Selling security means selling to people whose job is to distrust. A security leader reads vendor email the way they read a suspicious login alert: looking for the detail that does not add up. That is not a reason to avoid outbound. It is a reason to run it with more precision than most markets need.
This playbook is for cybersecurity vendors, consultancies and managed security providers selling to UK organisations. It covers how to choose accounts, which events create a genuine reason to talk, who sits in the buying group, how to write for a sceptical reader, why your own security will be examined, and how to run email, phone and LinkedIn within UK rules.
Why security buyers ignore most outreach
Three habits make security outreach easy to delete.
- Fear without evidence. Breach statistics with no source, or with a source the reader cannot check, read as manipulation. A security leader will not forward a message to a colleague if they cannot defend it.
- Category language instead of a specific problem. "Next-generation", "AI-powered" and "end-to-end" describe every vendor in the market, and therefore none of them.
- Pitching on first contact. Asking for a demo before establishing why this organisation, and why now, tells the reader the sender has not done the work.
The fix is not cleverer copy. It is a narrower list and a real reason to get in touch, which the rest of this playbook builds.
Choose accounts by trigger as well as fit
Fit tells you an organisation could buy. A trigger tells you it may be thinking about the problem now. The most useful triggers in security are public, or easy to confirm on a short call:
- A new security leader. A new CISO or head of security usually reviews tools, providers and priorities early in the role, and is often more open to an outside view while doing so.
- A new or changing obligation. Regulation, a contract requirement or a large customer's supplier demands can turn a known gap into a deadline.
- A significant infrastructure change, such as a cloud migration, an acquisition, a new site or a move to a managed IT provider.
- Hiring around the security function, which shows investment and often names the tools and frameworks the team works with.
Regulatory triggers deserve particular care, because they are easy to overstate. The Cyber Security and Resilience (Network and Information Systems) Bill is a good example. According to the government's summary, it would bring medium and large managed service providers and data centres into the scope of the NIS Regulations, let regulators designate critical suppliers, and require an initial incident notification within 24 hours with a fuller report within 72 hours. For a security provider selling to managed service providers, that is a legitimate reason to start a conversation. It is also a Bill, so check its current status and describe it accurately. The buyer may know the detail better than you do.
Supplier requirements are another dated, concrete trigger. The NCSC describes Cyber Essentials as the minimum standard of cyber security recommended by the government for organisations of all sizes, and notes that a growing number of organisations require suppliers to be certified to bid for work. A business that sells into those organisations has a reason to act, and a date to act by.
Map the buying group, not just the CISO
In a large organisation, the security leader rarely buys alone. Expect some combination of:
- the CISO or head of security, who owns the risk and usually the strategy
- security operations or engineering leaders, who will run the product or service day to day and can stop it on technical grounds
- infrastructure and IT leaders, whose systems the change touches
- risk, compliance or audit owners, particularly where a regulation or certification is driving the work
- procurement and finance, who control the route to contract
In smaller organisations the picture inverts. There may be no security team at all, and the decision sits with an IT manager, a finance director or the managed IT provider that runs their systems. For many security vendors, the managed service provider is the buyer worth reaching first, because one relationship can open many end customers.
Write the buying group down for each segment before anyone writes a message. The method is the one we use to define an ideal customer profile: who feels the problem, who owns it, who can block it and who pays for it.
Write for a reader who checks claims
Every claim in a message to a security buyer should survive a sceptical reading. A short structure works better than a long one:
- Why them: one specific, verifiable observation about the organisation, such as a new leader, a published obligation or a technology they evidently use.
- The problem: one problem you solve, in the buyer's terms rather than your product's.
- The proof: one piece of evidence you can stand behind, such as a certification you actually hold, a framework you can show alignment to, or a plain description of how the product works.
- The ask: a low-cost next step, such as a short technical briefing, rather than a demo request.
If you want to set out the wider threat picture, use figures the reader can check and name the source in the message. The government's Cyber Security Breaches Survey is published every year and is a far better reference than an unattributed number from a vendor report. Quote it accurately, with the year, or do not quote it at all.
Avoid absolute claims. "Stops ransomware" invites an argument. A clear description of what the control does, where it sits and what it does not cover invites a conversation.
Expect to be assessed as a supplier
A security buyer will examine your own security long before contract. Security questionnaires, evidence of certifications, data handling and access arrangements, incident response commitments and subcontractor details are all common requests. Vendors who produce them slowly lose momentum at exactly the point the buyer is ready to move.
Prepare that evidence before outbound starts. It shortens the sale, and it improves the outreach: a message that can honestly mention the certifications you hold and the assurance you can provide is more credible than one that cannot.
Channels: email, phone and LinkedIn against one list
Email carries the specific, checkable message. Named work addresses at companies fall under PECR's rules for corporate subscribers, but UK GDPR still applies to the person, so the first email has to say where you got their details and how to object. Our guide to whether cold email is legal in the UK sets out each requirement with its source.
The phone confirms ownership and timing. A short call that asks who owns a decision, and when the next review is, does not ask the buyer to disclose anything sensitive, which matters to people trained not to. Screen numbers against the TPS and CTPS first, as our guide to the UK cold calling rules explains.
LinkedIn shows you the shape of the security team, the tools people mention and the events they attend, and gives your name some familiarity before the call. Keep the activity personal and human-paced. Security people are quick to recognise automation, and slow to forgive it.
Sequence the three channels against the same account list, so each touch builds on the last instead of three campaigns competing for one inbox. Our guide to building a multichannel outbound sequence sets out the structure step by step.
What a qualified security meeting looks like
- The organisation fits the environment your product or service is built for.
- There is a live problem, project, review date or obligation, and you know which one.
- The person attending owns the problem or has been asked to evaluate it, and you know who else will be involved.
- The buyer has agreed a specific purpose for the meeting, such as a technical briefing on one control or a review of one gap.
A meeting that meets none of these is a conversation, not pipeline. Record it honestly and keep the account warm, rather than forecasting it.
Mistakes that cost security vendors meetings
- Leading with unsourced breach statistics or worst-case scenarios.
- Writing to the CISO only, and ignoring the engineers, IT leaders and managed providers who shape the decision.
- Presenting a regulatory change as certain before it is, or describing it inaccurately.
- Claiming certifications, partnerships or customers you cannot evidence.
- Asking for a demo on the first touch.
- Stopping after one channel and two emails, when the buyer's review cycle runs over months.
Where to start
Pick one segment where you have real proof, one trigger you can verify, and a list small enough to research properly. Write down the buying group, the one problem and the one proof point before anyone drafts a message. Then run email, calls and LinkedIn against that list for long enough to reach the people who were not ready the first time.
If you would rather not build that in-house, our cybersecurity lead generation programme identifies the organisations and security stakeholders that fit your offer, develops an evidence-conscious message, and coordinates cold email, LinkedIn and human calls around the same account plan.
Sources
- Cyber Security and Resilience (Network and Information Systems) Bill: summary of the Bill, Department for Science, Innovation and Technology (2026)
- Cyber Essentials overview, National Cyber Security Centre
- Cyber Security Breaches Survey, Department for Science, Innovation and Technology
Want this run for you?
Lead Conneqt gives B2B companies an outbound SDR function without building the team in house: ICP and account selection, prospect research and data preparation, cold email, LinkedIn, human telemarketing, reply handling, qualification and booked meetings, managed as one programme and reported on throughout.
Lead Conneqt Editorial
Outbound Growth Team. Lead Conneqt runs managed outbound programmes for B2B companies: telemarketing, email and LinkedIn outreach against one account list. About Lead Conneqt