Search cmothinks

Type your search query and press Enter
Julie Parrish

Building Modern Cybersecurity Around Network Evidence with Julie Parrish

Cybersecurity July 16, 2026

The network remembers what attackers hope you'll miss.

That's why network evidence is becoming one of the most valuable assets in enterprise cybersecurity. Julie Parrish, CMO of Corelight, shares how it helps organizations uncover the full attack story, strengthen AI-powered detection, and build faster, evidence-driven security operations.

You have spent nearly three decades leading growth initiatives across networking, cloud, storage, and cybersecurity. What key experiences have most influenced your approach to leadership and marketing in today's technology landscape?

I have learned far more about leadership while navigating rough waters than I have when everything is smooth sailing. The experiences I had while leading teams through a very challenging “merger of equals” in 2004 taught me a lot about leading without ego, looking for solutions that drove the greatest good for the greatest number of people and managing through uncertainty. A massive merger drives uncertainty - employees are concerned about job changes and elimination, or seeing projects they worked on getting scrapped or defunded. Focusing first and foremost on what will drive the best answer for mutual customers becomes a unifying “north star.”

From a marketing perspective, the experience I acquired at NetApp while formulating high-level corporate positioning fundamentally re-shaped my methodology for establishing compelling differentiation. On the surface, the procedure was straightforward: compile a factual and non-promotional inventory of the capabilities that NetApp delivered to its clientele. Subsequently, customers were requested to prioritize this inventory, while industry analysts evaluated which specific components offered genuine differentiation. The remaining three to five core attributes were then utilized to construct comprehensive value propositions, which were systematically tested. Remarkably, although our internal teams anticipated that the optimal positioning would center on proprietary technology, the final research indicated that our customer engagement model constituted the primary differentiator. This critical element was completely absent from our initial inventory and only emerged during rigorous vetting sessions with clients and analysts. This initiative yielded several profound insights, most notably:

  • Follow a structured, methodical process rather than unstructured brainstorming to reach definitive outcomes.
  • Stay objective and listen to stakeholders to move past preconceived notions about final conclusions.
  • Focus on the customer instead of the competition.
  • Superior partnership and collaboration with the customer, will trump having the best product.

What has carried across every company I’ve worked for is a bias toward proof over promise, and enablement before selling. Buyers in technical markets are skeptical by training, and rightly so. Leading with marketing claims doesn’t work. Leading with education, particularly around how to think about a particular trend or challenge works. Leading with vendor created numbers doesn’t work either. Leading with outcomes works.

Cybersecurity teams are facing increasingly complex threats while managing limited resources. What are some of the biggest challenges security leaders are dealing with today, and how does Corelight help address them?

Two problems dominate right now. The first is volume: the number of tools, alerts, and data sources feeding a SOC has grown faster than headcount, so analysts spend more time triaging than investigating. The second is evasion: attackers increasingly operate in ways designed to look like normal activity in logs that can be manipulated or turned off, which means teams need a data source that's harder to tamper with.

Network evidence addresses both. It gives analysts a record of what actually happened on the wire, independent of whether an endpoint agent was running or a log was configured correctly, and it's built to be integrated into the SIEM, EDR, and other tools teams already have rather than asking them to rip anything out. Nobody wants another dashboard. They want a faster, more reliable way to answer the question 'what actually happened here.'

Marketing cybersecurity solutions often requires translating complex technical capabilities into clear business value. How does your team approach this challenge while engaging both technical and executive audiences?

A structured approach to marketing is essential, particularly when you have a complex product that has value across several different persona. We leverage two key tools to help us with the process:

  1. Messaging Frameworks: These encompass positioning, strategic pillars, outcomes, capabilities, features, and use cases. We create these for overall company messaging, specific launches and campaigns, and for particular thought leadership narratives.
  2. Buyer’s Journey Matrix (mapping the buyer's journey against specific personas): This tool is utilized for every campaign to define core messages for each persona at each specific stage. Consequently, core assets are aligned and deployed with an eye towards hitting multiple altitudes.

Marketing directed toward practitioners should focus primarily on education, such as demonstrating new capabilities or highlighting unacknowledged insights. Superficial comparative claims regarding product speed are significantly less effective than most people think. Marketing to executives presents greater challenges; as this audience generally focuses on two primary criteria: risk reduction and increased operational efficiency.

As Chief Marketing Officer, what are your top priorities for strengthening the company's market position and helping organizations better understand the value of network evidence?

Several years ago, Corelight prioritized driving brand awareness to establish a strong association with the Network Detection and Response (NDR) category. Operating as a small company in a crowded market of over 3,000 competitors amidst significant market confusion, the strategic objective was to align with a recognized category to clarify our market position. Solidifying this market position currently relies on two primary factors: achieving distinct differentiation within the category and generating significant market “buzz” in the process. Our priority is to emphasize our most differentiated and critical capability, Network Evidence, while concurrently showcasing our advancements in both artificial intelligence and detection capabilities.

Our Provably Better Data campaign is a great case study here. We knew that we had the "best data" but we didn't have a great way to prove it, quantify it and show the market what better data looks like and why it matters. We were able to create a neutral CTF scenario and feed different types of data into the AI models that were used for the investigation to show that firewall and flow data answered about 50% of the required questions, but Corelight data answered nearly 100% accurately. Armed with a rich set of outputs from this test, we launched a campaign to help shift the narrative away from whose AI model is better, or how many AI/ML detection models do you have - to what really matters: the quality of data feeding the model is what is important.

Your background includes connecting strategy with execution across sales, operations, and marketing. What steps can organizations take to ensure these teams remain aligned around customer and business goals?

This starts with shared goals at the executive table that are "big" enough to cover more than one function. This forces discussion and alignment about how as a team we can achieve the company level goal. Our top level goals are a mix of business and customer focused outcomes. For customers, a company level goal of 115% net retention forces a focus on product quality, launch impact and support efforts. A company level goal of delivering 200 new logos drives focus on demand generation and enablement handshakes between marketing and sales. Top line revenue goals shine a spotlight on awareness, sales enablement, hiring, and new product development.

Next, you need to drive alignment down and through the organization by:

  1. Creating a simple plan on a page that pulls 2-3 company level goals to each individual and follows a classic GOST (goal, objective, strategy, tactic) approach. The key here is to make sure that the strategy, tactic, and metrics are actually 100% within the control of that individual. Measure your web developer on efficiency and quality metrics, not demand generation metrics for example.
  2. Investing in a tool like Lattice that makes cascading goals up and down very straightforward. Employees can then see how their work contributes to larger goals.
  3. Creating an operating cadence that is lightweight and focused to be sure that conversations are happening around what is on/off track and why. We have weekly 30 minute meetings for cross functional GTM teams and R&D teams for example. Continuous feedback loop takes place, discussions on course corrections take place earlier.

Corelight serves a broad range of customers, from Fortune 500 companies to government agencies and research institutions. What common security needs do you see across these organizations, despite their different environments?

All of these organizations are trying to do the same things at the highest level: reduce risk, reduce cost, and improve efficiency/productivity. And they all have the same core issues as well: too many tools, too many alerts, escalating attacks, and increasingly complex compliance regulations. So what do they all need? Cybersecurity solutions that…

  1. Consolidate and integrate with existing solutions.
  2. Context from the network to triage alerts.
  3. Detection strategy that covers the entire spectrum of attack types.
  4. AI tools to match the speed and scale of today's attacks.

What is different between various account types is things like their SOC structure, size/skill of the SOC team, and their top level mission or initiatives. Some SOCs are very large with sophisticated teams and they care more about raw network data and detections vs. dashboards, workflow assistance, and simplified UIs. They would typically be more interested in an on-premise, air-gapped solution instead of a SaaS one. We see this a lot with our largest financial customers and agencies.

What cybersecurity and AI trends should organizations be paying close attention to in 2026 and beyond?

Clearly AI is at the top of the list. But the macro-trend for 2026 isn't just about adopting more AI; it's about making AI accountable and effective. Opaque, black-box algorithms fed on low-quality data are a liability. The winning organizations will be those that pair true agentic, playbook-driven AI with high-fidelity network ground truth to achieve machine-speed, auditable threat containment.

There has been a big shift in vulnerability exploitation as the primary entry point: for the first time, software vulnerabilities are the leading cause of data breaches. Anthropic's Claude Mythos has demonstrated that AI can be leveraged to identify these vulnerabilities and develop exploits faster than ever. Organizations need to develop an “ assume-breach” mentality and prioritize the following:

  1. Detect post-breach behavior before it escalates. An attacker inside your network will evade defenses, including endpoint detection and response (EDR) systems, move laterally, establish command-and-control (C2), and stage data for exfiltration. Each of these activities has a behavioral signature. Your detection capability needs to catch these behaviors in near-real time with AI-powered defense.
  2. Reconstruct the complete attack chain. In the event of an incident, forensic evidence should provide a complete picture of the incident from the point of initial entry, the lateral movement route taken, the command and control channels utilized, staging, and exfiltration activities.
  3. Contain rapidly to limit the blast radius. Mean time to detection (MTTD) and mean time to respond (MTTR) are no longer secondary metrics; they are the primary measure of your security program's effectiveness. Every hour of dwell time is potential lateral spread, additional data access, and compounding remediation cost. Automation of the entire workflow can accelerate containment.
Cybersecurity Enterprise Security Network Security Threat Detection AI Security SOC Cyber Defense Network Evidence

Julie has more than 25 years of experience leading marketing, sales, and operations across security, storage, networking and cloud technology companies. She is a customer-focused CMO with a track record of driving strategy and execution across thought leadership, product marketing, brand, communications, and digital demand teams. Prior to Corelight, she served as COO/CMO for RedSeal where she led marketing, sales, and services teams and helped the company double bookings and secure Series D financing during her tenure. Julie previously served as CMO for both NetApp and Check Point and has held a variety of executive leadership positions at Symantec, Veritas and Nokia. She holds a bachelor’s degree in Decision and Information Science from Santa Clara University.

CMO Thinks

Thinking is the new competitive advantage

Connect with us

CMO Thinks

© 2026 CMO Thinks. All rights reserved.