In this blog, Hayley Goff, CEO at Whiteoaks, discusses:
- Why cyber security vendors must balance visibility with accurate claims
- How over-simplified messaging can damage trust and reputation
- Why clearer communications standards could help buyers make better decisions
Cyber security vendors operate in a market where credibility directly influences buyer confidence. Because marketing claims often help buyers assess highly technical products and services, those claims need to be accurate, transparent and proportionate.
That’s not always easy to achieve. Cyber security is complex, risk-based and often communicated to audiences with different levels of technical understanding. As such, the challenge for many vendors is to explain what their solutions can realistically deliver without over-simplifying the message or creating expectations that no product or service can guarantee.
This is particularly important when cyber security is being discussed in the context of real business risk. Recent attacks on major organisations, including M&S and Jaguar Land Rover in 2025, have shown the significant commercial and operational impact cyber incidents can have.
As a result, businesses need clear information to help them understand the threats they face and make informed decisions about the people, processes and suppliers that can help reduce risk and strengthen resilience. Communication plays an important role in that decision-making process.
To better understand where the risk of miscommunication can arise and how it can be reduced, Whiteoaks conducted research among 152 UK cyber security marketing, PR and communications professionals. Here’s what we found.
Complexity in cyber communications
One of the clearest examples of the sector’s communication challenge is the language used to describe cyber protection. Almost all respondents in our survey (99%) stated that they had used terms such as ‘total security’, ‘100 percent protection’ or ‘fully protected’ in their marketing materials. In addition, seven-in-ten (70%) cyber comms professionals said they had either been involved in, or aware of, marketing or PR content that they believed included unsubstantiated, misleading or excessive claims.
These findings shouldn’t be read as evidence of deliberate or widespread use of false information. They point to a more nuanced challenge. In a competitive cyber security market, PR and comms professionals are under pressure to stand out and simplify deeply complex topics, which can inadvertently increase the risk of overstatement or misunderstanding.
That risk grows when messages need to work for audiences with different levels of technical knowledge. A board-level decision-maker may not interpret a claim about protection or risk reduction in the same way as a CISO. And because claims rarely sit in one place, moving across websites, sales decks, social media, thought leadership and media commentary, the risk of miscommunication may increase as they travel, particularly if the core message isn’t backed by clear evidence.
The cost of miscommunication
In cyber security, miscommunication can create consequences long before a product is put to the test.
If a buyer takes an absolute claim at face value, they may misunderstand the level of protection, resilience or recovery support a solution can provide. That can shape procurement decisions, internal expectations and how risk is communicated across the business.
For vendors, the same issue can affect credibility if expectations are not met or a claim is challenged. Almost half of our survey respondents (47%) said their organisation has suffered commercial or reputational damage as a result of inaccurate or over-simplified messaging.
Why the industry could benefit from clearer comms standards
So how can the industry address the miscommunication challenge?
Many organisations already involve legal advisers and technical teams before content is published, but our research suggests these checks aren’t applied consistently: only 23% of respondents say all claims are checked by legal teams before publication. Three-quarters routinely add disclaimers or plain-English explanations, yet misunderstanding still persists, with 30% saying messaging is often misread. Checks and disclaimers can of course help, but they aren’t enough on their own.
That’s why our research points to an appetite for something more structural. More than eight-in-ten (86%) believe cyber communications practitioners should hold a cyber-related accreditation or certification, and 97% agree PR has an important role to play in reducing miscommunication risk. Almost all respondents (94%) say the industry needs clearer standards altogether – 70% point to clearer communications standards and 55% to a formal code of practice.
A voluntary code of practice tailored to the industry could offer a practical blueprint: a consistent way to describe products and services, backed by evidence rather than assertion, that gives buyers confidence without replacing any existing professional or ethical standards.
Done well, it could help reduce reliance on absolute claims like “100% protection”, encourage more considered use of testimonials, and, most importantly, help buyers understand exactly what value a solution can deliver.
Building and maintaining trust
Trust is at the core of success in the cyber security sector. Buyers need confidence in both the technology they procure and the claims made alongside it.
Clearer communication standards won’t remove the complexity of the market, but they can help move the industry beyond marketing murkiness towards messages that are backed by evidence and set realistic expectations from the outset.
Download the report, The state of cyber security communications, to find out more, or get in touch if you need support identifying and reducing miscommunication risks in your marketing materials.