General Cybersecurity

The Tool They Said No To Would Have Stopped It

Three months after a company turned down a DNS security tool, I was standing in their office reconstructing a DNS poisoning attack.

I wasn’t there for the pitch. I was there for the forensics.

The tool didn’t get rejected because it was a bad tool. It got rejected because the pitch was written in engineering language, for a CIO and a CFO who needed a business case. Feature specs and protection capabilities instead of a decision they could act on.

Three months later, they got hit. Forensic investigation activated. Incident response plan triggered. I got brought in to trace what happened — and the attack that hit was one the rejected tool would very likely have caught or prevented.

This wasn’t bad luck. It was tier confusion.

Threat intelligence isn’t one thing. It’s four different products for four different audiences.

Strategic — for the board and C-suite. Multi-year decisions. Long shelf life.
Operational — for security leadership. Months. Campaign-level detail.
Tactical — for analysts and threat hunters. Days to weeks. TTPs.
Technical — for tools and detection engineers. Hours. IOCs.

The DNS tool got pitched at the technical tier — features, specs, protection mechanisms — to a strategic audience that needed something else entirely: what decision does this help you make, and what happens if you don’t make it.

That mismatch isn’t rare. It’s the most common reason security conversations fail with executives who would otherwise say yes.

What the mismatch actually cost

Here’s the math. Three months of no added DNS protection between the rejected pitch and the attack. Then the forensic investigation. Then incident response activation. Fortunately, other controls held, so the damage stayed contained to the cost of the investigation — but that cost, plus the lost time, plus the same tool eventually getting purchased anyway under worse conditions, is the real price of the original tier mismatch.

For context, one industry survey found that organizations globally face multiple DNS attacks a year, averaging seven per company, at a cost of around $942,000 per attack. Even a contained incident sits inside that range once you count the investigation and the response.

What a strategic-tier pitch actually looks like

A pitch to a CIO and CFO doesn’t lead with features. It leads with the decision and the risk.

Name the specific threat the tool addresses for that organization — not DNS threats in general, theirs. Name the cost of not acting. Then name the cost of the tool, so leadership can weigh it against the exposure. The technical detail still matters, but it sits underneath as backup, not as the headline.

It’s the same instinct that makes teams chase low-value indicators instead of high-value techniques. Wrong altitude, wasted effort, every time.

Know the tier before you pitch

The tool wasn’t rejected because it was wrong. It was rejected because nobody translated it into a decision a CIO and CFO could act on. Three months later, that gap got tested for real.

Before you pitch anything to leadership, know which tier they need — and build the case at that altitude, not the tier you’re most comfortable talking in.

→ Free download: the Intelligence Tier Mapping Worksheet — use it before your next pitch. https://jrobertsonsecurity.gumroad.com/l/tier-mapping-worksheet

← What 125,336 People Had to Say About Breaking Into CybersecurityPriority Intelligence Requirements: The PIRs Your CTI Program Is Missing →
← Back to Blog

Want to Go Deeper?

Browse online courses that cover these topics with the depth and clarity you need to apply them.