Top Cybersecurity Marketing Agencies

Primary vs Secondary Research Services at Cybersecurity Agencies

Primary research generates defensible findings.

Columnist · · 9 min read
Cover illustration for “Primary vs Secondary Research Services at Cybersecurity Agencies”
cybersecurity research agencies · August 27, 2026 · 9 min read · 1,984 words

Primary research and secondary research at cybersecurity agencies produce two different animals, and treating them as interchangeable is how marketing budgets go to die. One makes original data nobody else has their hands on, while the other takes data that already exists and turns it into something a busy practitioner can actually use. Mixing up which one you're buying leads to trouble either way: you overpay for a report that says nothing new, or you underpay for something that needed six months of fieldwork it never got.

What primary research actually produces and what it costs to produce it

Primary research means somebody went out and made the data exist, through commissioned surveys, sensor telemetry, red team engagements, pen test observations, lab experiments, and interviews with practitioners who actually touch the systems in question. Think of the difference between reporting on a fire and setting one, minus the arson charges.

Studios like Cyberou, a cybersecurity-specialist content shop that runs on live threat intelligence, exist partly because that bar is higher than most generalist agencies can clear.

The bar here got set by the big vendor surveys, and it's a real bar, not a marketing one. CompTIA's 2025 State of Cybersecurity report surveyed 1,026 US-based professionals online, with a stated margin of sampling error of ±3.1 percentage points at 95% confidence, and Ivanti's 2025 report ran 1,215 professionals. Those numbers aren't there for decoration. They're the receipts a practitioner checks before believing a single line of your findings.

Why does this cost so much? Because nobody gets to skip steps, and skipping steps is usually where the money would've been saved. Research published on arXiv found that analyzing one incident from a single publicly available article takes an analyst several hours on average, and that's just one incident. A real study needs dozens, sometimes hundreds, and each one takes that same slow crawl through the evidence, so you end up needing a research panel, a proprietary sensor network, or practitioner access the agency already has sitting in-house, because there's no shortcut to a sample size that holds up.

The payoff is the part that makes the cost worth it: nobody can copy a dataset you own. A competitor can summarise a vendor's findings in their own newsletter by Thursday, but rerunning the survey and landing on the same numbers is a different task entirely. That is the core trade-off.

What secondary research actually produces and where it earns its place

Secondary research takes what's already public and does something with it that wasn't obvious before. Threat landscape summaries, vulnerability roundups, actor profiles stitched together from disclosures that are already out in the wild, commentary that gives someone else's findings context they didn't have on their own. This work is reading, connecting, and framing, which appears straightforward until it is done rigorously.

Speed is the whole advantage, and it's not a small one. A primary study takes months to field, while secondary research can go out the same week a vulnerability drops, and in a threat landscape that moves week to week, that timing is often the entire value of the piece.

OSINT-driven threat reports live in an odd middle ground, and they're more labor-intensive than most people assume from the outside. The real workflow runs through triage (deciding which disclosures actually matter, out of the fifty that showed up in your feed that morning), deep search (finding the supplementary evidence that turns a headline into an actual finding), and TI drafting (mapping the thing to indicators of compromise and ATT&CK techniques). That workflow depends on judgment, exercised over and over, article by article, and it's easy to underpay for because it looks like reading.

Secondary research that merely repeats what practitioners have already read is worthless. If a reader can reach the same conclusion by skimming the three cited sources, the vendor has added a logo, not a finding. Secondary research only earns its keep when the synthesis is the original part, and the underlying facts are just the raw material.

Why the threat landscape right now generates demand for both research types simultaneously

Ransomware attacks jumped 60% in H1 2025 compared to the prior period, according to CyberProof's mid-year threat landscape report. Secondary research tracks a number like that well, because it's a live signal, not something you'd wait for a quarterly survey to confirm. Yet that number also raises a question secondary research can't answer on its own: why now, and what's actually different about how these attacks run?

AI-augmented attacks are the clearest argument for primary work happening right now, full stop. Deepfake-assisted KYC bypass, GPT-generated phishing templates, pig butchering scams running on scripts instead of human labor sitting in a call center somewhere. These are new enough that summarizing a competitor's press release about them doesn't hold up for a technical reader, so somebody has to actually go look.

Meanwhile, the IBM 2025 Cost of a Data Breach Report put the global average breach cost in the multimillion-dollar range, down from the prior year's figure as security AI sped up detection. That single figure got cited across the industry constantly, in nearly every secondary report about breach costs published after it came out, and whoever produces a number like that owns the citation cycle for the next year. That is the primary research payoff.

So there's a structural tension baked into all of this. Secondary research keeps a vendor in the conversation as the landscape shifts week to week; primary research creates the fixed points that all that secondary reporting eventually cites back to. Vendors that run only secondary research are always one citation behind their own sources. Vendors that run only primary research produce something genuinely impressive twice a year, then go quiet for the ten months in between.

Venn diagram: Primary vs Secondary Research in Cybersecurity. Compares Primary Research and Secondary Research; overlap: Shared Requirements.

How practitioners evaluate the credibility of vendor-produced research

Practitioners read like auditors, not customers, and that distinction matters more than most content teams plan for. Sample size, confidence interval, fielding period, conflict-of-interest disclosure: all of it gets checked before anyone believes a single conclusion. CompTIA and Ivanti set the visible bar for what "showing your work" actually looks like, Leaving those details out of a vendor's report signals to readers that the omission was deliberate.

Trust beats price, and it's not close. 82% of buyers prioritize trust over price when picking security partners, according to Martal, and a 2024 TrustRadius report found 88% of B2B buyers prefer vendors who educate without pushing product on them mid-sentence. Taken together, the message is clear: research that reads like a sales pitch is discarded before anyone reaches the findings.

Fear-based pitches have run out of road. Practitioners have read enough "everything is on fire" headlines to build an immune response to them, so credibility now comes from being straightforward about complexity instead of dialing it up for effect. A report that says "this is bad, here's exactly how bad and why" earns more trust than one shouting that the sky is falling with no specifics attached.

One more thing readers check, and it gets skipped constantly: who actually did the work. A named researcher with a track record carries weight that "our research team" never will, and attribution is accountability. Practitioners distinguish between a named researcher and an anonymous 'research team' credit.

Where primary research fits in a security vendor's content programme

Primary research earns its budget when a vendor needs an anchor asset, something built to support a whole campaign, pull in media coverage, generate inbound links, and give every follow-up piece something to point back to for the next year. This is infrastructure, the kind you build once and lean on repeatedly.

Real money is already moving this direction. The services segment of the threat intelligence market holds a 40.2% revenue share and is projected to grow faster than any other segment in the sector, according to Mordor Intelligence.

Primary research also makes sense when a vendor's product holds proprietary telemetry nobody else can access: endpoint data, DNS query patterns, honeypot logs. Publishing that data converts a product feature into public intellectual property, a trade worth making whenever the opportunity exists.

Timing is the piece marketing leaders keep getting wrong. A primary study takes weeks or months start to finish, so it belongs on a calendar, planned months out, not commissioned the Monday after a headline breaks. When primary research lands well, it becomes an anchor asset with a shelf life measured in years, not a campaign that expires when the next news cycle arrives.

Where secondary research fits and how to keep it from becoming noise

Secondary research is the right tool for staying visible: responding to fresh disclosures, covering active campaigns as they unfold, giving someone else's findings context specific to a vendor's own customer base. It is the consistent cadence that keeps a vendor visible to practitioners between major primary research releases.

The line between useful and recycled is drawn at triage, and that is where most teams demonstrate their value or fail to. Somebody has to decide which findings actually deserve commentary, and what that commentary adds beyond restating the source article in nicer formatting. Skip that judgement call and the result is a content mill, not a research programme.

Security content works when it helps before it sells, and that ordering matters more than it sounds like it should. Secondary research that walks through what a new disclosure actually means for a security team on a Tuesday morning is doing real work for the reader. By contrast, secondary research that quotes a press release and calls it analysis leaves the reader no better off, no matter how clean the formatting looks.

There's good raw material floating around for this kind of work. US FBI data recorded 859,532 cybercrime complaints in 2024, with $16.6 billion in reported losses, a figure 33% higher than 2023. That's a legitimate anchor for commentary, provided the commentary does something with the number instead of just repeating it and calling the piece done. What separates a specialist research studio from a content mill is not the research type, it is whether a practitioner with domain knowledge evaluated the findings, asked whether they mattered, and explained why.

What marketing leaders should ask before commissioning either type

The first question is whether the vendor holds proprietary data or practitioner access unavailable to others. If so, the brief is for primary research.

The second question concerns intent and should be answered before the brief is written: is the goal to own a conversation or simply to remain present in one? Owning the conversation requires a primary anchor asset; staying present requires a steady secondary cadence. Confusing the two results in overpaying for the wrong format.

Then there's the audience test, the simplest one to ask and the most uncomfortable one to answer honestly: what does the reader gain from this piece that they could not obtain from the cited sources? If the honest answer lands somewhere around "not much, just convenience," the brief needs a rewrite before it needs a research type assigned to it.

It's also worth checking whether the studio or agency doing the work actually has practitioner-level fluency in the subject, or whether they're producing something research-shaped without the background to know if their own conclusions hold up under a second look. Practitioners identify the gap immediately, typically within the first paragraph, while generalist marketing reviewers do not. That discrepancy is precisely how weak research gets approved internally, published, and then ignored by the audience it was meant to reach.

Last question, and it's the one that actually decides everything else: is this research built to serve the audience's understanding of the threat landscape, or to serve the vendor's own positioning? Research built around the first goal tends to land the second one anyway, almost as a side effect, while research built backward from positioning rarely earns the trust it sought.

Sources

  1. cyberproof.com
  2. arxiv.org

More in cybersecurity research agencies