Cybersecurity · Cold Call
Cybersecurity Cold Call Script: Getting a SOC Leader to Book 25 Minutes
You are about to dial someone who has already been called four times this week by a vendor claiming AI-powered zero trust, and twice by someone who opened with "I saw the news about the breach in your sector." A Director of Security Operations answers the phone with their hand already on the hang-up. A CISO answers because they're between an audit committee prep and a cyber insurance renewal call and thought you were the broker. Either way, you're a stranger interrupting a shift that already has 12,000 alerts in it.
The only thing that buys you thirty seconds in this market is naming the mechanics of their day out loud. Not "alert fatigue" — four analysts, three noisy rules generating most of the queue, and the Friday afternoon bulk-close that gets the board back to zero before the weekend. Not "visibility gaps" — the log sources they have deliberately not onboarded because the SIEM licence is priced per GB per day and they're already near the cap. When a SOC manager hears their own Friday afternoon described by someone they've never met, the reflex brush-off dies in their throat. That's the whole game.
This script is built for that. It assumes no prior email, no referral, no webinar download. It assumes you will be interrupted inside eight seconds, told to submit to the third-party risk portal, and asked what makes you different from every other vendor with the word "autonomous" on their homepage. Your job is not to sell, not to run discovery, not to explain your architecture. It is to earn a 25-minute technical conversation with the person who owns detection content, and to have the invite land on their calendar before you hang up.
The cold call script
Say it in your own words. The structure is the part that matters.
- 1
Before you dial — the 90-second prep, out loud
Answer these four in one sentence each, spoken, before the phone rings: 1. WHO: "Priya Raghavan, Director of Security Operations at Meridian Health, in seat 14 months, owns the SOC and the co-managed MDR relationship — not the GRC programme." 2. TRIGGER: "Two Tier-1 SOC analyst reqs posted 90+ days, plus a detection engineer posting that went up last week." If there's no trigger, the segment is the trigger: "every four-to-six-analyst SOC we talk to running Splunk with an MDR on top is dealing with the same thing." 3. ONE PROBLEM: written down, one only. Default for SecOps leaders: the Friday bulk-close and what's buried in it. Default for a CISO: the ransomware slide and the insurance questionnaire. Default for GRC: the third-year repeat finding. 4. THE ASK: "25 minutes, Thursday 8:15am or Tuesday 4pm, with you and whoever owns detection content." Have the follow-up email drafted in a window before you dial. Subject line already typed.
- 2
Opener — Director of SecOps / SOC Manager
"Priya — it's Sam at Corvid. We've never spoken, this is a cold call. Give me thirty seconds to tell you why I rang and then tell me to get lost?" [PAUSE. Two full seconds. Do not fill it.] Tonality: slower than feels natural. "Get lost" lands flat and slightly amused, not pleading. The ask ends on a downward inflection — "...tell me to get lost." down, not up.
- 3
Opener variant — pattern interrupt (for the clipped answerer)
"Priya — Sam, Corvid. You don't know me. Is this a terrible time or just a bad one?" Most people answer "depends what it's about." That is permission. Go straight to the reason.
- 4
Opener variant — trigger-led (open reqs / new in seat)
Open reqs: "Priya, Sam at Corvid — cold call. You've had two Tier-1 analyst reqs open since roughly March and a detection engineering role that went up last week. That's actually why I rang. Thirty seconds?" New CISO in seat: "Marcus, Sam from Corvid, we've not met. You're about four months into the CISO seat at Halberd, which means you've probably just finished counting tools. That's the reason for the call. Can I have thirty seconds?"
- 5
The reason — problem, not product (SecOps version)
"We work with about a dozen SOCs running four to eight analysts on a co-managed SIEM. The thing that comes up every single time is the alert-to-incident ratio — twelve, fifteen thousand alerts a day out of the SIEM, three noisy rules making most of it, and by Friday afternoon somebody's bulk-closing the queue to get it back to zero before the weekend. Nobody's worried about the alerts they closed. They're worried about the one credential-stuffing hit sitting inside the pile that nobody read, and the dwell time clock that started that night. Is that anywhere near your world, or have you actually got that ratio under control?" Note: no product name. No company story. The last question gives them a graceful, honest out — which is exactly why they answer it honestly.
- 6
The reason — CISO version
"Most of the CISOs we talk to at your size have the same problem in two places. The board asks 'are we protected against ransomware' and there's no honest one-slide answer, so it becomes a MITRE ATT&CK coverage percentage and a quiet hope nobody asks about the missing eight percent. And then the insurance renewal questionnaire wants a defensible number for MFA coverage and EDR coverage as a percentage of known assets — and getting that number takes a two-week manual reconciliation across three overlapping endpoint tools. Is that a fair description of your last renewal cycle, or is your asset picture cleaner than that?"
- 7
The reason — Director of GRC & Compliance version
"Every GRC lead I talk to has the same three findings coming back every cycle. Privileged access review. Log retention. Offboarding. Remediation gets assigned to an ops team with no capacity, closed on paper, and reopens at the next SOC 2 or PCI window — and then you're the one explaining to the audit committee why it's the third year running. Is that on your list this cycle, or did you finally get those closed?"
- 8
Two questions, maximum — then close
Pick two. Narrow and factual only. - "Roughly how many alerts hit the queue in a shift, and how many of those become actual incidents?" - "Is the triage a person reading a queue, or does the MDR filter first and hand you the survivors?" - "What's your SIEM priced on — GB per day or EPS? Are you near the cap?" - "Are there log sources you've decided not to onboard because of ingest cost?" - "Is fixing that on someone's plan this year, or is it just something you live with?" Listen for the admission: "honestly, it's a mess," "we've been meaning to tune those rules," "don't ask me about our Okta logs." The moment you hear it, STOP ASKING and go to the ask.
- 9
The ask
"Here's what I'd suggest. Twenty-five minutes, not a demo, no deck. I'll walk your detection lead through what we did with a SOC that had a four-figure alert-to-incident ratio — what we collapsed, what we left alone, and what they'd have missed if we'd got it wrong. You tell me on the call whether it's worth a second one. I've got Thursday 8:15 before your day starts, or Tuesday at 4. Which is less bad?" When they pick: "Sending the invite now while we're on — can you tell me it landed? And is there anyone who owns detection content you'd want in the room?" Do not hang up before they confirm the invite. A meeting calendared later no-shows far more often.
- 10
Gatekeeper / EA screen
"It's about their alert triage volume in the SOC — Sam at Corvid, she won't know me, it's a cold call. If she's not the right person for that I'd genuinely rather you told me now than put me through." Short, calm, specific. Never claim a prior relationship, never say "she's expecting my call," never be cute about it. Security orgs check.
- 11
Voicemail — under 20 seconds, no ask
"Priya, Sam at Corvid — you don't know me. Calling about alert-to-incident ratio in SOCs your size; the bulk-close-on-Friday problem. Not a fit for everyone. I'll try you Thursday morning. 415-555-0148." The voicemail's job is name recognition for attempt two and the email. No meeting request, no value prop, no URL.
- 12
The soft no — recycle with a dated reason to return
"No problem at all. One last thing and I'll let you go — is this a timing thing or a 'this isn't a priority' thing?" [Listen.] "Got it. When's your SIEM renewal — and is the ingest number set before that or during?" "Perfect. I'll come back to you in early August, before that conversation starts. I'll send one email so my name isn't a surprise." A call that produces "SIEM renewal is November, ingest is the pressure point, call me in August" is a good call. A call that produces "send me an email" and nothing else is a polite hang-up.
- 13
Follow-up email — send within five minutes
Subject: Our call just now — alert-to-incident ratio Priya — Sam from the cold call. You said the queue is around 11,000 a day and Tier-1 is four people plus on-call at night. Thursday 8:15 is on your calendar. 25 minutes, no deck. I'll bring the before-and-after alert volumes from a SOC on a co-managed Splunk build roughly your size, including the two things we suppressed that they made us turn back on. SOC 2 Type II, last pen test summary and our data flow diagram attached so your GRC team can start early — we read from the SIEM read-only over API, there's no endpoint agent. Sam Use their words, not yours. "Bulk close," "the Okta logs," "our MDR eats the easy stuff" — whatever they said, quote it.
How the call actually sounds
Prospect on the left, the rep on the right.
Rep
Priya — it's Sam at Corvid. We've never spoken, this is a cold call. Thirty seconds to tell you why I rang, and then you can tell me to get lost?
Buyer
We don't take vendor calls. Everything goes through the portal — if you want to be considered you submit to our third-party risk process and someone gets to you in a quarter. That's the whole answer.
Rep
Fair, and I'll submit today. Before I do — I'd be submitting into a queue with sixty other vendors and no reason for anyone to read mine. Thirty seconds and if it's not a thing at Meridian I'll put myself in the portal and stop calling.
Buyer
Thirty. Go.
Rep
Every SOC we work with running four to eight analysts on a co-managed SIEM has the same thing. Twelve, fifteen thousand alerts a day, three rules making most of it, and Friday afternoon somebody bulk-closes to get the queue back to zero before the weekend. Nobody worries about the ones they closed. They worry about the credential-stuffing hit buried in the pile that nobody read, and the dwell time clock that started that night. Is that anywhere near your world, or have you got the ratio under control?
Buyer
Okay, stop. Let me guess — you're an AI SOC. Autonomous triage, ninety-eight percent noise reduction, trained on billions of events. I've had four of these calls this month and two of them opened with a breach in our sector, which I found genuinely offensive.
Rep
I'm not going to claim a category and I'm not going to mention anybody's breach. One question instead: how many alerts hit your queue last week and how many turned into incidents? If that ratio is worse than about a hundred to one, you've got a triage problem, not a detection problem, and triage is the only thing I do. If your ratio is fine, I'll hang up — I mean that.
Buyer
It's not a hundred to one. But that's what the MDR is for. Deepwatch takes first pass, they escalate maybe thirty a day to us. So the volume you're describing isn't landing on my analysts.
Rep
Understood — and that's the version I'd expect. Two things I'd ask about that. First, you're paying Deepwatch on the volume they have to look at, and that volume grows every time you onboard a log source. Second, of the thirty they escalate, how many does your Tier-1 close as benign inside five minutes?
Buyer
...Most of them. Honestly. It's the same handful of patterns — service accounts, the VPN geo thing, our scanner tripping its own rules. We keep meaning to push tuning back at them and it keeps not happening.
Rep
That's the exact thing. We sit at the ingest point, in front of the MDR, and collapse duplicates and known-benign into one item before anyone's billed to look at it or paid to read it. And nothing gets deleted — everything stays queryable and retained for your auditor, we just change what gets presented first.
Buyer
Here's my problem with that. If we suppress and we miss something, that's my name on the incident report. Nobody has ever been fired for reading too many alerts.
Rep
They get fired for dwell time, and reading eleven thousand alerts a day is how dwell time happens. But I'd hold the same line you're holding. So: you set the suppression rules, we auto-close nothing you haven't approved in writing, and the way we prove it is a replay — thirty days of alert metadata, no payloads, no PII, against incidents you already know the outcome of. If we skip one your team caught, that's a real answer and you've lost an afternoon.
Buyer
There's no agent in this? Because I'm not putting anything new on five thousand endpoints. The risk review alone is a quarter and my engineering manager will simply refuse.
Rep
No agent, no kernel driver, no golden image change. Read-only API against the SIEM you already ingest into. Your review is a data-handling review, not an endpoint deployment — usually a shorter form and a different reviewer.
Buyer
Fine. Send it through the portal and I'll flag it internally. That's genuinely more than I usually do.
Rep
Appreciated — going in today with the SOC 2 Type II, pen test summary, data flow diagram and subprocessor list so your GRC team isn't chasing. The review takes six weeks either way, so let's run it in parallel: 25 minutes with you and whoever owns your detection content, no demo, no deck. I'll bring the before-and-after alert volumes from a health system on a co-managed Splunk build about your size, including the two suppressions they made us reverse. Thursday 8:15 before your day starts, or Tuesday at 4?
Buyer
Thursday. Early. And bring the reversals, not just the wins — that's the only part I care about.
Rep
Sending the invite now while we're on. Can you confirm it landed? And should I put Dan from detection engineering on it, or do you want to forward it yourself?
Objections you will hear
What they say, and what you say back.
| Objection | How to answer it |
|---|---|
| “Every vendor says AI-powered zero trust. You've got ten seconds to be different.” | "Fair. I'm not going to claim a category. One question: how many alerts hit your queue last week, and how many became incidents? If that ratio is worse than about a hundred to one you have a triage problem, not a detection problem, and that's the only thing I do. If your ratio is fine, I'll hang up." |
| “Adding your agent to 5,000 endpoints? The risk review alone takes a quarter.” | "Agreed, and I'd fail that review too. There's no agent — we read from the SIEM you already ingest into, via API, read-only. No kernel driver, no change window, no image rebuild. Your security review becomes a data-handling review rather than an endpoint deployment, which is usually a different and much shorter form." |
| “We already have a SIEM, a SOAR, and an MDR. Where does this even sit?” | "In front of all three. Your SOAR runs playbooks on alerts after somebody decides they matter; your MDR bills you on the volume it has to look at. We sit at the ingest point and collapse duplicates and known-benign into one thing your analyst reads. Fastest way to know if that's real is a two-week replay against last month's alerts — no production change." |
| “Send me a SOC 2 Type II, a pen test report, and fill out our TPRM questionnaire, then we'll talk.” | "Sending all three today, plus the data flow diagram and subprocessor list so your GRC team doesn't have to chase. While that's in the queue — can we do 30 minutes with whoever owns your detection content? The security review takes six weeks either way; I'd rather it run in parallel with the people who'd actually use this." |
| “We're not buying anything until Q3. Budget's committed.” | "Understood, I'm not asking for budget. What I want is to be the thing you've already validated when Q3 arrives, instead of starting from a cold POC in August. Quick one — what's the ingest number your SIEM renewal is priced on, GB per day? If alert volume drops the way it does elsewhere, that renewal conversation changes, and that's usually a different budget line than mine." |
| “Prove it in our environment. Everyone's demo looks great on their own data.” | "That's the only proof I'd trust either. Give us a 30-day export of alert metadata — no payloads, no PII — and we'll show you what your analysts would have skipped and what they'd have surfaced, against incidents you already know the outcome of. If we miss one you caught, that's a real answer and you've lost an afternoon." |
| “If we cut alerts and miss something, that's my job. Nobody gets fired for reading too many alerts.” | "They get fired for dwell time, and reading twelve thousand alerts is how dwell time happens. Nothing gets deleted — everything stays queryable and retained for the auditor, we just change what's presented first. And you set the suppression rules; we don't auto-close anything you haven't approved in writing." |
| “I'm not interested.” | "Totally fair, you don't know what I do yet. If I'm wrong I'll hang up — is the Friday queue bulk-close a thing at your shop, or have you genuinely got the alert-to-incident ratio where you want it?" |
Questions reps ask about this call
- What should the first line of a cybersecurity cold call script actually be?
Name, company, and an admission that it's a cold call: "Priya, it's Sam at Corvid. We've never spoken, this is a cold call — thirty seconds and then tell me to get lost?" Security buyers are professionally suspicious; the fastest way to stop them trying to place you is to tell them there's nothing to place. Then pause two full seconds. Do not open with "how are you today," do not open with "did I catch you at a bad time," and never open with a breach in their sector — SOC leaders find ambulance-chasing openers genuinely offensive and will remember your company name for the wrong reason.
- Should I cold call the CISO or the SOC manager?
Depends on the problem you lead with. If your one problem is triage volume, analyst attrition or alert-to-incident ratio, call the Director of Security Operations or SOC Manager — they live in the queue and can describe their Friday afternoon to you unprompted. If it's coverage evidence, the ransomware board slide, or insurance questionnaire numbers, that's a CISO or VP of Security Operations conversation. Repeat audit findings on privileged access review and log retention belong to the Director of GRC & Compliance. In mid-market accounts with no dedicated CISO, the security-owning IT Director holds all three, and is often the easiest to reach because nobody has built a wall around them yet.
- How do I get past "submit it to our third-party risk portal"?
Don't fight it — agree to it and then ask for a parallel track. "Submitting today with the SOC 2 Type II, pen test summary, data flow diagram and subprocessor list so your GRC team isn't chasing. The review takes six weeks either way — can we run 25 minutes with your detection lead in parallel?" The portal is a real process, not a brush-off, but on its own it produces a submission nobody reads. You need a human inside who has a reason to look for your name in the queue.
- What triggers are worth calling on in security?
Open SOC analyst or detection engineering reqs aged past 90 days (tells you the shift is thin and the queue is heavy). A new CISO inside six months (they've just finished counting tools and can't get a coverage number). A publicly disclosed SIEM or EDR migration. An acquisition that just doubled the estate. A compliance regime change that pulls a new framework into scope. If you have no trigger, use the segment: "every four-to-eight-analyst SOC on a co-managed SIEM we talk to is dealing with the same three noisy rules." That's honest and it's still specific.
- How many discovery questions should I ask on a security cold call?
Two. Narrow and factual only — "roughly how many alerts hit the queue a shift, and how many become incidents?" and "is your SIEM priced on GB per day, and are you near the cap?" Do not ask about their top three priorities, their MITRE ATT&CK coverage percentage, their decision process or their budget. You haven't earned those answers, they'll be shallow, and asking them burns the entire reason to hold a second meeting. The moment you hear an admission — "honestly, it's a mess," "don't ask me about our Okta logs" — stop asking and ask for the calendar slot.
- What's the right meeting ask at the end of a cybersecurity cold call?
Twenty-five minutes, explicitly not a demo, with a named second attendee and two specific times. "25 minutes, no deck — I'll walk your detection lead through what we collapsed at a SOC your size and, more usefully, the two suppressions they made us reverse. Thursday 8:15 or Tuesday 4?" Naming what you'll get wrong is disproportionately effective with security buyers, who assume every vendor is hiding the miss rate. Then send the invite while they're still on the line and get verbal confirmation it landed.