Cybersecurity · Manager Coaching Call

Sales Coaching Roleplay for Cybersecurity Teams: The Two-Quarter Miss Conversation

This is the 1:1 nobody sleeps well before. Your rep sells alert triage into SOCs. They've missed two quarters — not spectacularly, just consistently — and they're walking in with the excuses already loaded: the leads are all IT Directors at 200-person companies with no SOC, every account already has an MDR and a SOAR, and three deals died in third-party risk review because you're not FedRAMP. Some of that is genuinely true, which is exactly what makes this hard.

Underneath it, two things are almost certainly happening. Their discovery is thin — they hear "our tier-1 queue is a mess" and go straight to the dedupe demo instead of asking what the alert-to-incident ratio actually is, what dwell time was on the last confirmed incident, and what the SIEM licence is priced at per GB per day. And they stopped prospecting somewhere around week three of last quarter, when they got busy "working" two deals that were never going to close. They will not volunteer either one. You'll only get there if you stay curious longer than they expect, argue about numbers instead of feelings, and make it obvious that admitting the real problem is safer than defending the fake one.

A note on labels: in the dialogue below, Rep is you, the sales manager running the coaching call. Buyer is the rep you're coaching — because in this conversation, they're the one you have to earn agreement from. Your job is not to win the argument, deliver a speech, or say the letters P-I-P in the first ten minutes. It's one true root cause and one changed behaviour they actually agreed to.

The manager coaching call script

Say it in your own words. The structure is the part that matters.

  1. 1

    Before you open your mouth: pull the tape

    Do not walk into this with a feeling. Walk in with six things: 1. **New opps created per week, last 90 days.** If it reads 7 in month one, 4 in month two, 2 in month three, that graph is the entire conversation and you don't need to say much else. 2. **Pipeline coverage against next quarter.** 1.6x is a different call than 4x with terrible conversion. 3. **Stage conversion vs. team median.** In this business the two that matter are first-call-to-technical-session (do they earn time with the Head of Detection Engineering or the detection content owner?) and technical-session-to-replay/POV (do they convert curiosity into a 30-day alert metadata export?). 4. **Closed-lost reasons, counted.** Split "price" from "no decision" from "security review stalled." Then check how many of the losses had a documented number in the pain field — alerts per analyst per shift, GB/day ingest, MTTD. Usually near zero, and that's your case. 5. **Lead-to-meeting rate against a peer on the same source.** This is how you find out whether "the leads are garbage" is real. If they're booking meetings off the same list at the same rate as Priya, the leads are fine and the floor drops out after first call. 6. **Two recordings, timestamped.** One won, one lost. You will play 90 seconds of one of them.

  2. 2

    Open: name the stakes, don't swing the hammer

    Two sentences. No warm-up. They know why they're here. "Two quarters is a pattern, not bad luck, and I'm not going to pretend otherwise. But I didn't book this to read you your numbers — you know your numbers. I want to work out what's actually going wrong, because I think it's one thing and not five, and I genuinely don't know yet which one. Fair?" Do not open with 'how's your week been.' The false warmth reads as a setup and they'll lock down before you've asked anything real.

  3. 3

    Drain the tank: every excuse, before you touch any of them

    This is the step managers skip and it decides the call. Rebut the first grievance and you'll spend thirty minutes litigating lead quality and never hear the fourth one — which is always the closest to the truth. "Before I say a word, give me the whole picture. What's making this hard right now? All of it — not the diplomatic version." Then after each one: **"What else?"** Three times minimum. Write the list where they can see you writing it. In this market it usually comes out as: the MQLs are IT Directors at companies with four people in IT and no SOC; every real account already has a SIEM, a SOAR and an MDR so there's no room; two deals sat in TPRM for eleven weeks; we're not FedRAMP so public sector is dead; the SE couldn't get the replay environment stood up for Caldera. Read it back flat, no editorial: "So — lead fit, incumbent stack, TPRM cycle time, no FedRAMP, SE coverage. That's the list? Nothing else?" Getting them to confirm the list is complete closes the escape hatches you'll need closed in twenty minutes.

  4. 4

    Sort the list: real, partly real, story

    Take each one completely seriously, then put it next to the data. On leads: "Let's do leads first, because if that's broken I need to go fight for a different segment and I'd rather know today. You got 38 MQLs last quarter. Priya got 35 off the same two campaigns. She booked 14 first calls, you booked 13 — so you're converting leads to meetings at basically the same rate she is. Where it splits is after that. She moved 8 of 14 to a technical session with the detection content owner. You moved 3 of 13. Help me understand that gap." Then stop talking. Ten seconds of silence here is worth more than anything you'd say into it. On price and no-decision: "Eleven losses. Four said price, seven said no decision or stalled in security review. Of those eleven — how many had a number in the pain field? Not 'they have alert fatigue.' A number. Alerts per analyst per shift. Alert-to-incident ratio. GB per day on the SIEM licence and what the renewal's priced at. Walk me through Wexler. What did the VP of Security Operations tell you their ratio was?" When they can't answer, do not say 'exactly, that's the problem.' Say: **"Okay. What do you make of that?"** And concede the true one out loud. "TPRM is real. Both Wexler and Caldera sat in third-party risk for over two months and I watched it happen. That's a legitimate headwind and I'm not going to pretend it isn't — and it's also why I want the security review running in parallel from week one instead of after the technical win." Conceding the true grievance is what buys you the right to press the others.

  5. 5

    Make it safe to say the real thing

    They know their discovery is shallow and they know they stopped dialling. What stops them saying it is the belief that saying it converts a bad quarter into a documented file. "Let me say the thing that's sitting between us. I'm not building a file right now. If the honest answer is 'I got two big logos in the pipe in week three and quietly stopped prospecting' — that's fixable, I've fixed it with reps before, and it's a much better Monday than the version where nothing is in your control. Because in that version neither of us has anything to do." Then the two questions that usually crack it: "If I handed you 40 perfect leads tomorrow — Directors of Security Operations at 5,000-endpoint shops with a SIEM they're already over-ingesting on — do you hit the number?" The hesitation is the admission. Follow it: "What's the part of this you'd fix if nobody was watching and there was no consequence?" Or take the direct route: "Walk me through the last three weeks of Q3. What did a Tuesday morning look like?" Reps who've stopped prospecting cannot describe a Tuesday. They describe deals.

  6. 6

    Go to the tape: a moment, not a theme

    'Your discovery needs work' is a horoscope. Play 90 seconds. "This is minute nine of the Wexler first call. Their Director of Security Operations says — and I'm quoting — 'we're four analysts against about twelve thousand alerts a day and we bulk-close the queue Friday afternoon.' Listen to what you do next." [Play it.] "You said 'that's exactly what we solve' and opened the dedupe screen. What were the three questions you didn't ask?" Let them name the misses. If they can name them — what's your alert-to-incident ratio, what was dwell time on the last confirmed incident, what's your ingest priced at per GB per day and when's the renewal — this is an execution problem. They know the move and aren't making it, usually because they're rushing to prove value before the prospect writes them off as another AI-powered-zero-trust vendor. If they genuinely cannot name them, it's a skill gap and your plan is training, not coaching. That distinction changes everything you do next. Don't skip it.

  7. 7

    Land on one root cause and say it plainly

    You will be tempted to fix five things. Fix one. "Here's where I've landed. TPRM cycle time is real and I'm going to do something about it. But the thing actually killing you is that you're demoing at minute nine instead of finding out what the queue costs them — so every deal turns into a feature comparison against their existing SOAR, and the CISO has no number to take to a budget conversation, so it dies as no-decision. And because you're only creating two opps a week, you can't afford to disqualify anything, so you keep polishing deals that were never real. Does that match what you see?" Ask for agreement. If they push back with a real argument, listen — you might be wrong. If they push back with a sixth excuse, name it: "That's a new one. We agreed the list was five. I think you're looking for a reason this isn't about the calls."

  8. 8

    Let them write the plan, then make it measurable

    "Given all that — what do you want to change first?" Whatever they say, convert it into something you can both check on Friday: - "Prospect more" → "Two hours Tuesday and Thursday, 8 to 10, calendar-blocked, five new opps a week, and the target list is Directors of Security Operations and SOC Managers at 3,000+ endpoint shops — not IT Directors at 200-seat companies." - "Better discovery" → "No product on a first call for three weeks. If they push, you say: 'I'd rather show you the two screens that matter than all forty — give me ten more minutes of questions first.'" - "Quantify impact" → "Nothing advances past stage 2 without three numbers in the pain field: alerts per analyst per shift, alert-to-incident ratio, and GB/day with the renewal date." Then your half, out loud: "I'll sit in on your first two discovery calls this week and debrief straight after. And I'll get legal to pre-package the SOC 2 Type II, the pen test summary, the data flow diagram and the subprocessor list so you can send all of it the day TPRM comes up instead of two weeks later." A plan that only assigns work to the rep reads as a warning, not a partnership.

  9. 9

    Close with the standard, not a pep talk

    "So: two hours Tuesday and Thursday, no product on first calls for three weeks, three numbers in the pain field before anything moves to stage 2. I'm on your Caldera call Wednesday. We meet Friday at four and look at opps created — opps, not deals. And to be straight with you: a third quarter like the last two changes this conversation. I don't think that's where we're going, but I'd be doing you a disservice not saying it once." Then: **"What did you hear me commit to?"** Their summary tells you whether any of it landed. Do not finish with 'you've got this' — it tells them the last thirty minutes were theatre.

  10. 10

    If they never admit anything

    Some versions of this call end with the rep still holding the line on lead fit and FedRAMP. Don't force a confession; you'll get a fake one. "Alright. We disagree on cause. Let's test it. Three weeks, no product on first calls, five new opps a week off the SOC-manager list. If the leads are the problem, nothing changes and I'll take that fight to marketing myself. If something does change, we know what we're dealing with. Either way we know more in three weeks than we do right now." That turns a stalemate into data and gives you a clean decision point without wrecking the relationship.

How the call actually sounds

Prospect on the left, the rep on the right.

  1. Rep

    Two quarters is a pattern, not bad luck, and I'm not going to pretend otherwise. But I didn't book this to read your numbers back to you — you know them. I want to work out what's actually going wrong, because I think it's one thing and not five, and I don't know yet which one. Fair?

  2. Buyer

    Fair. I'll save you some time though — it's the list. Half my MQLs are IT Directors at companies with four people in IT and no SOC at all. They don't have a tier-1 queue, they've got a guy called Dave who checks the Defender console on Tuesdays. And the ones that do have a real SOC already have a SIEM, a SOAR and an MDR. There's no room.

  3. Rep

    Okay. What else?

  4. Buyer

    TPRM. Wexler sat in third-party risk for eleven weeks. Caldera's GRC director wanted SOC 2 Type II, a pen test report, our data flow diagram and a 200-line questionnaire before I could even get a second technical call. And we're not FedRAMP, so anything public sector or defence-adjacent is dead on arrival.

  5. Rep

    What else?

  6. Buyer

    Honestly? Positioning. Every single CISO I get on the phone has heard 'AI-powered' from nine vendors that week. One of them literally said 'you've got ten seconds to be different' and I don't think the deck helps me there. And I lost two named accounts to the enterprise team in the carve-up.

  7. Rep

    So: lead fit, incumbent stack, TPRM cycle time, no FedRAMP, positioning against the AI noise, and the carve-up. That's the list? Nothing else?

  8. Buyer

    That's the list.

  9. Rep

    Let me give you the two that are real before I push on anything. The carve-up is real — you lost two accounts that were about a fifth of your historical pipeline and I'm not going to pretend that's nothing. And TPRM is real; I watched Wexler sit in risk review for a quarter. That's on us as a company as much as you. Now let's do leads, because if that's broken I need to go fight for a different segment. You got 38 MQLs last quarter. Priya got 35 off the same two campaigns. She booked 14 first calls, you booked 13. So lead-to-meeting, you're identical. Where it splits is after: she moved 8 of 14 into a technical session with whoever owns their detection content. You moved 3 of 13. Help me understand that gap.

  10. Buyer

    …Her accounts are bigger. And she's got a dedicated SE, I've been sharing one since June.

  11. Rep

    Maybe. Let me put another number next to it. Eleven losses. Four said price, seven said no decision or stalled in security review. Of all eleven — how many had a number in the pain field? Not 'they have alert fatigue.' An actual figure. Alerts per analyst per shift. Alert-to-incident ratio. GB per day on their SIEM licence and when the renewal lands. I counted one.

  12. Buyer

    You can't always get that on a first call. A VP of Security Operations isn't going to hand a stranger their ingest volume and their dwell time in the first fifteen minutes. That's basically telling you where the gaps are.

  13. Rep

    Sometimes true. Let's listen to one. This is minute nine of Wexler. Their Director of Security Operations says — quoting — 'four analysts, about twelve thousand alerts a day, we bulk-close the queue Friday afternoon to get it back to zero.' Listen to what you do next. [plays] You said 'that's exactly what we solve' and opened the dedupe screen. What were the three questions you didn't ask?

  14. Buyer

    …Alert-to-incident ratio. What their MTTD looked like on the last confirmed incident. And whether the Friday bulk-close had ever buried something — which he was about half a sentence from telling me, actually.

  15. Rep

    Okay. What do you make of that?

  16. Buyer

    That I'm scared of the ten seconds. Every one of these people has been pitched to death and I think if I don't show something concrete fast, they write me off as another AI-powered zero trust vendor. So I go to the screen. And then it's a feature argument against their SOAR and I lose.

  17. Rep

    That's the most useful thing either of us has said. Second question, and I'm not building a file here: if I handed you 40 perfect leads tomorrow — Directors of Security Operations and SOC managers at 3,000-plus endpoint shops who are already over their ingest cap — do you hit the number?

  18. Buyer

    Not this quarter, no. There's nothing behind the two deals I've got. I stopped calling around week three when Caldera and Wexler both got warm. I told myself I was working them.

  19. Rep

    Right. So here's where I've landed. The carve-up cost you pipeline and TPRM is genuinely slow — I'll go pre-package SOC 2, the pen test summary, the data flow diagram and the subprocessor list so you can fire all of it the day it comes up. But the thing killing you is that you're going to product at minute nine instead of getting the ratio and the GB/day number, so the CISO never gets a figure they can take into a budget conversation and it dies as no-decision. And at two new opps a week you can't afford to disqualify anything, which makes the discovery worse. Does that match what you see?

  20. Buyer

    Yeah. It does.

  21. Rep

    Then you tell me — what do you change first?

  22. Buyer

    No product on first calls. Three weeks. And I'll block Tuesday and Thursday mornings for prospecting — SOC managers and Directors of SecOps, not IT Directors at 200-seat shops. Five new opps a week.

  23. Rep

    Done. Add this: nothing moves past stage 2 without three numbers in the pain field — alerts per analyst per shift, alert-to-incident ratio, and GB/day with the renewal date. I'm on your Caldera call Wednesday and we debrief straight after. Friday at four we look at opps created, not deals. And to be straight with you once: a third quarter like the last two changes this conversation. I don't think that's where we're going. What did you hear me commit to?

Objections you will hear

What they say, and what you say back.

ObjectionHow to answer it
"The leads are unqualified — half of them are IT Directors with no SOC at all."Concede the segment problem if it's real, then show the split. "You and Priya converted the same list to meetings at the same rate — 13 of 38 versus 14 of 35. If the leads were the problem, that number would be different, not the one after it. Where you diverge is first-call to technical session: 3 of 13 against 8 of 14." Then fix the real part out loud: reset the target profile to Directors of Security Operations and SOC managers at 3,000+ endpoint shops that are already over their ingest cap, so they can't use fit as cover for the next three weeks.
"Every account already has a SIEM, a SOAR and an MDR. There's no room."That's a positioning gap you can fix in ten minutes, and it's worth roleplaying on the spot. "Say it to me as if I'm the VP of SecOps." The answer is: we sit in front of all three. The SOAR runs playbooks on alerts after somebody has already decided they matter. The MDR bills on the volume it has to look at. We sit at the ingest point and collapse duplicates and known-benign into one thing the analyst reads. Fastest way to know if it's real is a two-week replay against last month's alerts, no production change. Make the rep say that sentence three times before they leave the room.
"Deals die in third-party risk. Wexler sat in TPRM for eleven weeks."Half real, half a sequencing failure — say both. "The cycle is real and I'll get the SOC 2 Type II, pen test summary, data flow diagram and subprocessor list pre-packaged so you can send all four the hour it comes up. What isn't real is waiting for the technical win before you start it. The review takes six weeks either way. Your line is: 'sending all three today plus the data flow diagram so your GRC team doesn't have to chase — meanwhile can we get 30 minutes with whoever owns your detection content, in parallel?'"
"They all say the same thing — you've got ten seconds to be different, every vendor says AI-powered zero trust."Don't sympathise, drill it. "Good, that's a gift, because it invites a question instead of a claim. Try: 'Fair. I'm not going to claim a category. One question — how many alerts hit your queue last week and how many became incidents? If that ratio's worse than about a hundred to one you have a triage problem, not a detection problem, and that's the only thing I do. If your ratio's fine I'll hang up.' You've just made them tell you their alert-to-incident ratio in the first thirty seconds. That's discovery, not a pitch."
"They're not buying until Q3 — budget's committed, so there's nothing to work."This is how a rep justifies not prospecting. "Two things. One, a stalled account is not a reason to stop creating new ones — you went from seven opps in month one to two in month three and that's the whole graph. Two, 'no budget until Q3' is a question you didn't ask. What's the ingest number their SIEM renewal is priced on, and when does it land? If we cut alert volume the way we do elsewhere, that renewal conversation changes — and that's a different budget line from yours."
"I know, I know — I need to prospect more." (arriving at minute six, before any number has been discussed)Don't accept it. That's a rep managing you out of the room, and the tell is that it arrived before you'd shown them a single figure. "I'll take that, but not yet — because if that's the answer we'd have got there after looking at something. Let's look at the Wexler recording first, and then tell me if prospecting is still the top of the list." A fast flat admission gets complied with for eleven days; one they reach after hearing themselves demo at minute nine sticks.

Questions reps ask about this call

Why use a sales coaching roleplay for cybersecurity teams instead of just reviewing the pipeline?

Pipeline review tells you a deal stalled. It doesn't tell you that the rep heard 'four analysts, twelve thousand alerts a day' and went straight to the dedupe screen instead of asking for the alert-to-incident ratio and the GB/day the SIEM licence is priced on. Roleplay surfaces the moment. It also lets a manager rehearse the coaching conversation itself — the drain-the-excuses sequence, the concession, the silence after the number — before doing it live on a rep who's already braced for a PIP.

What should I have in front of me before running this call?

Six things: new opps created per week for the last 90 days; pipeline coverage against next quarter; first-call-to-technical-session conversion against team median; closed-lost reasons split into price, no-decision and stalled-in-security-review; lead-to-meeting rate against a peer on the same campaign source; and two timestamped recordings, one won and one lost. If you can't show a rep a number they can't argue with, you'll spend forty minutes debating whether the MQLs are any good.

How do I tell a skill problem from an effort problem in a cybersecurity rep?

Play 90 seconds of a first call and ask which three questions they skipped. If they can name them — ratio, MTTD on the last confirmed incident, ingest volume and renewal date — they know the move and aren't making it. That's execution, usually driven by fear of being written off as another AI-powered vendor in the first ten seconds, and you fix it with a no-product-on-first-calls rule. If they genuinely cannot name the missed questions, it's a skill gap and you're running training, not coaching. Effort shows up separately, in the opps-per-week graph.

The rep's excuses are partly true — TPRM really is slow and we really aren't FedRAMP. How do I handle that?

Say the true one out loud, early, and without hedging. "TPRM is real, I watched Wexler sit in risk review for eleven weeks, and I'm going to pre-package SOC 2 Type II, the pen test summary, the data flow diagram and the subprocessor list." Conceding the genuine grievance is what buys you the right to press the ones that aren't. A rep who feels heard on one point stops defending all five. And in this market there's almost always a real one — the security review genuinely does take six weeks.

What if the rep never admits anything?

Don't force a confession, you'll get a fake one. Convert the disagreement into an experiment: three weeks of no-product first calls, five new opps a week off a corrected target list of Directors of Security Operations and SOC managers, three numbers required in the pain field before stage 2. If nothing changes, you take the segment fight to marketing yourself. If it does change, you both know what you're dealing with. That keeps the relationship intact and gives you a clean decision point in 21 days.

Which metrics should end up in the rep's discovery, not just in my coaching?

Make three non-negotiable before an opp advances: alerts per analyst per shift, alert-to-incident ratio, and SIEM ingest in GB/day with the renewal date. Those three turn a feature comparison against an incumbent SOAR into a budget conversation a CISO can carry. Secondary ones worth training: dwell time on the last confirmed incident, MTTD/MTTR, EDR and log-source coverage as a percentage of known assets, and SOC analyst attrition with the age of any unfilled req. A Director of GRC & Compliance will also give you repeat audit findings if you ask — that's a second door into the same account.