Back to docs
Use Cases

AI Customer Research for Cybersecurity Companies: Interview CISOs and Practitioners at Scale

How security vendors run buyer and practitioner research with AI-moderated interviews that respect confidentiality, survive the alert queue, and reach the whole buying committee.

Short answer: Cybersecurity companies can run rigorous buyer and practitioner research with AI-moderated interviews that fit how security people actually work: asynchronously, with confidentiality designed in, and in fifteen minutes instead of a booked hour. Rather than another vendor survey that a CISO deletes unopened, a platform like Koji runs real one-on-one conversations by voice or text, asks adaptive follow-up questions, and analyzes hundreds of responses automatically. That is how you find out why a shortlisted deal went quiet, which detections your analysts actually trust, and what a competitor promised that you did not.

Security is one of the hardest categories in B2B to research, and the reasons are structural rather than a matter of trying harder. This guide explains them, then shows the studies that work.

Why Cybersecurity Research Is Uniquely Hard

ISC2's 2024 Cybersecurity Workforce Study estimated the global cybersecurity workforce at 5,468,173 people and the workforce gap at 4,763,963. That ratio is the most important fact about researching this market: the practitioners you need to talk to are understaffed and interrupt-driven, and their attention is the scarcest resource in the category.

  1. Participants are scarce, senior, and interrupt-driven. A SOC analyst's day belongs to the alert queue, and a CISO's belongs to the board, the auditors, and whatever is currently burning. Any method that requires a scheduled synchronous hour systematically loses the busiest and most senior people, who are precisely the ones whose opinion decides the deal. The result is a sample skewed toward the under-employed and the junior. See how to research hard-to-reach audiences.
  2. Confidentiality is the default posture, not a preference. Security professionals are trained not to disclose their stack, their coverage gaps, or their incident history. Ask which endpoint tool someone runs and a careful respondent will decline on principle, because naming a control is itself an information leak. Research designs that ignore this get bland, defensive answers and mistake them for genuine indifference.
  3. The buying committee is large, technical, and internally divided. A security purchase pulls in the practitioner who will operate the tool, an architect who owns the reference design, procurement, legal and privacy reviewers, and an internal champion who has to defend the budget. These people frequently disagree, and a single-respondent study will confidently tell you the wrong thing. Key informant interviews explains why one person cannot speak for a whole company.

How AI-Moderated Interviews Fix It

  • Asynchronous and short. Participants open a Koji interview from a link, in a browser, whenever the queue goes quiet. There is no calendar negotiation, no video, and no moderator waiting. A fifteen-minute async conversation is a far easier ask of a security lead than a booked half hour.
  • Confidentiality designed into the instrument. You can run studies that collect no personally identifying information at all, and you can ask about categories of control rather than named products. See anonymizing customer interview data for the practical patterns, and AI interview data privacy and security for how the platform itself handles the record.
  • Depth without a moderator. The AI asks adaptive follow-up questions rather than accepting the first answer. When a respondent says the tuning was painful, Koji's interviewer probes it: walk me through the last rule you had to tune, and what you did when it kept firing. That is the difference between a complaint and a product requirement.
  • Structured and qualitative in a single pass. Koji supports six structured question types, so one study can both quantify and explain. The types are open_ended, which captures a free-form qualitative answer with AI follow-up probing; scale, for a numeric rating such as a one-to-five confidence score; single_choice, to pick one option; multiple_choice, to pick one or more; ranking, to order items by preference; and yes_no for a binary. Full detail is in the structured questions guide.
  • Interview modes that match the question. A study can run structured, which follows the key questions closely and suits validation work; exploratory, which is open-ended discovery that follows interesting threads; or hybrid, which starts structured and opens up when something interesting appears. Compliance and packaging research wants structured; alert-fatigue discovery wants exploratory.
  • Automatic analysis you can read the next morning. Koji codes themes across every transcript and assembles a report as responses land, rather than after fieldwork closes. See real-time research insights.
  • A quality gate on spend. Only conversations scoring 3 or higher consume a credit, so low-effort responses do not burn budget. A text interview costs 1 credit and a voice interview costs 3.

High-Value Cybersecurity Research Playbooks

1. Stalled-Deal and Win/Loss Debriefs

Security deals rarely die with a clear no; they go quiet after the technical evaluation. Interview the practitioner and the champion separately about what changed between the proof of concept and the silence. Use a ranking question to order the blockers and open-ended probes to capture the internal politics a scorecard never records.

2. Alert Fatigue and Trust in Detections

Ask analysts what they do when your product fires. The honest answer is often that they suppress a rule or ignore a class of alert entirely, which is a retention problem disguised as a tuning problem. A scale question measures confidence in your detections; follow-ups reveal which false positive broke that trust and when.

3. Compliance-Driven Buying Versus Real Risk Reduction

Many security purchases are driven by an audit finding, a customer questionnaire, or a cyber-insurance requirement rather than by a threat model. Knowing which of those is the real trigger changes your messaging and your pricing. Yes_no and single_choice questions separate the trigger from the stated rationale.

4. Practitioner Onboarding and Time to First Value

Deployment is where security tools quietly fail: agents are not rolled out, integrations stay half-configured, and the tool becomes shelfware before renewal. Interview recent deployers about the first two weeks, then map the drop-off. Pair with feature validation before you build the fix.

5. Channel, MSSP, and Partner Research

If you sell through managed providers, your real user is an operator running dozens of tenants, whose needs differ sharply from a single enterprise. Run a separate study for that audience; multi-tenancy, reporting, and per-client isolation will dominate.

6. Pricing and Packaging Without Seats

Security products are often priced per endpoint, per gigabyte ingested, or per protected asset, and buyers find those meters hard to forecast. Interview buyers about how they budget and what unpredictability costs them politically. Ranking questions across candidate meters surface which one feels fairest.

Why Not Just Use a Survey?

A survey cannot ask the next question, and in security the next question is the whole study. When a respondent says the integration was fine, a survey records satisfaction; an interviewer asks which integration, what broke, and what they did instead. Surveys also invite the most defensive possible answer, because a flat form with a vendor logo reads as a data-collection exercise rather than a conversation. And a survey has no way to tell a thoughtful fifteen-minute respondent from someone clicking through, whereas Koji's quality scoring makes that visible and only charges for conversations that clear the bar. For the broader comparison, see AI interviews versus surveys.

Getting Started

  1. Pick one decision that is currently being made on anecdote: a stalled-deal pattern, an alert-fatigue suspicion, or a packaging change.
  2. Write a short brief naming the decision, then let the AI consultant draft the guide and add follow-up probing.
  3. Decide what you will not ask. Drop any question that requires naming a specific control, and ask about the category instead.
  4. Send the link through the channel your audience already trusts, usually a named account manager, a community, or a post-deployment email rather than a cold blast.
  5. Run voice and text together and read the report as interviews land.

A Worked Example: Why a Shortlisted Deal Went Quiet

A cloud security vendor keeps reaching the final two and then losing to no decision. Sales believes it is price. The team runs an async study across twenty recent evaluations, interviewing both the security engineer who ran the proof of concept and the manager who sponsored it, with a ranking question over candidate blockers and open-ended follow-ups whenever a respondent mentions internal process.

The report contradicts the pricing theory. Engineers ranked the product highly and the blocker was almost always the same: the deployment required a change to an identity integration owned by a different team, and nobody wanted to open that ticket. The verbatim quotes are specific about which team and which approval. That is not a discount problem, it is a sequencing problem, and the fix is a deployment path that does not touch identity on day one. Sixteen interviews produced a change no pricing experiment would have found.

A Note on Confidentiality and Scope

Design the study so that a careful participant can answer everything honestly without disclosing anything they should not. Ask about control categories rather than vendor names, about classes of incident rather than specific ones, and make it explicit up front that the interview is product research and not a security questionnaire, an audit, or a sales qualification call. Never ask for credentials, configuration detail, or architecture diagrams; no legitimate research needs them. If a participant volunteers something sensitive, the honest handling is to exclude it from the analysis rather than quote it. Studies that visibly respect these boundaries get markedly more candid answers, because the participant stops managing risk and starts explaining their work.

Frequently asked questions

How do you recruit CISOs and security practitioners for research?

Go through channels that already carry trust rather than cold outreach. In practice that means named account managers, post-deployment emails, user communities, and partner networks. Keep the ask short and asynchronous, state the time cost honestly, and say what you will not ask about. A fifteen-minute async interview with no scheduling and no video converts far better with senior security people than a calendar invitation for a call.

Will security professionals disclose their stack in an interview?

Often not, and you should not design a study that depends on it. Naming a deployed control is an information leak, so careful respondents decline on principle. Ask about categories of control, the job the tool does, and what happens when it fails, rather than product names. You will get the behavioural detail you actually need without asking anyone to breach their own disclosure rules.

How long should a cybersecurity research interview be?

Aim for ten to fifteen minutes of actual conversation. Security practitioners are interrupt-driven, and an asynchronous format lets them answer between alerts rather than blocking a half hour. Shorter interviews also reduce the senior-participant drop-off that biases these samples toward junior and less busy respondents. If you need more ground covered, run two short studies rather than one long one.

Is voice or text better for interviewing security practitioners?

Text usually wins for this audience. It is quieter, it works in an open office or a SOC, it leaves a reviewable record, and it costs 1 credit against 3 for voice. Voice is better when you want tone and frustration, which matters for alert-fatigue work. Offering both and letting the participant choose is generally the highest-completion option; see the voice versus text comparison for the trade-offs.

How many interviews do you need for a security buyer study?

For a focused question about one segment, patterns usually stabilise between twelve and twenty interviews. The bigger risk in security research is not sample size but role coverage: twenty analysts will not tell you why procurement stalled. Budget interviews across each role on the buying committee, because a single-role sample is the most common way these studies go confidently wrong.

Can AI interviews handle NDA or confidential material?

The safer approach is to design the study so confidential material never enters it. Scope questions to categories rather than specifics, collect no personally identifying information where the research question does not require it, and tell participants plainly that this is product research rather than an audit. Review how the platform stores and processes transcripts before fieldwork, and exclude anything a participant volunteers that falls outside the agreed scope.

Related Resources

Related Articles

AI Interview Data Privacy & Security: A Buyer's Evaluation Guide

How to evaluate the privacy and security of an AI customer research platform — the questions to ask about data handling, PII, retention, sub-processors, and compliance — plus how Koji approaches each one.

AI Interviews vs. Surveys: Complete Comparison with Data

Traditional surveys give you data. AI-powered interviews give you understanding. Compare response quality, completion rates, insight depth, and cost-effectiveness between survey tools and AI interview platforms like Koji.

Anonymizing Customer Interview Data: A Practical Guide for Privacy-Safe Research

Five operational techniques for handling PII in AI customer interviews — from intake-time anonymization to stakeholder-safe quote sharing — without sacrificing research signal.

Enterprise Security for AI Customer Research Platforms: SOC 2, SSO, and Vendor Review

A procurement-ready guide to evaluating the security of an AI customer research platform — SOC 2, encryption, SSO/SAML, data residency, sub-processors, and the questions your security team should ask.

How to Research Hard-to-Reach Audiences: Executives, B2B Buyers, and Niche Segments

The people hardest to recruit for research are often the ones whose insights matter most. Learn how async AI interviews unlock executives, B2B buyers, and niche specialists who will never take a 60-minute call.

Key Informant Interviews: Why One Person Cannot Speak for a Whole Company (2026)

A key informant's report correlates only .612 with an independent source - and just .502 on internal process questions. What the measurement literature says about interviewing one person about a whole organization.

How to Recruit B2B Participants for User Research

B2B participant recruiting is harder than consumer research — but more valuable. Learn the strategies, channels, and tactics that actually work.

Structured Questions in AI Interviews

Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.