Cybersecurity investors evaluate a different risk profile than the rest of your board package acknowledges. We create the reporting, fundraising narrative, and incident plan before you need any of them.
Board Decks Track SaaS Metrics, Not Security Metrics
Most board packages for cybersecurity companies still lead with ARR, burn, and headcount, the same template every SaaS company uses. But cybersecurity investors are underwriting a different risk profile: logo retention after a customer's security review, net revenue retention in a market where procurement now requires a pen test before renewal, and how fast the team detects and patches a vulnerability a researcher disclosed. When those numbers aren't in the deck, the board asks about them anyway, and the founder is answering cold in the room.
Technical Differentiation Gets Lost in Translation at the Board Table
A founder can walk an engineer through the detection architecture in ten minutes and get a nod. Put the same explanation in front of a board member or a growth-stage investor and it lands as noise. The gap between what makes the product defensible and what makes the company investable is where most cybersecurity founders lose the room, not because the technology is weak, but because nobody translated it into a narrative an investor can repeat to their own partners.
Without a Pre-Incident Plan, the First Statement Is Drafted Under Pressure
Every cybersecurity company eventually has an incident, a disclosed CVE, or a customer asking hard questions after a competitor's breach makes headlines. Companies without a stakeholder communications plan write their first response in the middle of the event, unreviewed and reactive. That first statement becomes the story instead of the fix, and it shows up in the next board meeting as a trust problem, not a technical one.
The Fundraising Story Stalls at 'We Stop Bad Guys'
Series B and Series C cybersecurity rounds get underwritten against a category story, not a product demo: TAM, competitive moat against platform players, and a defensible reason the company wins the next three years, not just the last twelve months. Founders who can build the product but not the category narrative watch rounds slow down in diligence, answering the same positioning questions they assumed the pitch had already covered.
We begin by reviewing what's already being shared: board decks, investor updates, previous incident postmortems, and the current approach to reporting metrics. Most often, the numbers already exist within the company, across support tickets, churn reasons, and detection times, but no one has organized them into a stakeholder-facing format. We assess the gap between what the company understands internally and what it actually communicates to investors and board members.
We interview the founder and the people responsible for security and GTM metrics to uncover the true differentiation, the thing a competitor couldn't replicate in six months, and distinguish it from feature-level claims investors have already heard a dozen times this year in other cybersecurity pitches.
Then we develop the narrative architecture. That includes a board reporting framework combining standard SaaS metrics with the security-specific signals investors actually examine: NRR by security tier, logo retention across renewal cycles, detection and response times, and audit and compliance milestones. Separately, we create the fundraising narrative: the category story, competitive positioning against point solutions and platform incumbents, and the metrics required for that story to withstand diligence.
We also create what most cybersecurity companies overlook until it's too late: a stakeholder communications plan for an incident or disclosure. This includes pre-drafted holding statements, an internal escalation and approval chain so nothing is released without the right review, and a rehearsed sequence defining who speaks with customers, who speaks with the board, and who, if anyone, speaks with the press, before an incident occurs rather than during one.
During the engagement window, we join or ghostwrite the actual investor updates and board materials, ensuring the new format is tested in a real board meeting or fundraising conversation instead of being delivered as a template that eventually slips back into old habits.
We measure whether the new reporting improves the conversation: fewer unexpected questions during board meetings, investor updates that are read and answered rather than skimmed, and a fundraising narrative that holds up through partner-level diligence instead of getting stuck on the same three questions each round.
A board member asking about logo retention after a breach headline isn't posing a routine question; they're losing confidence in real time.
Winston Francois handles stakeholder communications as a 90-day sprint, rather than a retainer that delivers one deck per quarter. The initial 30 days focus on assessment and framework development: reviewing current board materials, identifying security-specific metrics available internally but not yet reported, and drafting the incident communications plan before anything is tested live.
The following 30 days apply the framework to a real cycle, whether that's the next board meeting, investor update, or stage of an active raise, with us in the room or working on the draft and refining it based on what actually resonates rather than what we expected would.
The last 30 days transfer a system the internal team can operate without us: a reporting template, update cadence, and disclosure plan that has been rehearsed, not merely documented. Most cybersecurity companies at this stage don't need us forever. They need the capability established once, properly, against a real deadline.
Day 1-30: we review existing board decks, investor updates, and any previous incident response, while interviewing the founder and whoever internally owns security and GTM metrics. The output is a reporting framework and the initial draft of an incident communications plan.
Day 31-60: we test the framework in a live board meeting or investor update cycle, drafting or reviewing the materials that are actually distributed, then refining them based on the questions received from board members or investors.
Day 61-90: we transfer the system, templates, cadence, and rehearsed disclosure plan to the person responsible for investor relations internally, typically the CEO or VP Marketing at this stage, with a brief training session so it can operate without us.
The engagement includes one senior Winston Francois lead embedded weekly, rather than a rotating account team. Most engagements last the complete 90 days before shifting to quarterly check-ins around fundraising milestones or significant board meetings; some clients retain us for a single high-stakes raise and no longer.
If your cybersecurity company needs investor & stakeholder communications leadership, we should talk.
Let us take a custom approach to your growth goals by assembling and leading the best-in-class marketing team to support your next stage.
Engagements are structured around the 90-day sprint and priced as a fixed project instead of an hourly retainer, giving the company visibility into the full cost before the board deadline or raise begins. Pricing varies based on how much metrics infrastructure is already in place versus what must be built, and whether the incident communications plan needs to be created from scratch. Request a scoped quote during the strategy call rather than a rate card. Supporting a Series A company reporting to three board members costs less than supporting a Series B company conducting an active raise with a dozen investor stakeholders.
The first real test is generally the next board meeting or investor update within the 90-day period, rather than months afterward. Founders usually see the change within one or two reporting cycles: fewer unexpected questions and more specific follow-ups rather than generic ones. The incident communications plan works differently. Its value becomes clear on the day it's actually required, which is precisely why it's created before that day comes.
We collaborate with whoever manages investor relations internally, most commonly the CEO or VP Marketing at this stage, because most Series A/B cybersecurity companies don't yet employ a dedicated IR function. We create the framework, run it through a live cycle alongside that person, and then transfer it so they can manage it without us. We don't replace an internal hire when the company is ready to make one.
A PR agency is designed to secure press coverage. An IR agency generally serves public companies with quarterly earnings requirements. Neither is designed for a private, venture-backed cybersecurity company that must translate security-specific metrics into a board and investor narrative. Our background is on the operator side, not the agency side, and we create reporting and disclosure infrastructure the company retains, rather than monthly retainer deliverables that end as soon as we depart.
We don't track vanity metrics such as impressions or press hits. ROI appears through fewer unresolved questions in board meetings, investor updates that receive replies rather than silence, and, for actively fundraising companies, whether the fundraising narrative withstands partner-level diligence instead of hitting the same objections each round. For incident readiness, the test is whether the real response, should it ever be required, follows the rehearsed plan rather than being improvised.
The strongest fit is a Series A through growth-stage cybersecurity company, approximately $5M to $100M ARR, with genuine board and investor responsibilities but no dedicated IR or communications function yet; typically, the CEO or VP Marketing handles it alongside everything else. Companies currently raising or preparing to raise gain the most immediate value, though any company whose board is beginning to ask tougher security-specific questions is also a fit.
Tuesday, June 16, 2026
Frank Growth – Episode 224 – The Bootstrapper’s Revenge with Alex Roy
Tuesday, July 21, 2026
Frank Growth – Episode 229 – Longevity Medicine’s Dirty Secret with Jim Donnelly
Tuesday, September 1, 2026
Frank Growth – Episode 235 – The Marketing Engineer with Nick Lafferty
Tuesday, August 25, 2026
Frank Growth – Episode 234 – Nobody Has The Playbook Yet with Dave Steer
Ready to unlock your growth?
Book Free Call