Get a Demo
Under Attack?
Buyers Demos

Why Buyers Remember Solving a Demo, Not Watching One

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Tomer Hadassi August 12, 2026

Key Takeaways

  • Security demos fail on format, not product. A passive walkthrough loses buyers fast, because watching is the one job people are worst at holding.
  • A demo that floods the room is the same mistake as a SOC that floods the analyst. Too much visibility, not enough action.
  • Buyers retain what they figure out. Active, hands-on learning beats passive viewing, confirmed across 225 studies in a 2014 PNAS meta-analysis.
  • Investigation-style demos build trust and convert. Letting a buyer solve an attack gives them proof they found, not a claim they have to take on faith.

I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive into videos, setup guides, any research he could get his hands on, I began to conceptually understand. But he went on to explain that to really understand hydroponics, you have to get your hands dirty. His trail of deceased plants can attest to this. 

This had me thinking about the way the security industry treats demos. Defensive security isn’t always intuitive, yet we treat the teaching of it as if buyers don’t need to get their hands dirty. 

A security demo works best when the buyer investigates an attack instead of watching one. Buyers remember what they solve for themselves, which is why hands-on, investigation-style demos hold attention and earn trust where passive walkthroughs lose both.

I’ve sat through a lot of security demos. Leading a company in this space and spending a few years working with hundreds of security teams will do that to you. And the pattern is almost always the same. We keep trying to make the demo better by making it slicker. Tighter story, better pacing, a more dramatic attack, one more thing that lights up red on the screen. Yet, the buyer still drifts.

I’ve learned over time that the fix isn’t more polish, it’s to meet people where they’re at. 

That sounds like more work for them, but it’s actually the opposite. I’ll elaborate on this because the data here is interesting and I think it’ll change how you run your next demo.

Nobody tunes out because the product is weak

Watch most security demos and you see the same thing every time. The first attack lands and people are with you, but by the third attack, eyes go to phones or minds start to drift. This isn’t because a product is weak. It’s because the buyer’s only job in the room is to sit and be impressed, and that’s a job nobody is good at for very long. 

It’s also a job buyers are openly trying to quit. Gartner surveyed 646 B2B buyers in 2025 and found that 67 percent would rather buy with no sales rep involved at all, and 70 percent want a fully digital, self-service path. That’s not a knock on salespeople, it’s a clear signal about how people want to engage. They want to get their own hands on the thing and play around. By Gartner’s own count, buyers spend only around 17 percent of the entire buying journey actually meeting with any vendor, and most of them would shrink that number if they could. Not to mention, buyers have more access to information now. All they have to do is go ask their neighborhood chatbot what it thinks about any given sector of vendors and they can have a full breakdown in seconds. By the time a real practitioner talks to a salesperson, they have done a solid portion of their research. 

So when you sit a buyer down and ask them to watch a demo, you’re working against the exact instinct they walked in with. Attacks are all hands on deck in real life, but spectacle is passive by design. Or think of it like this: a demo with a wall of features and flows  is a fireworks show. Nice to look at, forgettable by the time people reach their cars in the parking lot.

The interactive demo industry has measured this for years, and the gap is large. Demand Metric’s content research found interactive formats convert roughly twice as well as passive ones. Arcade’s own benchmark puts interactive demos at about seven times the click-through of a plain walkthrough video. These are industry and vendor numbers, so hold the exact figures loosely. The direction is the part that holds, and it lines up with what Gartner documents about buyers, who increasingly want to vet a product themselves before a rep is ever in the room. Simply put, there’s a difference between watching someone cook and cooking yourself.

There’s a trust layer underneath this, and it should worry every vendor. Gartner found that 69 percent of B2B buyers run into inconsistencies between what a company says on its website and what its sellers say out loud. Read that again. Most buyers have already caught vendors contradicting themselves, so most of them have stopped taking the pitch at face value. When you tell a skeptical buyer your product stops an attack, you’re spending trust you may not have. When you let them watch it stop the attack and then allow them to prove to themselves how, you are not asking for trust at all. You’re handing them the evidence to build their own trust with your product.

You can have the best risk narrative in the category and still lose the room, because the room was never the problem. The problem was in the role you handed them from the beginning. Let them cook.

The demo and the alert queue fail the same way

This part may sting a little because it’s the same mistake the industry has spent years making inside the product itself.

A loud demo and a noisy alert queue are the same miss. Both bury a person in events and ask them to be impressed instead of helping them understand. The buyer who checks out at attack three is the same human, in the same posture, as the analyst who checks out at alert three hundred.

This is the thing a lot of security tools got backwards. They were built with too much of a security mindset and not enough of an operations mindset, so they shipped a deluge of dashboards and findings and called it visibility. Too much visibility, not enough action. The actual job runs the other way. It’s cutting three thousand findings down to the handful that matter and telling someone exactly what to do about them. A demo is that same job, just performed live.

And we have the numbers on what all that noise does at scale. Vectra AI’s 2026 research puts the average organization at nearly 3,000 security alerts a day, with about 63 percent of them never getting touched.

The 2025 SANS Detection and Response Survey found 73 percent of security teams now rank false positives as their single biggest detection problem, up sharply from the year before. Microsoft and Omdia’s 2026 State of the SOC report put it plainly: roughly 46 percent of all alerts turn out to be false positives, so nearly half of an analyst’s day produces no security value at all. Pull the surveys together and roughly 40 to 60 percent go uninvestigated, for the dumbest possible reason, which is that there are simply too many of them to look at.

Sit with that for a second. If a flood of events loses trained defenders inside a real SOC, where the stakes could not be higher, what makes anyone think a flood of events will hold a buyer’s attention in a calm room where the stakes are zero?

A demo that drowns people and calls it value has the same flaw as a product that drowns people and calls it visibility. Volume is not understanding, it never was. The passive demo is just the smaller, friendlier version of the problem we’re all supposed to be solving. Which is why how you run a demo quietly tells the room how you actually think about defense.

So flip it and hand them the keys.

Flip the whole thing. Why not?

Don’t narrate the attack for them, let them work it as it surfaces. Then hand over the keys. Here is what’s running, something got in. Want to see if you can spot how?

Now the buyer isn’t just watching. They’re working the problem out. They follow a thread, hit a wall, find the open port, trace what moved where and when. There are a few questions guiding them under the hood. Which port did they come in through? What was the authentication on the API they hit? What moved laterally after that? But it never feels like a quiz, because nobody is standing over them with a red pen. It feels like the good kind of puzzle, the one you don’t want to put down.

The security world already knows this format inside out. It’s a capture-the-flag challenge, or CTF, and these have been a staple of how the industry trains people for years, because they work. A SANS Internet Storm Center writeup followed a team whose lectures and workshops kept failing to land, with people tuning out and retention sliding. They switched to capture the flag style challenges and watched recall and real on-the-job application climb. A participant who had done both said the hands-on version was far more memorable than the classroom one. Academic studies of CTF in the classroom find the same thing: higher engagement, better retention, learners describing the work as more interactive and more motivating than the passive version sitting right next to it.

This isn’t a thought experiment. It’s already how Evan’s team runs a demo. He described it to me like this:

“At Upwind, we run what we call a threat workshop. Instead of walking through a scripted attack narrative, we simulate an attack in an environment that mirrors the customer’s own infrastructure. Things surface in the console in real time. And instead of narrating every finding, we ask the practitioner what they’re seeing and where they’d go next. Here, it’s simply about treating the people in the room like the professionals they are, and letting them interact with what’s actually happening instead of watching a presentation about it.” – Evan Grace, Solutions Architect @ Upwind.

What makes an investigation land, and what ruins it

This only works if you build it right, so a few honest guardrails from watching it go both ways.

The puzzle has to be winnable. Interesting, but a softball. The payoff is the click of figuring it out, not the satisfaction of stumping someone. A challenge that is too clever just rebuilds the frustration you were trying to escape, but with extra steps.

Friction is what we want to avoid. If the buyer spends the session fighting copy-paste, clunky navigation, or a setup that keeps breaking, you have recreated passivity and made it feel even worse. The environment has to be clean enough that the only effort in the room is the thinking. Effort spent on the puzzle is engagement. Effort spent fighting the tool is churn.

Give them a clear question and a reachable finish line. “Which port did they use to get in” is answerable. “Tell me everything you notice” is a shrug. Concrete questions with hints in your back pocket keep momentum alive, and hints are a feature, not a failure. You are a guide on the trail, not a proctor.

And match the depth to the person. Some buyers want rails and a clear path. Some want to roam and break things. The format flexes to both, which is the whole advantage it has over a script that runs the same way no matter who is sitting there.

Isn’t that just making the buyer work?

This is where someone usually pushes back. Are you not just making the buyer do the work?

No. You’re giving them the two things they actually came for.

First, the win. People remember what they figure out far better than what they are shown, and this is one of the most settled findings in learning science. A 2014 meta-analysis in the Proceedings of the National Academy of Sciences pooled 225 studies and found that students in plain lecture formats were about one and a half times more likely to fail than students who learned by doing. Active learning lifted exam scores by roughly half a letter grade, across every discipline and class size they checked.

The brain holds onto the thing it had to reach for. That small click of “oh, that’s how it got in” sticks in a way a slide never will. A week later your buyer won’t recall your third attack. They’ll recall the moment they cracked it. They might even retell it to their boss, and that’s when you know you’ve really hit it out of the park. 

Second, the truth. They walk out knowing whether this thing would actually help them, hands on it, instead of taking a stranger’s word for it. The whole reason they’re there is to try before they buy, after all. They’re not there to be entertained. They’re there to de-risk a bet they’ll have to defend to their own leadership. Remember, an investigation gives them proof they found for themselves and a spectacle gives them a feeling that wears off shortly after. And the buying data lines up exactly with this. Prospects who experience a product before the sales conversation show up warmer, move faster, and close more often, because they already answered their own biggest question on their own time.

And underneath both of those: respect. A spectacle demo treats the buyer as an audience to impress. An investigation treats them as a capable pro who can be trusted to drive. The respect is the benefit. Security people have sat through plenty of magic shows. They already prefer to research alone, vet alone, and form an opinion before anyone gets on a call. Meeting them with a hands-on investigation instead of a slideshow just gives them, in the room, the same autonomy they’re already demanding everywhere else. Hand a skeptical professional something real and they remember you for it.

The demo is a tell

Here’s what it all comes down to.

How you demo gives away what you believe about security.

Demo by spectacle and you’re telling the room security is something you watch. A show that happens to you. Demo by investigation and you’re telling them it’s something you do, in real time, against an attack that’s already in motion. The demo is a tell and defenders were never meant to be an audience.

That’s how we think about it at Upwind, and it’s the same belief that has shaped the product since day one. We build for the defender who wants the wheel and the truth of what is actually running, not a highlight reel of attacks that showed up and a promise that everything is fine. The whole premise of runtime is that you can’t secure what you only watch from a distance. You secure it by seeing what is really happening and following the thread to the root of it. Too much visibility was never the goal. Action is. 

So stop showing attacks. Hand someone the keys and let them find their way in. They’ll remember the room they got to explore long after they have forgotten the one they sat through.

Contents

Further Reading

Buyers Demos

Why Buyers Remember Solving a Demo, Not Watching One

Key Takeaways I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive…
PagerDuty-Hero

Upwind Integrates with PagerDuty for Instant Incident Response

Upwind now integrates with PagerDuty, enabling security teams to create workflows that automatically route Upwind findings and detections to the appropriate on-call team based on existing incident management workflows. This integration expands Upwind's growing library of native workflow integrations, giving security and platform teams even more ways to turn real-time detections into immediate action. What's…
OpenAI Breach

Everyone Read the OpenAI Breach as a Model Story, But It Was a Runtime Story

Key Takeaways Autonomous AI agents can now break out of a sandbox, cross an internal network, and breach a production system with no human at the keyboard. OpenAI's evaluation that hacked Hugging Face this month is the clearest proof on record. Most of the coverage read it as a story about a model turning dangerous.…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS