Industry playbooks

Cybersecurity sales call playbooks

Your buyers are four analysts under twelve thousand daily alerts, sixty overlapping tools, a board that wants a straight answer on ransomware, and an audit finding that has reopened three years running — and they get pitched 'AI-powered' by six vendors a week. Practise here and you learn to earn the next ten seconds from someone who has already decided you're noise, survive the agent-deployment and third-party-risk objections without flinching, and talk about dwell time and ingest cost the way they do.

Every call type for Cybersecurity

Scripts, sample dialogue, objection handling and a live AI buyer for each one.

Who you're calling

In Cybersecurity, the people who pick up are security leaders and SOC owners. The titles you will actually reach:

  • CISO
  • VP of Security Operations
  • Director of Security Operations / SOC Manager
  • Head of Detection Engineering
  • Security Engineering Manager
  • Director of GRC & Compliance
  • IT Director (security-owning, no dedicated CISO)

What keeps them up at night

Name one of these in your first thirty seconds and you have earned the rest of the call.

  • Tier-1 is drowning and the real detection is buried

    Four analysts, 12,000 alerts a day out of the SIEM, most of them the same three noisy rules firing over and over. Everything gets bulk-closed on Friday afternoon to get the queue back to zero. The nightmare isn't the alerts they closed — it's the one credential-stuffing hit inside the pile that nobody read, and the dwell time clock that started that night.

  • Tool sprawl with no clear coverage map

    Sixty-plus tools bought over eight years, three of them overlapping on endpoint, two on email, agents fighting each other on the same golden image. Nobody can answer 'what percentage of our estate has working EDR telemetry today' without a two-week manual reconciliation. Renewals hit and they cannot prove which tool actually caught anything.

  • Audit findings that come back every single year

    Same finding on privileged access review, same finding on log retention, same finding on offboarding. Remediation gets assigned to an ops team with no capacity, closed on paper, and reopens at the next SOC 2 or PCI cycle. The CISO has to explain to the audit committee why this is the third year in a row.

  • The board question they can't answer cleanly

    'Are we protected against ransomware?' There is no honest one-slide answer, so they present MITRE ATT&CK coverage percentages and hope nobody asks what happened to the eight percent. Meanwhile cyber insurance renewal wants proof of MFA coverage, EDR coverage, and immutable backups, and the numbers in the questionnaire have to be defensible.

  • Headcount that will not grow and analysts who leave

    Two open reqs unfilled for seven months, a night shift covered by on-call rotation, and the good detection engineer just got a 30% raise to go work for a vendor. Every new tool means more runbooks for the people who are already burnt out on triage.

  • SIEM ingest costs rising faster than the security budget

    Log volume grows with every new SaaS app and cloud account; the licence is priced per GB per day. They are actively choosing NOT to onboard log sources because they can't afford to ingest them — which means visibility gaps they know about and can't fix without a budget conversation.

What they'll push back with

The objections that come up on nearly every call, and a response that keeps the conversation alive.

Every vendor says AI-powered zero trust. You've got ten seconds to be different.
Fair. I'm not going to claim a category. One question: how many alerts hit your queue last week, and how many became incidents? If that ratio is worse than about 100 to 1 you have a triage problem, not a detection problem, and that's the only thing I do. If your ratio is fine, I'll hang up.
Adding your agent to 5,000 endpoints? The risk review alone takes a quarter.
Agreed, and I'd fail that review too. There's no agent — we read from the SIEM you already ingest into, via API, read-only. No kernel driver, no change window, no image rebuild. The security review is a data-handling review, not an endpoint deployment, which is usually a different, much shorter form.
We already have a SIEM, a SOAR, and an MDR. Where does this even sit?
In front of all three. Your SOAR runs playbooks on alerts after somebody decides they matter; your MDR bills you on volume it has to look at. We sit at the ingest point and collapse duplicates and known-benign into one thing your analyst reads. Fastest way to know if that's real is a two-week replay against last month's alerts — no production change.
Send me a SOC 2 Type II, a pen test report, and fill out our third-party risk questionnaire, then we'll talk.
Sending all three today, plus our data flow diagram and subprocessor list so your GRC team doesn't have to chase. While that's in the queue — can we do a 30-minute technical session with whoever owns your detection content? The security review takes six weeks either way; I'd rather it run in parallel with the people who'd actually use this.
We're not buying anything until Q3. Budget's committed.
Understood, I'm not asking for budget. What I'd like is to be the thing you already validated when Q3 comes, instead of starting from a cold POC. What's the ingest number your SIEM renewal is priced on? If we cut alert volume the way we do elsewhere, that renewal conversation changes, and that's usually a different budget line than mine.
Prove it in our environment. Everyone's demo looks great on their own data.
That's the only proof I'd trust either. Give us a 30-day export of alert metadata — no payloads, no PII — and we'll show you what your analysts would have skipped and what they'd have surfaced, against incidents you already know the outcome of. If we miss one you caught, that's a real answer and you've lost an afternoon.
If we cut alerts and miss something, that's my job. Nobody gets fired for reading too many alerts.
They get fired for dwell time, and reading 12,000 alerts is how dwell time happens. Nothing gets deleted — everything stays queryable and retained for the auditor, we just change what's presented first. And you set the suppression rules; we don't auto-close anything you haven't approved in writing.

Their language

Use these the way they do. Getting one wrong costs more credibility than getting none of them right.

Jargon

  • dwell time
  • MTTD / MTTR
  • alert-to-incident ratio
  • tier-1 triage
  • detection engineering
  • SIEM ingest (GB/day, EPS)
  • EDR vs XDR
  • SOAR playbook / runbook
  • MITRE ATT&CK coverage
  • true positive vs false positive rate
  • log source onboarding
  • IOC vs TTP
  • agentless / read-only API integration
  • co-managed SIEM / MDR
  • third-party risk questionnaire (TPRM)
  • SOC 2 Type II

Metrics they are measured on

mean time to detect and mean time to respond (MTTD/MTTR), alerts per analyst per shift and alert-to-incident ratio, false positive rate / percentage of alerts auto-closed, dwell time on confirmed incidents, EDR and log-source coverage as a percentage of known assets, SIEM ingest volume (GB/day) and cost per GB against licence cap, critical vulnerabilities open past remediation SLA, repeat audit findings and remediation closure rate per cycle, MITRE ATT&CK technique coverage percentage, SOC analyst attrition and unfilled req age

Related industries

Buyers with adjacent pressures, and the same call types against them.

Practise against a Cybersecurity buyer

A live AI prospect with Cybersecurity context — their pressures, their jargon, their objections. They talk back, they interrupt, and they can hang up on you. You get a scored breakdown when the call ends.

Start a roleplay