Skip to main content
demandaxisDemandaxis

ICP and positioning

An ICP built from pain and urgency, not firmographics alone

Company size, sector and job title tell you who could buy. They do not tell you who is likely to buy now, or why. We define the ideal customer profile from the problem outwards, then test it in the market.

Six questions for every campaign

Before any outreach starts, each campaign has a written answer to these six questions.

  1. Which company has the painful condition?

    Not every company in a sector has the problem. We look for the conditions that create it: the tooling, the shape of the team, the regulation it works under or the way it is growing.

  2. Which person feels the consequence?

    The person who deals with the problem day to day. Often an analyst, an engineer or a team lead rather than the budget holder.

  3. Which person can move or influence budget?

    The person who can approve spend, or argue for it. Their concerns are usually risk, cost and timing rather than features.

  4. What event makes the problem urgent now?

    A problem that has existed for years rarely creates a buying decision on its own. Something usually changes first.

  5. What alternatives are already being considered?

    Incumbent tools, add-ons to a platform the buyer already owns, an internal build, or doing nothing. The message has to account for each of them.

  6. What proof would make action feel safer than waiting?

    Security buyers carry the risk of a poor decision. Each role needs different evidence: references, technical validation, a contained pilot or clear commercial terms.

Where the evidence comes from

If you have sales history

We review closed-won and closed-lost opportunities. Why deals were won, where they stalled, who was involved, and which triggers were present. Your best customers are compared with the rest to find what actually separates them.

If you are early stage

History is limited, so we work from founder knowledge, early customer and design-partner conversations, product use cases and structured market tests. The first ICP is treated as a hypothesis and tested through outreach before anything is scaled.

How the work runs

  1. Gather the evidence

    Closed-won and closed-lost opportunities where history exists. Founder knowledge, early conversations, use cases and market tests where it does not.

  2. Find the painful condition

    Identify the companies where the problem is present and costly.

  3. Map the people

    The person who feels the consequence and the person who can move budget.

  4. Name the trigger

    The event that turns a known problem into a reason to act.

  5. Define the ICP

    Written down, specific enough to exclude companies, and agreed with your team.

  6. Align with positioning

    Make sure the outbound message matches how you present the company elsewhere.

  7. Test through focused outreach

    Put the message in front of a defined set of accounts and personas.

  8. Feed the learning back

    Use what the market says to refine positioning, product priorities and the next campaign.

Cybersecurity trigger events

Triggers are used to decide who to contact and when. They are signals, not proof of intent, so each one is checked against the ICP before an account is included.

  • New CISO or security leader

    New leaders review tools, suppliers and team structure in their first months, and often have a mandate to change things.

  • Funding round

    New capital brings growth targets, hiring and closer investor attention to security maturity.

  • Merger or acquisition

    Bringing two organisations together exposes gaps in identity, tooling, data handling and policy.

  • New compliance requirement

    Regulation, standards and audits create deadlines and a need for evidence. Examples include DORA and NIS2 for organisations operating in the EU.

  • Public incident or breach

    An incident at the company, a peer or a supplier changes how the board views risk, at least for a period.

  • Cloud, AI or transformation programme

    Large programmes create new exposure and new budget lines, and security is often asked to catch up.

  • Customer or supplier security requirement

    A major customer asking for evidence, a questionnaire or a certification can make a long-deferred project urgent.

  • Expansion into a regulated market

    Selling into financial services, healthcare or the public sector brings new obligations and closer scrutiny.

  • Security hiring

    Job adverts show where a team is investing, which tools it uses and where it is short of people.

  • Vendor consolidation or platform review

    When a buyer reviews its tool estate, contracts come up for discussion and new options get a hearing.

A note on product-market fit

For early-stage companies, this work produces evidence: which segments respond, which problems buyers recognise, which roles engage and which objections repeat.

That evidence can support decisions about positioning, product priorities and product-market fit. It does not settle those questions on its own, and we do not promise to find product-market fit for you.

Start with a pipeline review

A 45-minute call about your ICP, your current outbound and how opportunities are qualified. You should leave with a clearer view of where to focus, whether or not we work together.