We reverse-engineered a 59,515-keyword content plan for a cybersecurity company to understand what search data reveals—and what it misses about real buyer questions.
An enterprise cybersecurity company recently received a content plan from an SEO agency.
The plan contained:
The work behind it was sophisticated. The agency had researched the company, its products, customers, competitors and differentiators. It had expanded a carefully selected set of seed terms, grouped related searches into clusters, analyzed the pages already ranking and generated a proposed title and detailed content brief for almost every opportunity.
It had even crawled over 900 pages on the company’s website to determine which topics were already covered and where those pages were currently ranked.
So this was not a superficial keyword export.
But it raised a much more important question: how should a marketing team decide which of 15,326 possible pieces of content are actually worth creating?
And if the objective is visibility in AI answers, not just traditional search rankings, is keyword demand still the right place to start?
That's the question, we wanted to answer in this blog.
We reverse-engineered the spreadsheet to understand the process behind it.
The agency appears to have started by creating a detailed “brand book.” This described the company’s target customers, products, competitors, positioning, customer pain points and areas of differentiation.
From there, it created 98 seed keywords. These included:
Each seed was assigned a priority and accompanied by include and exclude terms to help disambiguate broad searches.
Those seeds were then expanded into 59,515 keywords. Each keyword was assigned search volume, keyword difficulty, intent, funnel stage, relevance and a suggested title.
Next, related keywords were consolidated into 17,463 clusters. Each cluster had a primary keyword, secondary keywords and a combined search volume.
For each cluster, the agency examined the search results. It classified the types of pages ranking, identified what appeared to be missing and generated a content brief containing a proposed angle, target audience, recommended page structure, word count, calls to action, internal links and schema suggestions.
Finally, it compared those ideas with the company’s existing website, classified potential matches as strong or partial and recorded whether the existing page ranked for the target keyword.
As a system for turning search data into content possibilities, it was impressively comprehensive.
The analysis surfaced several commercially credible opportunities.
Many were exactly the kinds of questions that might appear during an active evaluation according the the cybersecurity customer. They relate directly to products the company sells and problems its buyers are trying to solve.
The SERP analysis also added something beyond volume. It looked at what was already available and attempted to identify gaps: a lack of pricing transparency, insufficient explanation of implementation, generic vendor claims or content that failed to address the needs of a particular industry.
This is useful work. Search data can reveal how buyers express a problem, how frequently a phrase is searched, what content Google currently rewards and where the available answers appear inadequate.
The mistake would be assuming that this is enough to determine the content strategy.
The spreadsheet assigned every recommendation a score probably based on:
But the big question from the client was: does the question represent the company’s buyer? Does it relate to a strategic product? Would winning that search create a meaningful pipeline or authority?
Search data cannot answer those questions on its own.
A keyword opportunity tells you that somebody may want an answer. It does not tell you whether that person is your buyer, whether the question matters commercially or whether your company should be the one answering it.
In traditional SEO, a company might justify a broad informational article because it could rank, attract traffic and introduce new visitors to the brand.
But in AEO, that logic becomes more complicated.
AI systems do not need 15 slightly different pages explaining the same concept. They can retrieve and synthesize information from multiple sources. Google’s own guidance for generative search advises companies to focus on valuable, non-commodity content rather than creating separate pages for every possible query variation. It specifically emphasizes unique points of view and first-hand expertise over summaries of information that already exists. (Google Search Central)
Publishing another generic definition of ransomware, SOC or threat intelligence may add a page to the company’s index. It does not necessarily give an AI system a new reason to cite the company.
The opportunity is not simply to answer more questions. It is to identify the right questions and contribute answers that are difficult for anyone else to provide.
For the cybersecurity company that may have questions with less conventional search volume than a broad definition. But they are much closer to the decisions buyers are making and the areas where the company has genuine expertise.
Keyword research is valuable because it captures expressed search demand. But buyers reveal their actual nuanced questions in many other places:
These sources often expose questions that keyword tools miss and are more comparable to what users might ask an AI tool.
A buyer may tell a salesperson, “We already own Microsoft E5. Why do we need to pay someone else to manage it?” That objection may never appear as a high-volume keyword. But it is commercially important, and answering it well could influence both sales conversations and future AI answers about when managed security services are necessary.
Similarly, repeated Reddit discussions about excessive alert tuning, opaque MDR pricing or disappointing incident-response support may reveal the criteria buyers actually use to evaluate providers.
Search data shows what people type into a search box. Buyer conversations show what they are trying to understand, decide or defend internally.
A strong AEO strategy needs both.
Instead of treating keyword volume as the starting point and primary organizing signal, AEO teams can evaluate questions using other forms of evidence.
Is the question appearing in sales calls, LinkedIn conversations, Reddit threads, customer meetings or other places where the company’s real buyers communicate?
Is the question connected to a problem the company solves? What stage of the buying journey does it represent? Could answering it help create, progress or close an opportunity?
Does the company have experience, data or a defensible point of view that improves the existing answer? Which internal expert can provide it?
Where would the answer be most useful? Should it live on the company website, in a comparison page, within a LinkedIn discussion, in a Reddit response or across several of these sources?
The most valuable opportunities are usually found where these signals overlap.
A high-volume keyword with no buyer or commercial evidence may be a traffic opportunity, but not an AEO priority. A lower-volume question that repeatedly appears in sales calls and is poorly answered online may be far more valuable.
In our analysis of the content briefs from the SEO company, we found the briefs were detailed, but most were derived from the pages already ranking. This is an unavoidable limitation of SERP-led content generation: it is very good at describing the existing answer and suggesting a more comprehensive version of it.
It is less capable of discovering what the company knows that is absent from the search results.
That knowledge is with product leaders, security analysts, incident responders, sales engineers and customer-facing teams.
For priority questions, the content workflow should therefore begin with evidence and expert input—not with an AI-generated first draft.
An expert might contribute:
These inputs can then become a website article, a service page, sales enablement content and informed contributions to relevant external discussions.
That is more likely to create content that AI considers worth citing because of its unique information than rewriting the current top 10 search results.
The plan we analyzed concentrated overwhelmingly on content for the company’s own website.
That is necessary, but incomplete.
When a buyer asks an AI system to recommend an MDR provider or compare two cybersecurity companies, the answer may draw on vendor websites, independent comparisons, customer experiences, community discussions, partner pages and other external sources.
The company therefore needs more than a page claiming that it is the best provider. It needs its expertise to be visible and credibly corroborated in the sources buyers and AI systems consult.
This does not mean manufacturing mentions or flooding forums with promotional answers. Google explicitly cautions against pursuing inauthentic mentions for generative visibility. It means enabling credible experts to participate helpfully in relevant conversations and making it easier for partners, customers and independent sources to understand what the company does differently.
At Rocksalt, we do not see buyer-question intelligence as a replacement for keyword research, SEO platforms or AI visibility monitoring.
Those systems provide important signals. The missing layer is connecting them with questions expressed by actual buyers and the expertise required to answer those questions credibly.
Rocksalt brings together questions from sources such as search, LinkedIn, Reddit and sales conversations. It helps teams identify which questions matter commercially, where the existing answers are weak and which internal experts have something valuable to contribute.
Those expert answers can then inform both onsite content and useful participation in the external conversations that shape buyer understanding and AI visibility.
The objective is not to produce the longest possible list of content ideas.
It is to answer the questions that matter—with expertise worth retrieving, citing and trusting.
The SEO analysis we reviewed was not wrong. In many ways, it was impressively thorough.
It demonstrated how far modern keyword research, clustering, SERP analysis and AI-assisted content planning have advanced. It also demonstrated their limit.
Starting with 59,515 keywords produced 15,326 possible pieces of content. It did not, by itself, reveal the 30 questions most likely to influence the company’s buyers or establish the company as an authoritative source in AI answers.
That requires another layer of evidence: what buyers are asking, what the business needs to be known for and what its experts know that the internet does not already say.
SEO tells you where content might rank.
Buyer intelligence tells you what is worth answering.
Expert activation gives buyers and AI systems a reason to believe the answer.