Lack of trust – why cyber security communications needs clearer standards

In a market built on trust, cyber security vendors face a difficult communications challenge. Buyers often need to rely on marketing claims to assess highly technical products, making accuracy and transparency in communications materials particularly important.  

Claims around protection, resilience and risk reduction need to be clear, evidence-based and proportionate, especially when they are being interpreted by audiences with varying levels of technical knowledge. 

Recent events make the stakes concrete. From the attacks on M&S, Co-op and Jaguar Land Rover in 2025, costing those businesses hundreds of millions of pounds, the question for any organisation is not whether a cyber-attack could happen, but when, and whether their people, processes and suppliers are prepared for it. 

That context is important for how cyber security is communicated. New research conducted among UK cyber security marketing, PR and communications professionals shows that miscommunication is already a significant concern within the sector. Of 152 senior professionals surveyed, 99% said they had encountered or used language such as “100% protection” or “fully protected” in their marketing materials. More than half (51%) have seen marketing claims they believe to be unsubstantiated or misleading, and 30% have been directly involved in their use. 

The findings should not be read as evidence of deliberate or widespread misconduct. They point to a more nuanced challenge. Communications professionals are operating in a competitive and highly technical market, where pressure to simplify complex capabilities can increase the risk of overstatement or misunderstanding. 

Many professionals recognise this risk, with 89% acknowledging such claims can give the impression of total protection from cyber threats – a level of certainty that no solution can realistically offer.  

The research also points to a confidence gap between how organisations view their own communications and how they perceive the wider market. Most respondents (86%) said they have full confidence in their own organisation’s marketing and PR content, even while many expressed concern about the use of exaggerated or potentially misleading claims more broadly. This suggests many organisations recognise a problem in the industry while believing they themselves could be exempt from it. 

Competition and complexity add pressure in communications

The challenge is partly linked to the intensity of competition in a global cyber security market. In the UK alone, the government estimates there to be 2,600 firms in the sector, all of which must compete to some extent for visibility with rivals overseas.  

It is also linked to the difficulty of explaining complicated cyber security technology to audiences with different levels of technical knowledge. The research found this was the most frequently cited major challenge among cyber marketing professionals (38%) – much higher than the 23% who cited avoidance of miscommunication and exaggerated claims. 

The board member who holds the purse strings is likely to have a vastly different level of technical understanding of risk from the CISO, if the organisation has one. Cyber security marketing has to therefore present the evidence accurately and ensure claims are consistent across all channels. 

When claims become too broad, too absolute or insufficiently supported, they can increase the risk of misunderstanding, and in cyber security, that risk can have commercial and reputational consequences for both buyers and vendors. These are very real dangers, not theories. Nearly half of the survey respondents (47%) say their organisation has suffered commercial or reputational damage from inaccurate or over-simplified messaging.  

In an attempt to reduce the risks, some professionals surveyed said they have their marketing content checked over by their legal advisers and technical teams before publication. Yet the research suggests these checks are not always applied consistently or with the buyer’s interpretation in mind. That can leave room for messages to be interpreted more broadly than intended, particularly by audiences without specialist technical knowledge. Many more businesses include disclaimers, plain English explanations or risk guidance. Even so, 30% of respondents admit their marketing messages are still misunderstood. 

The case for clearer communications standards 

There is strong appetite for change, as 94% of respondents say the industry needs clearer communication standards or a code of practice to reduce miscommunication. A further 86% believe communications practitioners in the sector should hold a cyber-related accreditation. And 97% agree that PR has an important role in reducing the risks associated with miscommunication, which places particular responsibility on agencies and in-house comms teams to challenge unsupported claims, not just amplify them. 

A cyber-specific voluntary code of practice could help organisations describe products and services more consistently, while giving buyers greater confidence in the claims they are assessing. It would not replace existing professional or ethical standards, but cyber security has specific communications challenges because the subject matter is technical, risk-based and linked to serious operational consequences – as the attacks of the past year have shown. 

Such a code could reduce the use of absolute claims like “total security” or “100% protection”, encourage stronger evidence for marketing messages, support more careful use of testimonials and ensure products and partnerships are presented accurately. Perhaps most importantly, it could help shift communications away from implying complete protection and towards language that reflects what solutions can realistically deliver: risk reduction, greater resilience and faster recovery when – not if – an incident happens. 

Cyber security ultimately depends on trust. Buyers need confidence not only in the technology they purchase, but also in the claims used to sell it. Implementing clearer communications standards would help ensure that confidence is earned through evidence, transparency and realistic expectations rather than marketing hyperbole. 

Join our LinkedIn group Information Security Community!

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *