignore the rest, which is where so many unhealthy arguments start. 

What we’ve been slow to acknowledge in B2B is that buyers are human beings making emotional decisions. If a buyer has three vendors with similar products, they’re often going to choose the one they remember. The one they connected with, that made them feel something.

”At the end of the day, they’re human, and we’re human. And what if we just show a little empathy and sell to a human versus sell to a business?”

We’re starting to see cybersecurity companies take more risks: more humor, personality, and creativity. 

For years cybersecurity marketing relied heavily on fear, uncertainty, and doom. Lots of dark colors, binary code, locks, shields, and warnings about what could go wrong. Now we’re seeing companies show more personality, which is a good thing. 

The consumer world figured this out a long time ago. People remember experiences, stories, and brands. Cybersecurity buyers are no different.

Attribution feels like one of the most contested topics in marketing. What’s your read on the marketing versus sales tension it creates?

The tension is real because attribution often gives people something to fight about. One example always sticks with me. At a company I worked for, the lead source field in Salesforce was editable by anyone with access. 

Think about that for a second. You run campaigns, track performance, and review results six months later. Then you discover that what was originally attributed to an event is now attributed to outbound sales activity because someone changed the field. 

It sounds ridiculous, but it happens. That’s why I think people sometimes become too obsessed with figuring out exactly who gets credit. 

We absolutely need data, and a general understanding of what’s working. But spending time arguing over revenue ownership creates conflict where none is needed. Marketing and sales are supposed to be on the same team. 

The more interesting challenge is understanding how buyers make decisions. A lot of research happens outside your channels, in Slack groups, private communities, and text messages. It happens in conversations you’ll never see. 

People are talking to peers long before they talk to vendors, which is another reason brand matters so much. When somebody asks for recommendations in a community, you want your company to already be in their head.

How are you using AI in your day-to-day, and where do you think it earns its place?

Operationally, it’s been useful. I manage a lot of events, and every event comes with endless emails from organizers. Booth deadlines, artwork specifications, electrical orders, exhibitor manuals, attendee information, logistics, and schedules. 

It used to take hours to sort through all of it, but now I can put everything into Claude and ask it to organize the information into something useful. Within minutes, I have an event brief for the sales team that tells them exactly what they need to know. That kind of time saving is significant. 

For content, I think the best use case is extending something that already exists. We’ll record a webinar, create a transcript, and build a blog from it. We’ll take a human-written piece and create social content from it. The source material already contains expertise and perspective. The technology is helping us reuse it more efficiently. 

The part I worry about is what I jokingly call the infinite loop. If you’re creating AI content to feed AI, isn’t that a crazy infinite loop? It’s a risk, because if everyone is creating machine-generated content for machine-generated search results, eventually you end up with lots of content and very little original thinking. 

The people who do well over the next few years will still be the people with something real to say. 

One thing I feel strongly about is that messaging architecture should come from humans. Talk to customers and product teams to understand the problem. Build your positioning from real conversations and real research. Once you have that foundation, then use AI to help execute faster, but the blueprint has to come from people. 

What’s the uncomfortable truth about cybersecurity marketing that most people won’t say out loud?

Too many cybersecurity marketers are afraid to get technical. I say that with a lot of love because cybersecurity marketers are my people and I’ll defend them all day long. 

I also know that many of the decisions people criticize are driven by organizational realities. Budget constraints, leadership priorities, internal politics, and approval processes. 

Many marketers already know what they should be doing differently, but the technical knowledge gap is something we can control. 

You don’t need a computer science degree or to become an engineer. You do need to understand the product you’re marketing.

”Don’t be the marketer that doesn’t know anything about the product, but you’re the marketer for the product.”

That’s advice I strongly believe in. You should be able to explain what the product does and be able to answer a few follow-up questions. You should be able to have a conversation before bringing in a sales engineer or product specialist. 

Most engineers are far more approachable than marketers assume. Many of them enjoy explaining what they’ve built to someone who genuinely wants to learn. 

Talk to them. Sit in on product marketing meetings and read the technical material. Ask questions and build relationships with product managers and engineers. 

Product marketers are especially valuable because they sit between technical teams and marketing teams every day. They know how to translate. 

Over time, you build enough knowledge to speak confidently about the product, and that confidence changes everything. It changes your content, your event conversations, your credibility with internal teams, and your ability to tell a stronger story. 

The marketers who stand out are usually the ones who made the effort to learn.

Maria Velasquez is co-founder of the Cybersecurity Marketing Society and Director of Growth Marketing at Brinqa. She runs the annual CyberMarketingCon conference. Find her on LinkedIn. 


ABOUT BORA

We’re Bora. We work with security companies to turn complex technical capabilities into clear, credible market narratives.

Get in touch for a free 30 minute consultation. If we’re not the right fit, we’ll help find someone who is.

RELATED