ECG
Enquirer Consulting GroupReachable Buyer Map
Prepared for Protexxa and Netzzar · July 2026

The market, from the outside

Everyone who owns human-layer risk, mapped.

The buyer roles a CISO-only lens leaves out, and how many of them are actually reachable. United States, organizations of 1,000+ employees unless marked. Counts are deliberately banded, and describe the market, not any one company.

US · 1,000+ employees
3,000 to 3,500

The narrow lane: CISOs only

Chief Information Security Officers.

The most guarded inbox in the building, and the title every security vendor writes to first. Real, but small, and defended.

US · 1,000+ employees
20,000+

The wider room: security leadership

VPs and directors of security, heads of information security, directors of cybersecurity, security operations leaders.

More than six times the reachable owners of the same problem. These are the people who evaluate, champion and walk it upstairs.

US · 1,000+ employees
20,000+

The security-owning generalists

CIOs and CTOs.

In organizations without a dedicated CISO, this is who owns employee exposure and the human layer. A second, largely uncontested room.

US · All sizes
6,000+

The verticals where identity risk concentrates

Security leadership across financial services, healthcare and higher education, broken out below.

Where personal identity, credentials and regulated data concentrate, the human layer is the exposed layer.

4,000+

Financial services

Security leadership at banks, lenders, insurers and asset managers.

1,400+

Healthcare

Security leadership at providers and health systems.

~1,000

Higher education

Security leadership at colleges and universities.

Where we would start

Three openings, mapped to how this market actually buys.

1

Widen the aperture without lowering the bar

The same message discipline, aimed at every title that owns human-layer risk, not only the most guarded one. The problem has many owners; the outreach should too.

2

The door-opener path

Security VPs and directors answer, evaluate, and walk it upstairs. The CISO joins a conversation their own team started, which is a very different conversation.

3

Vertical proof loops

Financial services, healthcare and education buy on peer evidence. Capture the win, publish it, and aim the next wave at the same vertical while the proof is fresh.

What this becomes

In a working session, this map becomes the targeting brief: you mark the segments that matter most, and we build the named list behind each one, person by person, before anything is sent.

Built from public business registries and professional-network data. Counts are banded deliberately and describe roles and segments, never any company's internal numbers.