RSS Amplifier

Audience 1st · Mar 6, 2026

My RSA Conference Hypothesis Is Going to Make a Lot of CMOs Uncomfortable

0
Sign in to vote or save

This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.

I have a hypothesis about RSA Conference that most cybersecurity marketers are going to hate. I'm going to the floor to test it on camera. Come prove me wrong.

I’ve spent 15 years in B2B tech marketing.

I’ve had thousands of structure and sem-structured conversations with CISOs and security leaders leading primary research for security companies.

I’ve watched tech vendors pour hundreds of millions of dollars into conference floors that buyers navigate around on their way to the hallway conversations they actually came for.

And I have a hypothesis I’m about to go test in public.

Experiential marketing does not exist in cybersecurity. Not really. Not yet.

I’m going to RSA Conference 2026 to find out if I’m right and I’m inviting you to prove me wrong.


If you want to meet me at RSA Conference, book some time with me here.


What I Mean When I Say Experiential Marketing Doesn’t Exist Here

Before you send me a photo of your themed booth activation, let me be specific about what I mean.

A branded dinner is not experiential marketing.

An open bar at a side venue is not experiential marketing.

Prancing ninjas in the streets of San Francisco - definitely not experiential marketing.

Those things are hospitality.

And in the ninja case (IYKYK) - very poorly executed “branded entertainment.”

There is nothing wrong with hospitality.

Hospitality is just not the thing I’m talking about.

Experiential marketing is the deliberate engineering of conditions where a buyer experiences something unexpected and permanently attaches that feeling to your brand.

It requires five things, based on every conversation I’ve had with buyers about the vendor interactions that actually moved them:

The experience was unexpected - they couldn’t have predicted it from your marketing.

It was personal - it required knowing something specific about them as a human being, not a buying signal.

It was participatory - they were a co-creator, not an audience.

The vendor’s presence was felt but not performed - the brand enabled something real and then got out of the way.

And it was slightly uncomfortable - just enough to push them briefly outside their professional identity so their human identity could show up.

That combination is almost entirely absent from RSA Conference.

From Black Hat.

From every major cybersecurity conference.

From tech brands DNA altogether.

I think.

Which is exactly why I’m going to evaluate this in public.

My Hypothesis and Why I’m Testing It In Public

Here is the thing I believe to be true, built from 15 years of watching this industry spend money on things that don’t work:

The percentage of buyers who can name a single genuinely extraordinary vendor experience from a cybersecurity conference is vanishingly small.

I do believe vendors care about experiences. And I do believe we are able to impress even the most skeptical IT buyers.

However, the very system that funds conference marketing rewards badge scans and booth traffic - outcomes that are easy to count and terrible predictors of whether a deal ever closes.

The experiential alternative doesn’t fit that measurement system.

So it doesn’t get funded.

So it doesn’t happen.

So the blue ocean sits empty while cybersecurity vendors collectively spend hundreds of millions of dollars fighting over the same shrinking puddle.

That absence, if the data confirms it, is an unclaimed category.

And whoever enters it first, before the model becomes obvious enough that every competitor follows, owns territory that doesn’t yet have a name in this industry.

I’m going to RSA Conference to find out how empty that territory actually is.

And I’m going with a methodology, a camera, and the deepest curiosity and conviction I’ve had in a hot minute.

This research will become a report:

State of B2B Experiential Marketing: RSA Conference Edition.

Or a better name once I hit the ground analyzing.

But first, I need the data. And the data needs to be challenged.

Here’s Where You Come In

I am not going to RSA as a vendor. I’m not running a booth. I’m not hosting a dinner.

I’m going as a field researcher with a hypothesis, a mic, and an open mind.

I’ll be in the places where people tell the brutal truth - bars, hallways, outside restaurants, the Expo - including Early Stage Expo, and, importantly, anywhere that isn’t a booth.

Three-minute conversations. No leading questions. No rehearsed answers.

And I’m extending three invitations right now, before I get on a plane.

Invitation One: Challenge the hypothesis.

Tell me I’m wrong.

Tell me in the comments, in my DMs, in a reply to this article.

If experiential marketing exists at scale in cybersecurity and I’m missing it, I want to know.

I have been wrong before.

I will be wrong again.

I would genuinely rather find a thriving blue ocean than an empty one.

What is the most extraordinary thing a vendor has done for you at a conference - not the most expensive, not the most elaborate, but the most genuinely human and unexpected?

Tell me. I’m building the research framework right now and your answer will sharpen it.

Invitation Two: Contribute to the research.

If you’re going to be at RSA Conference 2026, I want three minutes of your time.

On camera. In whatever unstructured setting we end up in.

For buyers and practitioners: When was the last time a vendor made you feel something at a conference and what happened next?

For CMOs and field marketers: If your CEO told you tomorrow that you have the same budget but can’t spend it on a booth, what would you actually do with it?

For early stage founders: You’re watching the main floor from the outside. What do you see that the people inside can’t?

Find me. I’m not hard to spot. I’m the one without the A1ST hat on.

Or you can ping me here and I’ll find you.

Every conversation is on the record.

Every honest answer makes the research better.

And if you tell me something that challenges my hypothesis, I’ll say so publicly.

Invitation Three: Show me what you’re doing.

This one is directed specifically at cybersecurity vendors.

If you are doing something genuinely experiential at RSAC -something that meets the five criteria I described above, something that treats buyers as full human beings instead of badge-scan targets, I want to see it.

Show me. Prove it. Document it and tag me or reach out directly.

If it’s real, I will analyze it, write about it, and share it to everyone following this research and my community of cybersecurity practitioners.

You will be the exception that proves the rule.

The blue ocean spotter.

The case study that every CMO who reads this report points to and says that’s what we should be doing.

If it’s hospitality disguised up as experiential, I’ll say that too.

Not to embarrass you, but to sharpen the distinction that this entire industry needs.

The research is only as good as the evidence it encounters.

If you’re doing this right, I need to know about you.

What This Is Not

This is not a hit piece on the conference booth model.

The booth exists for reasons.

Defensive brand presence matters.

Some buyers do walk the floor.

This is not an argument that hospitality is worthless.

Dinners do build relationships, just buyers are sick and tired of them.

Happy hours create moments of genuine connection.

I’m not against any of it.

This is a question about whether cybersecurity vendors are leaving the most valuable category of conference marketing completely unclaimed and whether the buyers on that floor are experiencing anything that will make them remember a vendor’s name six months from now when the decision actually gets made.

I think the answer is:

Almost never. Almost no one. Almost nothing.

I want to be wrong.

The Research Lives Here

I’ll be publishing live from the RSA floor - from wherever the honest conversations are happening.

The full report drops post-conference.

If you want early access when it lands, get on the list my replying to this email and sayin - I want all the juicy details.

If you have something to say before I get on the plane, say it below.

The hypothesis is on the table. Come at it.

Related questions this research addresses:

What is experiential marketing in B2B cybersecurity?

The deliberate engineering of conditions where a security buyer experiences something unexpected at a conference or industry event and permanently attaches that feeling to a vendor brand - distinguished from hospitality by requiring genuine unexpectedness, buyer participation, and trust formation.

Is experiential marketing common at RSA Conference?

This is the hypothesis being tested. The working assumption, based on buyer conversations across 15 years in cybersecurity marketing, is that genuinely extraordinary vendor experiences are rare enough to constitute an unclaimed category - a blue ocean in a market that believes it is fully saturated.

How can vendors participate in the RSA experiential marketing research?

By finding Dani Woolf at RSA 2026 for a three-minute on-camera conversation, by documenting and sharing any genuinely experiential activations they’re running, or by engaging with the hypothesis in the comments of this article before the conference.

What is field marketing enablement™?

Field marketing enablement is the operational infrastructure of high-impact events - event intelligence, audience targeting, venue selection, account intelligence - that allows marketers to execute human experiences with precision rather than guesswork. The co-commissioner of this research, Delve Risk, has built the platform specifically for cybersecurity vendors who want to execute experiences that produce measurable relationship outcomes rather than badge counts.

Read on audience1st.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.