Four triggers, and the window each one opens
Search demand in security is event-driven in a way almost no other B2B category is. Nobody wakes up idly wondering about their attack surface. They search because something happened — to their software, to a company that looks like theirs, or to the rulebook they're audited against.
That has an awkward implication for the standard agency product. A content calendar agreed in January is, by construction, out of phase with demand that arrives in March and lasts nine days.
| Trigger | Who is searching | What they type | Window |
|---|---|---|---|
| A named CVE with a vendor advisory | Sysadmins and SOC leads running the affected software | The CVE ID, the product name with the word vulnerability, am I affected, patch | Days. Interest collapses once the patch is widely deployed |
| A breach in the news | Boards, CISOs, journalists, and every competitor of the breached firm | The company name with breach, how did it happen, are we exposed, the technique used | About a week, then it reopens when the regulator responds |
| A CERT-In direction or advisory | Compliance and IT leads at every covered entity | The direction, what it means, reporting timelines, log retention | Weeks, with a long tail as the deadline approaches |
| A regulatory deadline | Legal, compliance and procurement, together | The obligation, the date, checklist, who it applies to | Months — and the only one you can plan a year ahead |
The newsroom model, and the approvals that have to exist before it works
The operational answer is a small newsroom: a standing page template, a named technical author, a pre-agreed rule on what may be said, and a publishing target measured in hours.
Here's the part agencies don't say out loud. Almost every security firm that fails at this fails on governance, not on writing. Your best analyst can draft a competent advisory in two hours. It then sits with legal for nine days, comes back with the interesting sentences removed, and publishes into a dead query. The work wasn't the problem. The approval chain was.
So the first deliverable isn't content. It's five decisions, made once, in writing.
- One named approver and one named deputy. Not a committee, not a mailing list. Committees cannot clear a page inside a window that closes on Friday.
- A standing rule on what may be said about a live issue — no client names, no undisclosed technical detail, no exploit specifics, and no wording that implies a named organisation is compromised.
- A template that publishes without a designer. If a page needs a design ticket, it needs a sprint, and the window will not wait for one.
- A turnaround written into the contract in hours, with what happens when it's missed. Vague urgency is not a process.
- A kill rule. If you're engaged on the incident, you don't write about the incident. Deciding that in advance protects the client relationship that pays for the marketing.
Original research is the link unit, and it costs engineer time
Security is one of the few B2B categories where earning links from serious publications is genuinely achievable, because practitioner sites and journalists link to novel data as a matter of routine. They will not link to your services page, and no amount of outreach changes that.
What gets linked is a measurement nobody else has: a population scanned with a stated and reproducible methodology, a tool released publicly, a dataset, a disclosed vulnerability with a proper write-up. What doesn't get linked is a listicle about password hygiene, however well optimised.
Budget it as engineer time rather than writer time. A piece with genuinely original data is typically one to three engineer-weeks before anybody writes a sentence, and that number — not the content plan — decides whether you run two of these a year or six. It also means the cost sits outside a normal content retainer, and any agency implying otherwise hasn't produced one.
- Coordinated disclosure decouples your calendar from the news. If you found it, you publish after the vendor fix, often months later. Run two tracks: fast commentary on other people's disclosures, slow publication of your own.
- Reproducibility is the link magnet. Publish the method and the caveats. A researcher who can check your work is a researcher who will cite it.
- One asset, several surfaces. The research page, the conference talk, the tool repository and the advisory all point at the same finding. That's digital PR done properly rather than a press release.
- Name the humans. Google's guidance on helpful content asks who made this and whether it shows first-hand expertise. In security, an unattributed technical page reads as either marketing or AI output, and both cost you the reader you wanted.
Compliance deadlines are the only demand you can diarise
This is the durable layer, and in India it's unusually rich. Regulators here publish dated, specific obligations, and every covered entity searches for them — first when the rule lands, then again as the deadline gets close.
CERT-In's 2022 directions under section 70B of the IT Act are the clearest example: covered entities must report specified cyber incidents within 6 hours of noticing them and maintain ICT system logs securely for a rolling 180 days within Indian jurisdiction. Those two numbers alone generate steady search from every compliance lead who has to explain them upward.
The RBI's Information Technology Governance, Risk, Controls and Assurance Practices Directions, 2023 do the same for regulated financial entities, with board-level committees, a CISO who reports independently of the IT function, periodic vulnerability assessment of critical systems and annual penetration testing. SEBI's cyber resilience framework covers its own regulated entities, and DPDP obligations sit across everyone processing personal data.
One page per obligation. What the rule actually says, who it covers, what has to be done by when, what you do about it, and roughly what that costs. Then a review date and a named owner, because these get amended and a stale compliance page in this industry is not a ranking problem.
Service pages are the floor, not the plan
VAPT, red teaming, managed detection, vCISO, ISO 27001 and SOC 2 readiness — these pages have to exist and have to be good, but they are low-volume, heavily contested in ads, and they will not grow. Treat them as the conversion layer that everything else feeds.
What separates a service page that converts from one that doesn't is boring specificity, and almost nobody publishes it.
- Scope boundaries — what's in the test and what explicitly isn't. Buyers have been burned by a quotation that excluded the thing they cared about.
- A named methodology and a redacted sample deliverable. A prospect wants to see the report before they want to see the price.
- Retest policy. Whether a retest after remediation is included, and for how long. This is the single most common surprise in a VAPT engagement.
- Who does the work, with certifications, and whether the same people run the engagement they pitched.
- CERT-In empanelment, with the period, if you hold it. In regulated sectors it's the credential procurement filters on, and burying it in a footer wastes it.
- vCISO is a separate query set with a separate buyer. Those searches follow a board mandate or a failed audit, not a scan result, and the page should read as a role description rather than a service.
What we'd change about our own retainer before quoting you
A standard SEO retainer buys fixed monthly output — so many pages, so much technical work, so much outreach. In this vertical that shape is wrong, and pretending otherwise would be a comfortable way to bill you for twelve months of the wrong thing.
What we'd propose instead is two halves. A smaller standing retainer covering the durable layer: the compliance library, the service pages, technical health, internal linking and measurement. Then a pre-agreed rapid-response block with a stated turnaround in hours, drawn down only when a trigger fires, and expiring at the end of each quarter so it never becomes a bank of unused hours that quietly turns into a discount argument.
The honest conditions attached: rapid response is only worth buying if your approvals can match it, original research is engineer time you fund or we scope separately, and we can only hold standby capacity because we take three clients a month. If those don't work for you, buy the standing half and let the newsroom wait until the governance exists. That's a real recommendation, not a negotiating position — more on how we think about this in what an SEO retainer actually buys.
What it costs, and what we guarantee
Our SEO runs from ₹75,000/mo, and from ₹40,000/mo for smaller sites. Ex-GST, month-to-month after the first quarter, 30 days' notice, and you keep every asset. Full numbers on our pricing page, and the structures we normally offer are on our retainer plans.
We don't promise a ranking position — nobody controls Google's index, and in a market that sells trust for a living, promising one would be an odd way to open. We freeze your trailing-90-day qualified enquiries from organic search on day one, and if we haven't beaten that number in 90 days we keep working free until we do.
One caveat specific to this industry: if most of your pipeline comes from analyst relations, channel partners and conference presence, search is a supporting channel and we'll tell you that at the proposal stage. The SaaS version of this brief is a better fit for product-led security companies selling a subscription rather than an engagement.