1. Rodrigo, you operate at the absolute edge of the cybersecurity landscape- defining a new market (of AI agent security) that didn’t exist a few years ago. Pioneering a market such as this means wrestling with the market’s own status quo and lack of awareness. In your expertise, what are the foundational steps to designing a narrative that forces security leaders to acknowledge an invisible threat- without creating outright panic or letting ignorance persist?

I try to start with evidence rather than fear. Security leaders have spent years learning to be skeptical of vendors who open with worst case scenarios, and if the first thing they hear is that agents will destroy their business, they tend to tune out. So instead of leading with the outcome, I try to show the mechanism: how an agent actually gets manipulated, through a poisoned tool description, a prompt injection buried in a document, or a permission that was never scoped down. Once someone sees how it actually works, the risk stops feeling abstract and becomes something technical and concrete, which is language security leaders are comfortable evaluating.

And the numbers back it up. Gartner predicts agent security incidents will rise from 9% to 25% by 2028. Security leaders are already seeing this firsthand, which is why the risk doesn’t need to be argued for anymore, it needs to be managed.

2. Actively translating high-level market awareness clashes with Silicon Valley’s “move fast and break things” motto- one too dangerous for AI deployments. Given your belief in “secure, accountable and built for trust” AI practice, how must security be positioned (or even reiterated) within GTM motions to operate as an accelerator for AI adoption, and not turn into a brake pad?

Security tends to become a brake pad when it only shows up at the end of a process, as a gate someone has to get through. What’s worked better for us is positioning it earlier, as something that speeds decisions up rather than slows them down. If a security team can review and monitor agent behavior in days instead of quarters, that’s often what actually lets an AI initiative move forward at all.

Instead of saying we stop bad things from happening, we try to talk about helping teams say yes faster. Procurement, legal, and security tend to move quicker when they can point to runtime controls and audit trails instead of a policy document that nobody really enforces. That reframes the conversation a bit, from risk mitigation toward deployment speed, which is closer to what AI leaders are actually being measured on these days. That’s the shift we’re betting on: fewer security teams seeing themselves as the department that says no, and more of them wanting to be part of getting AI shipped safely.

3. Distilling multi-layered technical vulnerabilities of AI and the security domain into a relevant and coherent GTM narrative can be challenging. To what extent is it necessary to strip away the engineering jargon to uncover the human and business stakes that compel organizational buy-in? How should marketing leaders go about that?

I think it’s less about stripping jargon out and more about knowing where it belongs. The technical detail doesn’t need to disappear, it just doesn’t belong in the first sentence. A CISO or a board member usually needs the business stake up front, what breaks, who’s accountable, what it costs, and the mechanism, the injection vector, the permission creep, can follow for people who want to verify the claim. One thing I find useful is a simple check: could someone outside security explain this back to a colleague in a sentence or two? If not, the copy probably hasn’t earned the technical depth yet, it’s just borrowing credibility from it.

I’d encourage other marketing leaders in this space to treat jargon a bit like a citation, something that backs up a claim rather than something that makes the writing sound more expert. In my experience, the people who actually buy agent security notice pretty quickly when language is doing more performing than explaining. We try to stay away as much as possible from empty words and hyped industry phrases. The attention span in the end is more limited than ever, so clarity is very much appreciated.

4. Demand gen looks different when the product solves a future-state problem- the marketing narrative must translate into pipeline. In such a scenario, how must marketing teams equip themselves to balance short-term velocity with long-term category education? And how do you help buyers avoid confusion and overwhelm amidst all of this?

Honestly, we try not to treat pipeline and category education as separate tracks, because they end up pulling in different directions if you do. Pipeline work wants proof, case studies, specific outcomes, reasons to talk this quarter. Category education wants patience, helping people understand a problem they don’t have a name for yet. If you let the pipeline side win every time, you end up with content that assumes the market already understands agent security, which most of it doesn’t. On buyer confusion, in our experience it’s rarely about a lack of information. It’s that every vendor in this space describes the problem a bit differently, so buyers end up piecing together five slightly different versions of the same threat.

What’s helped us most is just being repetitive in a good way, using the same few terms and the same examples everywhere instead of reinventing the pitch for every channel. Buyers don’t need more content, they need to hear the same clear story enough times that it starts to feel familiar. Practically, that means our content and demand gen work off each other. Whatever we’re teaching the market shows up in the pipeline content too, and whatever questions come up in sales conversations tell us what the next piece of education needs to cover.

5. When scaling market momentum, brands must educate industry analysts and shape how external validators perceive them. They are the ones who figure out where your category, AI agent security, would fit. What role should marketing play here, where analysts themselves are debating whether agentic security is a standalone market category or just a subset of traditional Application Security?

I see marketing’s role with analysts as less about persuasion and more about supplying evidence. Analysts are trying to draw a boundary around a category with incomplete information from every vendor claiming to sit at its center, so the most useful thing we can do is give them something concrete: customer deployments, specific attack scenarios we’ve helped mitigate, a clear sense of where our product stops and a customer’s existing stack starts. On whether agentic security is its own category or a subset of AppSec, I don’t think marketing settles that by asserting a position.

Over the last year, I have been in more than 100 analyst meetings. Analyst recognition is decisive for any company selling to large enterprises. Even more so in cybersecurity. Thanks to these conversations, I have a clearer picture of what drives CISOs to make a decision. A better sense of where AI security is heading. And a sharper view of where NeuralTrust fits into that shift. In the last 12 months, we’ve been featured in 2 market guides, 4 hype cycles, and numerous research notes. That’s what the market looks like today. And we’re proud to be the best positioned company from the EU. It’s been quite a journey, from not being on anyone’s radar a year ago, to leading such an important positioning.

6. Defining a new category and educating the market means preparing for a new era altogether- and in NeuralTrust’s case, security. As we move away from traditional user-based security perimeters, what is the single outdated mental model about cybersecurity that security leaders must completely unlearn to survive the next few years of tech?

For most of its history, cybersecurity was built around things you could count and pattern match: signatures, hashes, packet structures, known bad IP addresses. Even behavioral detection was still statistics underneath, a deviation from a baseline. That worked because the thing you were defending against was mostly code, something with fixed syntax and rules. Agents change what the attack surface actually is. Increasingly, it’s language.

A prompt injection isn’t a malformed packet, it’s a sentence that can mean different things depending on context, tone, language, or what a model infers from it. What matters is meaning, and meaning is a lot harder to pin down. So the model I’d tell security leaders to unlearn is that security is mainly a detection problem you solve with better numbers. It’s becoming more of a comprehension problem, understanding what an instruction is actually asking a system to do, and whether that intent lines up with what it’s supposed to be allowed to do. That’s closer to linguistics than to traditional threat detection, and most security teams aren’t really built for that yet. It’s one of the things I find genuinely interesting about this moment, watching a field that used to be about zeros and ones turn into one that’s increasingly about the nuances of language and meaning.

7. Your role as the CMO at Neural Trust also extends to your public profiles across Substack, Medium, and the AI Trust Letter. Your research for these content pieces has offered you a front-row seat to what modern CISOs care about and what overwhelms them. In your opinion, how has the information appetite of CISOs changed with the advent of AI? Does it fundamentally alter marketing teams’ approach to ideating and crafting content?

There’s so much AI related noise right now, vendor claims, new attack types, regulatory movement, that most of what lands in an inbox only gets a few seconds before it’s judged. It’s not that they stopped caring about depth, it’s more that they’ve gotten more careful about whose depth is worth their time. Writing the newsletter has made that pretty clear to me. The pieces that get real engagement usually aren’t the broadest ones, they’re the ones that pick one narrow, verifiable thing, an incident, a specific technique, a real failure mode, and go deep on just that. There seems to be more appetite for specificity than for breadth right now. For marketing teams, that probably means fewer trend roundups and more writing grounded in actual cases. It also means being upfront about what we don’t know yet. CISOs have read enough AI content at this point to notice when a vendor sounds more confident than the evidence supports, and that tends to cost more trust than just admitting the uncertainty.

In the end, like any content today, the challenge lives in cutting through the noise. But it’s important not to forget that once you do reach your readers, the content needs to hold up to their expectations. I still have a lot to learn in this space, and keeping up with what the experts and leaders in the industry are writing every day remains critical for me. That said, I’ll admit the space has turned out to be far more exciting than I expected, and it’s hard to think of a better moment to be doing this work.

Headshot Rodrigo

Rodrigo Fernandez Baon, Chief Marketing Officer at NeuralTrust

Rodrigo Fernandez Baon is the Chief Marketing Officer at NeuralTrust, an AI agent security company headquartered in Barcelona with offices in London, Munich, and New York, and backed by a $20M seed round. He joined as the company’s first marketing hire and built the function from the ground up, leading a team that now covers SEO, events, content, and analyst relations.

NeuralTrust’s product suite, TrustGate, TrustGuard, TrustLens, and TrustTest, secures AI agents at runtime for enterprise customers in banking, aviation, energy, and retail, with recognition from Gartner, KuppingerCole, MarketsandMarkets, and Omdia.

Outside NeuralTrust, Rodrigo is the author of the novel “La Cerilla” (2023), a TEDx speaker, and a recurring keynote speaker at cybersecurity and technology events across Europe. He writes The AI Trust Letter and publishes on Medium and Substack, where he covers AI security, the European AI ecosystem, and the discipline of building a market category from zero. He has also been recognized as a LinkedIn Top Voice in AI Security and B2B Cybersecurity Marketing.

SHARE THIS ARTICLE
Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *