Industry playbooks
Cybersecurity sales call playbooks
Your buyers are four analysts under twelve thousand daily alerts, sixty overlapping tools, a board that wants a straight answer on ransomware, and an audit finding that has reopened three years running — and they get pitched 'AI-powered' by six vendors a week. Practise here and you learn to earn the next ten seconds from someone who has already decided you're noise, survive the agent-deployment and third-party-risk objections without flinching, and talk about dwell time and ingest cost the way they do.
Every call type for Cybersecurity
Scripts, sample dialogue, objection handling and a live AI buyer for each one.
Cold Call
You dialled someone who was mid-something-else — reviewing a P&L, walking between meetings, about to eat lunch — and they picked up without knowing your name, your company, or why their phone rang. There is no prior email, no referral, no webinar download to reference. The first three to five seconds decide whether you get thirty more, and the first thirty decide whether you get a meeting. Your job on this call is not to sell the product, qualify thoroughly, or run discovery — it's to earn a next conversation by naming a problem so specifically that the prospect thinks 'how do they know that about us?' You will be interrupted, you will hear a reflex brush-off before they've processed a word you said, and you have to stay conversational through it without sounding like you're reading. Success is a calendar hold, not a good chat.
Read the playbook →Discovery Call
A 25-minute scheduled discovery call with a prospect who took your first touch seriously, cleared time, and showed up expecting to be diagnosed — not sold to. They already know your one-liner, so repeating it burns credibility. They have a real, layered problem: a surface symptom they'll hand over in the first two minutes, a mechanism underneath it they'll explain if you ask a decent follow-up, and a cost or political consequence they'll only name once you've proven you can hold the conversation without reaching for a demo. Your job is to earn each layer with open questions, quantify what you find, understand how a decision like this actually gets made in their shop, and leave with a specific, dated next step that both sides agreed to out loud. Pitch early, monologue, or run a BANT checklist and they will answer politely, in short sentences, and never take the next meeting.
Read the playbook →Manager Coaching Call
This is the 1:1 nobody sleeps well before. You manage a rep who has missed two quarters in a row — not catastrophically, but consistently — and you've got 30 to 45 minutes to find out whether this is a fixable skill problem, a fixable effort problem, or the start of an exit. They walk in with the excuses pre-loaded: the leads are garbage, the territory got carved up, we're 20% over on price against the challenger. Some of that is even partly true, which is what makes it hard. Underneath it, they know their discovery calls are shallow and they stopped prospecting sometime around week three of last quarter when they got busy 'working' two deals that were never going to close. They will not volunteer that. They'll only get there if you stay curious longer than they expect, look at actual numbers instead of arguing about feelings, and make it clear that admitting the real problem is safer than defending the fake one. Your job is not to win the argument, deliver a motivational speech, or put them on a PIP by minute ten. It's to get to one true root cause and leave with one changed behaviour they actually agreed to.
Read the playbook →Pricing Negotiation Call
This is the call after the technical win. They've run the eval, they've told their VP your product is the pick, and the only thing left is the number. They are not trying to talk themselves out of buying — they're trying to buy the same thing for less, and they will use every lever they have to do it: a low anchor ("honestly, we budgeted about half that"), a competitor's quote they may or may not still be considering, a case study or logo trade dangled as if it's currency, a threat to push the PO into next quarter, and long, deliberate silence after they name a figure. The trap is that they're pleasant about all of it, so it doesn't feel like a fight — it feels like a friendly conversation in which you keep making small, reasonable-sounding concessions until you've given away 30 points and gotten nothing. Your job is not to win the negotiation; it's to hold price by trading, keep the relationship warm enough that they still want to sign with you, and leave the call with a dated path to signature.
Read the playbook →Renewal Call
This is a save call, not a renewal call — the paperwork is the last five minutes, not the first five. The contract ends in six weeks, the customer has already half-decided to leave, and they're taking the meeting partly to say out loud what went wrong this year. Adoption never got past the first team, support tickets went quiet for days in Q2 during their busiest stretch, and a competitor rep has been in their inbox with a number that's 20-30% lower. They still like one or two things — usually the thing their power user built a workflow around — but they need those failures acknowledged specifically and unflinchingly before they'll entertain another twelve months. Lead with the order form, the discount, or 'so what would it take to get this done,' and you confirm every suspicion they have that you only show up when money is due. Lead with the ticket numbers, the dates, what actually broke internally on your side, what changed, and a named-owner plan for the next 90 days, and the same person will start negotiating with you instead of against you.
Read the playbook →Upsell Call
You're calling a customer who is already paying you, already reasonably happy, and has no idea you're about to ask for more money. They picked up expecting a check-in. Your job is to convert an account review into an expansion conversation without burning the goodwill that made the account healthy in the first place. The buyer's default posture is defensive on three fronts: the budget for your category is already spent for the year, their team is underwater and can't absorb another rollout, and they suspect they aren't even getting full value from what they bought last time — a suspicion you must address before they'll hear anything new. This call is won or lost in the prep: if you can open with their actual usage numbers and the specific result they've already gotten, you get a real conversation. If you open with "I wanted to tell you about our new module," you get a polite ten minutes and a "send me something."
Read the playbook →Warm Call
A warm call is one where somebody else's credibility got you the answer. A peer downloaded your guide and said "you should call Dani", or a mutual contact fired off a three-line intro that the prospect skimmed on their phone and archived. They pick up expecting you, but expecting is not the same as knowing — they can usually name the referrer and almost never name what you sell. You start with maybe ninety seconds of borrowed goodwill and a very specific obligation: prove the referrer wasn't wasting their time. Warmth is a loan, not a grant. Two generic sentences — "So, just to give you a bit of background on us" — and you've converted a warm call into a cold call the prospect now feels mildly embarrassed to be on, which is worse than cold. The job is to cash the referral fast, convert it into one specific, testable reason you're relevant to *them* rather than to the referrer, and get out with a real second meeting.
Read the playbook →
Who you're calling
In Cybersecurity, the people who pick up are security leaders and SOC owners. The titles you will actually reach:
- CISO
- VP of Security Operations
- Director of Security Operations / SOC Manager
- Head of Detection Engineering
- Security Engineering Manager
- Director of GRC & Compliance
- IT Director (security-owning, no dedicated CISO)
What keeps them up at night
Name one of these in your first thirty seconds and you have earned the rest of the call.
Tier-1 is drowning and the real detection is buried
Four analysts, 12,000 alerts a day out of the SIEM, most of them the same three noisy rules firing over and over. Everything gets bulk-closed on Friday afternoon to get the queue back to zero. The nightmare isn't the alerts they closed — it's the one credential-stuffing hit inside the pile that nobody read, and the dwell time clock that started that night.
Tool sprawl with no clear coverage map
Sixty-plus tools bought over eight years, three of them overlapping on endpoint, two on email, agents fighting each other on the same golden image. Nobody can answer 'what percentage of our estate has working EDR telemetry today' without a two-week manual reconciliation. Renewals hit and they cannot prove which tool actually caught anything.
Audit findings that come back every single year
Same finding on privileged access review, same finding on log retention, same finding on offboarding. Remediation gets assigned to an ops team with no capacity, closed on paper, and reopens at the next SOC 2 or PCI cycle. The CISO has to explain to the audit committee why this is the third year in a row.
The board question they can't answer cleanly
'Are we protected against ransomware?' There is no honest one-slide answer, so they present MITRE ATT&CK coverage percentages and hope nobody asks what happened to the eight percent. Meanwhile cyber insurance renewal wants proof of MFA coverage, EDR coverage, and immutable backups, and the numbers in the questionnaire have to be defensible.
Headcount that will not grow and analysts who leave
Two open reqs unfilled for seven months, a night shift covered by on-call rotation, and the good detection engineer just got a 30% raise to go work for a vendor. Every new tool means more runbooks for the people who are already burnt out on triage.
SIEM ingest costs rising faster than the security budget
Log volume grows with every new SaaS app and cloud account; the licence is priced per GB per day. They are actively choosing NOT to onboard log sources because they can't afford to ingest them — which means visibility gaps they know about and can't fix without a budget conversation.
What they'll push back with
The objections that come up on nearly every call, and a response that keeps the conversation alive.
- “Every vendor says AI-powered zero trust. You've got ten seconds to be different.”
- Fair. I'm not going to claim a category. One question: how many alerts hit your queue last week, and how many became incidents? If that ratio is worse than about 100 to 1 you have a triage problem, not a detection problem, and that's the only thing I do. If your ratio is fine, I'll hang up.
- “Adding your agent to 5,000 endpoints? The risk review alone takes a quarter.”
- Agreed, and I'd fail that review too. There's no agent — we read from the SIEM you already ingest into, via API, read-only. No kernel driver, no change window, no image rebuild. The security review is a data-handling review, not an endpoint deployment, which is usually a different, much shorter form.
- “We already have a SIEM, a SOAR, and an MDR. Where does this even sit?”
- In front of all three. Your SOAR runs playbooks on alerts after somebody decides they matter; your MDR bills you on volume it has to look at. We sit at the ingest point and collapse duplicates and known-benign into one thing your analyst reads. Fastest way to know if that's real is a two-week replay against last month's alerts — no production change.
- “Send me a SOC 2 Type II, a pen test report, and fill out our third-party risk questionnaire, then we'll talk.”
- Sending all three today, plus our data flow diagram and subprocessor list so your GRC team doesn't have to chase. While that's in the queue — can we do a 30-minute technical session with whoever owns your detection content? The security review takes six weeks either way; I'd rather it run in parallel with the people who'd actually use this.
- “We're not buying anything until Q3. Budget's committed.”
- Understood, I'm not asking for budget. What I'd like is to be the thing you already validated when Q3 comes, instead of starting from a cold POC. What's the ingest number your SIEM renewal is priced on? If we cut alert volume the way we do elsewhere, that renewal conversation changes, and that's usually a different budget line than mine.
- “Prove it in our environment. Everyone's demo looks great on their own data.”
- That's the only proof I'd trust either. Give us a 30-day export of alert metadata — no payloads, no PII — and we'll show you what your analysts would have skipped and what they'd have surfaced, against incidents you already know the outcome of. If we miss one you caught, that's a real answer and you've lost an afternoon.
- “If we cut alerts and miss something, that's my job. Nobody gets fired for reading too many alerts.”
- They get fired for dwell time, and reading 12,000 alerts is how dwell time happens. Nothing gets deleted — everything stays queryable and retained for the auditor, we just change what's presented first. And you set the suppression rules; we don't auto-close anything you haven't approved in writing.
Their language
Use these the way they do. Getting one wrong costs more credibility than getting none of them right.
Jargon
- dwell time
- MTTD / MTTR
- alert-to-incident ratio
- tier-1 triage
- detection engineering
- SIEM ingest (GB/day, EPS)
- EDR vs XDR
- SOAR playbook / runbook
- MITRE ATT&CK coverage
- true positive vs false positive rate
- log source onboarding
- IOC vs TTP
- agentless / read-only API integration
- co-managed SIEM / MDR
- third-party risk questionnaire (TPRM)
- SOC 2 Type II
Metrics they are measured on
mean time to detect and mean time to respond (MTTD/MTTR), alerts per analyst per shift and alert-to-incident ratio, false positive rate / percentage of alerts auto-closed, dwell time on confirmed incidents, EDR and log-source coverage as a percentage of known assets, SIEM ingest volume (GB/day) and cost per GB against licence cap, critical vulnerabilities open past remediation SLA, repeat audit findings and remediation closure rate per cycle, MITRE ATT&CK technique coverage percentage, SOC analyst attrition and unfilled req age
Related industries
Buyers with adjacent pressures, and the same call types against them.
Practise against a Cybersecurity buyer
A live AI prospect with Cybersecurity context — their pressures, their jargon, their objections. They talk back, they interrupt, and they can hang up on you. You get a scored breakdown when the call ends.
Start a roleplay