Google Ads · Keywords

Which keywords should a security company bid on?

Security searches mix buyers with students, job seekers, researchers and people who want to break into something. The keyword list decides which of them you pay for. This page sorts security terms by intent and gives a starting negative list.

By the ShoutEx Team · Updated October 2026 · Facts checked October 7, 2026
A security keyword list is half bids and half exclusions. The exclusions are what make the bids affordable.Marketing for Cybersecurity Companies · Updated October 2026
3 match types
Broad (the default), phrase and exact
1 week
Data behind each Keyword Planner forecast, averaged to a daily figure
30 days
Period Keyword Planner uses for its bid ranges

Which keywords should a security company bid on?

Which keywords should a security company bid on?

Bid on four kinds of terms: problems a buyer needs solved, services or product categories you sell, compliance requirements with deadlines, and alternatives to named competitors. Exclude jobs, training and certification courses, free tools you do not offer, student searches and anything about hacking someone else's systems.

Each type attracts a different buyer stage. Service and compliance terms tend to bring people ready to talk; problem terms bring earlier researchers who may need a guide or a checklist first. Plan the landing page and offer to suit the stage, not just the keyword.

How do you sort security keywords by intent?

Put every candidate keyword in one column of the board below before you build ad groups. Anything that will not sit cleanly in a buyer column goes in the negative column or is dropped.

Example · keyword board by intent

Service and category

Buyers naming what they want. Usually the highest intent.

penetration testing servicesweb application pen testmanaged detection and responsesoc as a serviceMDRemail security for microsoft 365

Compliance with a deadline

Driven by an audit, a customer review or a contract.

soc 2 readiness consultantiso 27001 consultant canadacmmc level 2 helpUS defencevirtual ciso servicespen test for soc 2

Problem and alternative

Earlier stage or switching. Needs proof and comparison pages.

phishing simulation platformcloud misconfiguration alerts[competitor] alternativeswitchingot asset inventory tool

Negatives to add on day one

Searches that look close but are not buyers.

jobssalarycoursecertificationfreehow to hackstudentinternshippdf
How to use it: the three buyer columns become ad groups, each with its own landing page. The negative column goes into a shared list applied to every campaign. All terms are examples; your own list comes from your services and your search terms report.

The organic version of this work, with page types for each column, is on SEO for cybersecurity companies. For the general method across industries, see Google Ads keyword research.

Which match types should a security account use?

Google offers three keyword match types: broad, which is the default; phrase, written in quotes; and exact, written in square brackets. Google recommends pairing broad match with Smart Bidding, which lets the system find related searches.

Match typeHow you write itWhen it suits a security account
Exact[managed detection and response]Launch phase and expensive terms where you need control
Phrase"penetration testing"Core services with predictable wording around them
Broadsoc 2 readinessAfter offline conversions reach opportunity stage and negatives are in place

Match type also changes what the search terms report shows you. Exact match gives a clean list that is easy to read but small; phrase match shows the wording buyers put around your core term, which is often where new ad groups and negatives come from.

ShoutEx view: broad match in a young security account tends to wander into training, careers and hobbyist hacking content. It can work well later, once Google is learning from qualified opportunities rather than raw form fills.

Which negative keywords does a security account need?

Google allows negative keywords in broad, phrase or exact form, and they are not expanded to close variants. Start with a shared list and grow it from real search terms.

Starter negative keyword listShared across campaigns; review monthly
ThemeExample negativesWhy exclude
Careersjobs, salary, hiring, internship, resumeJob seekers, not buyers
Trainingcourse, certification, bootcamp, exam, study guideLearners looking for education
Hobby and offencehow to hack, crack, bypass, exploit downloadNot buyers, and close to policy trouble
Free and DIYfree, open source, template, pdfUnless you offer a free tool on purpose
Academicstudent, thesis, university project, definitionResearch, not purchase
Wrong markethome, personal, gaming, phoneConsumer intent for business services
Illustrative starter list written by ShoutEx for this guide. Add plurals and misspellings yourself.

Be careful with negatives that remove real buyers. "Free" blocks people looking for a free assessment, which some MDR and compliance firms offer on purpose. "Training" blocks awareness training buyers if you sell to them.

ShoutEx rule

Start narrow, then widen on evidence.

Launch with exact and phrase match on the clearest buyer terms. Add broad match only when conversion tracking reaches the qualified opportunity stage and the negative list is mature.

What if Keyword Planner shows almost no searches?

Expect it. Many security terms are rare, and Google's Keyword Planner forecasts are less reliable for new accounts and small geographies. Forecasts are based on one week of data averaged to a daily figure, and the bid ranges use the last 30 days.

  • Group related terms into one ad group so they reach enough volume to learn from together.
  • Widen the geography to all of Canada, or Canada and the US, before you widen the wording.
  • Run a short test on phrase match to see real queries; the search terms report beats any forecast.
  • Do not chase volume with generic words like "cyber security" that mostly attract learners and news readers.

For how a forecast becomes a budget, read Google Ads cost for security keywords.

How should penetration testing firms choose keywords?

Use the words a buyer uses when they need a test for a system they own: penetration test, pen test, security assessment, plus the asset (web app, external network, cloud, API) or the reason (SOC 2, customer requirement). Avoid bidding on offensive phrasing such as "hack a website" or "hacking service".

Those phrases attract the wrong people and sit close to the kind of offer Google's policies do not allow, as explained in the Google Ads overview for security companies. More on positioning a testing firm is in marketing a penetration testing firm.

What should you track for each keyword?

Judge keywords on what happens after the click, not on clicks alone.

Keyword reviewMonthly
MeasureWhat it tells you
Share of search terms that are real buyersWhether match types and negatives are tight enough
Qualified leads per ad groupWhich intent column is producing buyers
Opportunities per ad group (from CRM)Which keywords deserve more budget
New negatives addedWhether you are still cleaning up waste
Keywords with no impressionsTerms too rare to keep separate
Source: ShoutEx view, from running B2B search campaigns.

Frequently asked questions

What keywords should a cybersecurity company target in Google Ads?

Service and category terms, compliance terms tied to deadlines, problem terms and competitor alternatives. Exclude jobs, courses, free tools you do not offer and anything about hacking other people's systems.

Should we use broad match for security keywords?

Usually not at launch. Start with exact and phrase match, then test broad match with Smart Bidding once offline conversions and negatives are in place.

Why does Keyword Planner show zero volume for our terms?

Many security terms are rare, and forecasts are less reliable for new accounts and small geographies. Group related terms and test with a small budget to see real queries.

Do negative keywords cover plurals and misspellings?

No. Google says negative keywords won't match to close variants or other expansions, so add those versions yourself.

Should we bid on competitor names?

Competitor alternative searches can work if you have a real comparison page. Do not use a competitor's trademark in ad text without checking Google's trademark policy and your counsel.

Should pen-test firms bid on the word hacking?

Avoid it. Offensive phrasing attracts the wrong searchers and reads like the hacking services Google does not allow. Use penetration test, security assessment and the asset type instead.

How often should we update the negative list?

Weekly in the first two months, then monthly, using the search terms report.

Is "cyber security" a good keyword?

On its own it is too broad. It mostly attracts learners, job seekers and news readers. Add the service, framework or asset a buyer would use.

Sources & further reading

Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.