How do you turn threat research into marketing without losing credibility?
Original research is the strongest proof a security company can publish, and the easiest to spoil with a marketing tone. This page covers when research is worth publishing, the disclosure steps that come first, how to map findings so defenders can act, and how to get a year of content from one report.
How do you turn threat research into marketing without losing credibility?
Publish findings defenders can act on, disclose responsibly before you publicize, map what you found to a framework practitioners already use, let the researchers speak in their own voice, and keep sales offers next to the research rather than inside it.
The credibility comes from the method and the usefulness. Hype in the headline or a fear-heavy launch can undo both in a day.
Tone matters as much as content. The guidance in messaging without fear applies doubly to research launches: describe what happened, how often you saw it and what helps, without inflating the threat.
When is threat research worth publishing?
When it meets at least one of these tests. If it meets none, it is a blog post, which is fine, but do not launch it as a report.
- New: a technique, campaign or tool behaviour that others have not documented.
- Local: activity aimed at Canadian sectors, languages or infrastructure that global reports gloss over.
- Usable: detection queries, indicators with context, hardening steps or test cases.
- Measured: your own telemetry or engagement data with a clear method, scope and date range.
- Explained: a careful synthesis that saves defenders hours, with sources linked.
A services firm has research too. A pen test team can publish anonymized patterns from engagements, such as recurring misconfigurations, with every client detail removed and permission sought where contracts require it.
What disclosure steps come before publishing?
If the research involves a vulnerability in someone else's product, coordinate first. CISA's coordinated vulnerability disclosure program describes the stages as collection, analysis, mitigation coordination, application of mitigations and disclosure, and says CISA may disclose as early as 45 days after first trying to contact a vendor that does not respond. Reports can go through VINCE, run by Carnegie Mellon's Software Engineering Institute.
- Report privately to the affected vendor's security contact.
- Agree a timeline and what will be published, including proof-of-concept detail.
- Escalate to a coordinator such as CISA if the vendor does not respond.
- Publish after mitigation is available, with credit and a clear changelog.
- Only then plan the marketing around it.
Practise what you ask of others: publish your own security.txt, as described in RFC 9116, so researchers who find issues in your product can reach you. A research team that has no reporting contact of its own invites awkward questions on launch day.
How should you map findings so defenders can use them?
Map each behaviour to the matching tactic and technique in MITRE ATT&CK, then pair it with a detection idea and the log source it needs. Defenders can drop that straight into their own coverage reviews, which is why mapped research gets shared inside security teams.
| What you observed | ATT&CK tactic | Detection idea | Log source |
|---|---|---|---|
| Malicious OAuth app granted mail access | Persistence | Alert on new high-privilege app consents | Identity provider audit log |
| Remote access tool installed after phishing | Command and Control | Flag unapproved remote management tools | Endpoint process events |
| Backups deleted before encryption | Impact | Alert on bulk backup or snapshot deletion | Backup and cloud audit logs |
The table is a format example written for this guide, not findings from a real investigation.
The researcher approves the headline.
Marketing can shape the title, the summary and the distribution, but the person whose name is on the work signs off on every claim. That one habit prevents most credibility damage.
Should a threat research report be gated or ungated?
Publish the findings ungated and gate the extras. Defenders share open research and ignore a form; marketing still captures interest with an optional briefing, a data appendix or a subscription for the next report.
Field notes from incidents our responders worked this year, with detection queries mapped to MITRE ATT&CK.
- How attackers got in, by technique
- Detection queries with tuning notes
- What changed since our 2025 notes
The full data appendix and a 30-minute briefing for your security team.
- Raw technique counts by quarter
- Sigma-style rules as files
- Briefing with a Northwall Labs researcher
How do you get more reach from one research report?
Plan distribution before launch. One solid report can feed a quarter of content if each piece is cut for a different audience and channel.
| Week | Asset | Audience | Channel |
|---|---|---|---|
| 0 | Report page and researcher post | Defenders | Website, researcher's LinkedIn |
| 1 | Detection queries as a repository | Detection engineers | Code host, community channels |
| 2 to 4 | Document Ad of the key findings | Security leads at target accounts | |
| 3 | Briefings for customers and prospects | Account teams | Sales outreach |
| 4 to 8 | Talk submission and slides | Practitioners | Conferences, chapter meetings |
| 6 to 12 | Technique explainer pages | Searchers | Website, SEO |
The paid step is covered in LinkedIn Ads for security companies, conference talks in security events, and the explainer pages in SEO for cybersecurity companies. Measure shares by practitioners, briefing requests, replies to sales follow-ups that reference the report and opportunities where the report was a touch.
Frequently asked questions
Do we need our own telemetry to publish threat research?
No. Incident response notes, pen test patterns, honeypots, careful analysis of public data or a well-sourced synthesis can all be useful. Be clear about the method and its limits.
Should a research report be gated?
Usually not the findings. Defenders share open research and avoid forms. Gate optional extras such as a data appendix or a team briefing instead.
How long should we wait before publishing a vulnerability?
Until the affected vendor has had time to fix it under a coordinated disclosure timeline you agreed. CISA may disclose about 45 days after first contact if a vendor does not respond.
Can marketing edit researchers' work?
Marketing can improve structure, clarity and the summary. The researcher should approve every factual claim and the headline before it goes out.
Can we name the victim organizations in our research?
Only with written permission. Without it, describe the sector, size and region in terms that cannot identify the organization.
Why map findings to MITRE ATT&CK?
Defenders already use ATT&CK to describe coverage. Mapped findings fit straight into their reviews, which makes your research easier to use and to share.
How often should a security company publish research?
As often as you have something new and useful. Two strong reports a year with steady smaller notes beats a monthly report padded to hit a date.
Is it acceptable to market research during a major breach in the news?
Be careful. Share useful detection or mitigation guidance if you have it, and leave out sales offers and dramatic language while the victim is still responding.
Sources & further reading
Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.