New CISO reviews and changes vendors; vCISO for gap period
M&A activity
News; SEC filings
1-6 months
Due diligence; integration security; assessment
Cloud migration
Job postings mentioning cloud; technology signals
3-12 months
Cloud security architecture; assessment
Industry peer breach
News
1-4 weeks
"Is your industry a target? Assessment to check your posture"
Data sources for cybersecurity prospects
Source
What you find
Best for
LinkedIn (title search: CISO, IT Director, VP Security)
Decision makers by title and company
Direct outreach to security buyers
Compliance databases (SOC 2 reports, PCI ROCs)
Companies with compliance requirements
Compliance-driven outreach
Job postings (security roles)
Companies building security teams
Companies investing in security
Conference attendee lists (RSA, Black Hat, BSides)
Active security community members
High-quality prospects
Industry association directories (ISACA, (ISC)2)
Certified security professionals
Decision maker identification
Government contract databases (SAM.gov)
Companies with CMMC/FedRAMP requirements
Government compliance prospects
Breach notification databases
Companies that have been breached
Post-breach services
Crunchbase (recently funded companies)
Funded startups needing SOC 2
Compliance-driven outreach
Insurance broker networks
Companies renewing cyber insurance
Assessment-driven outreach
Cold Email Templates
Penetration testing outreach
Section
Content
Subject line
"[Compliance: SOC 2 / PCI / HIPAA] pen test requirement for [Company]"
Opening
"Many [industry] companies approaching their [SOC 2 audit / PCI assessment / compliance deadline] discover they need a penetration test 4-6 weeks before the deadline..."
Value
"We provide [network / application / cloud] penetration testing with [certification: OSCP, CREST, PCI ASV]. Our reports are accepted by [auditor types]. Average engagement: [X] days from kickoff to final report"
Differentiator
"Unlike automated scan-and-report services, our tests are manual, hands-on-keyboard assessments by senior testers with [X]+ years of experience"
Social proof
"We have tested [X] organisations in [their industry], including [relevant credential without naming clients unless permitted]"
CTA
"Do you have a pen test requirement coming up? Happy to discuss scope and timing"
vCISO outreach (to company without a CISO)
Section
Content
Subject line
"Security leadership for [Company] without the full-time cost"
Opening
"Companies at [Company]'s stage ([employee count] employees, [industry]) typically need a security leader but cannot justify a $250K-$400K full-time CISO hire..."
Problem
"Without dedicated security leadership, common issues include: ad hoc security decisions, compliance gaps, no incident response plan, no security budget or roadmap, and board or investor questions going unanswered"
Value
"Our vCISO service provides a fractional security executive who builds your security programme, manages compliance, handles vendor selection, reports to your board and responds to incidents, for a fraction of a full-time hire"
CTA
"Would a brief conversation about your current security posture make sense?"
Post-breach outreach (to company with recent public incident)
Section
Content
Subject line
"Post-incident support for [Company]"
Opening
"I understand [Company] recently experienced a security incident. This is a difficult time, and I wanted to offer support rather than a sales pitch..."
Value
"We specialise in post-incident services: forensic investigation, containment and remediation, regulatory notification support, and building the security programme to prevent recurrence"
Tone note
"Empathetic, not opportunistic. Acknowledge difficulty. Offer help, not 'I told you so'"
CTA
"If there is anything we can help with now or in the coming weeks, please reach out"
Outreach Sequencing
Security services sales sequence
Email
Timing
Content
Goal
Trigger-based introduction
Day 1
Tie to specific buying trigger; brief credential
Open conversation
Educational content
Day 5
"[Industry] security benchmark report" or "Top [X] risks for [industry] in 2026"
Demonstrate expertise
Case study
Day 12
"How we helped a [similar company] achieve [SOC 2 / reduce risk / pass audit]" (anonymised if needed)
Social proof
Compliance reminder
Day 20
"[Regulation] deadline approaching; what it means for [Company]"
Create urgency
Direct ask
Day 30
"Is security on your roadmap for this quarter? If so, I would welcome a conversation"
Qualify interest
Trust-Building in Cybersecurity Outreach
Security buyers are inherently sceptical. Trust signals that matter:
Trust signal
How to demonstrate
Where to include
Certifications (OSCP, CREST, CISSP, GPEN)
List in email signature; link to verification
Signature; company website
Industry experience
Name industries served (not clients, unless permitted)
Email body; case studies
Methodology
Reference established frameworks (OWASP, NIST, MITRE ATT&CK)
Technical content; proposals
Responsible disclosure
Mention CVEs attributed to your team (if applicable)
Bio; website; content
Conference speaking
Mention relevant talks at RSA, Black Hat, BSides, etc.
Email body; signature
Publications and research
Share original research; blog posts; white papers
Content emails
Insurance and liability
Mention professional liability / E&O insurance
Proposals; website
Metrics
Outreach type
Open rate
Reply rate
Meeting rate
Notes
Trigger-based (compliance deadline)
35-50%
8-15%
5-10%
Highest urgency; best performance
Post-incident
40-55%
10-20%
8-15%
Sensitive timing; empathy critical
General security outreach (no trigger)
25-35%
3-6%
2-4%
Lower urgency; educational approach
CISO / security leader
30-40%
5-10%
3-7%
Busy audience; quality over quantity
CEO / CFO (no CISO companies)
25-35%
4-8%
3-6%
Business risk framing
IT Director (SMB)
30-40%
5-10%
3-7%
Practical, budget-conscious messaging
Building Security Prospect Lists
When compiling prospect data from conference attendee lists (PDF), industry association directories (HTML), LinkedIn research, compliance databases, government contract databases (CSV), job posting data, Crunchbase exports and breach notification databases, upload the files to Email Extractor to extract and deduplicate email addresses. Security professionals appear across multiple conference attendee lists, professional associations and industry databases, so deduplication prevents contacting the same CISO or IT director through overlapping outreach campaigns.