They do need this, but they have no idea what it's called. (eg: drop the tech jargon). Many don't REALIZE they need it - mainly because it hasn't happened to them. The risk is highest for companies with real customers or events - since it's lost revenue.
Sure - hope it helps. I've sold many security engagements and done the work. I've seen startups first hand usually do not understand their risk unless they've experienced it directly (hack / vuln / PCI / DDOS). It's a hard sell at first.
In case anyone is interested, I can help you with SYN flood, amplification attack, volumetric attack, rate-limiting botnets and also against spoofed attacks.