Cybersecurity · Renewal Call

Cybersecurity Renewal Call Script: Saving a SOC Account That's Already Half Gone

This is a cybersecurity renewal call script for the call nobody wants: contract ends in six weeks, your alert-triage layer only ever got turned on in one SOC, your API connector broke during their SIEM upgrade and stayed broken for eleven days, and a competitor rep has been in the Director of Security Operations' inbox with a number roughly 25% under yours. They took the meeting. That's not interest — that's them wanting to say out loud what went wrong before they leave.

Security buyers are a specific kind of unforgiving here. A SOC Manager whose analysts spent eleven days triaging raw, uncollapsed alerts through a live credential-stuffing investigation does not want a QBR deck. A CISO who had to sit in front of an audit committee and explain a repeat finding does not want a discount. And a Head of Detection Engineering who built 200-plus suppression rules on your platform will quietly tell his boss the migration is "not that bad" if you spend this call defending yourself. The only thing that moves this room is you naming the ticket numbers, the outage dates, and the adoption gap before they do — and then shutting up for fifteen minutes.

The structure below assumes you did the autopsy. Lead with the order form or "so what would it take to get this done" and you confirm every suspicion they have that you only show up when money is due. Lead with what broke on your side, what changed structurally, and a 90-day plan with named owners on both sides, and the same Director of SecOps starts negotiating with you instead of against you. Price is the last five minutes.

The renewal call script

Say it in your own words. The structure is the part that matters.

  1. 1

    Before you dial: the renewal autopsy

    Do not walk into this call with a usage summary. Walk in with a timeline. Have these on one page, in front of you, with numbers: - **Every ticket over 48 hours to first touch.** ID, open date, first response, resolution, and what was happening in their environment that week. Know your three worst by number. - **Connector / integration health history.** Every drop, every gap in enrichment, how long it ran broken, and who noticed first — you or them. If they told you, that's the whole call. - **Weekly active by team, not by company.** "NA SOC 91%, EU shift 0 of 14 seats, detection engineering 2 logins since July." - **Their outcome metrics where you run vs where you don't.** Alert-to-incident ratio, alerts per analyst per shift, MTTD on confirmed incidents. Segmented by SOC, because the gap is your argument. - **CSM/AE churn on your side.** Two CSMs in fourteen months is your fault. Name it before they do. - **Every commitment made in a QBR and never delivered** — the SOAR write-back, the enablement session you rescheduled twice, the MITRE coverage mapping you promised in the January review. - **Their org changes.** Did the CISO who signed leave? Is there a new Director of GRC & Compliance who's about to re-run your third-party risk questionnaire from scratch? **Clear your remedies internally before the call.** Written confirmation from Support leadership on the named engineer and the P1 SLA. Written confirmation from your CS lead on how many enablement hours you can commit to their EU shift. A second broken promise ends this account permanently and it will be attributed to you personally. **Know your floor** on price, term and seat count before you dial. Concessions you invent reactively feel like guilt money.

  2. 2

    Opening: name it before they have to (first 90 seconds, you go first)

    "[Priya] — thanks for the thirty minutes. Contract's up [date], I know that. I'm not opening with the order form and I'm not going to ask how things have been going, because I've read the year. Here's what I can see from my side, and I'd rather say it than have you say it. One — our read-only connector into your SIEM broke when you cut over to 9.1 on April 3rd. It stayed broken eleven days. Your tier-1 was triaging raw, uncollapsed alerts through the back half of that credential-stuffing investigation. We didn't catch it. Your analyst did, and he had to open a ticket to tell us. Two — that ticket, [41-882], opened April 9th, nine days to a substantive response. Two more in that window over 48 hours to first touch. Three — adoption. Your North America SOC is at 91% weekly active. Your EU shift has never logged in: fourteen named seats, zero. Detection engineering got one enablement session that we rescheduled twice and then never ran. Four — you've had two CSMs in fourteen months and nobody on my side ran a QBR after March. That's my list. What am I missing — and what did it actually cost you? Not just queue time. Who did you have to explain this to?" **Then stop talking.** Do not fill the silence. The meeting is won in the four seconds after this.

  3. 3

    The listening phase: let it be worse than you thought (15+ minutes)

    No "but." No "to be fair." No defending a single ticket, including the ones where their team genuinely broke the integration themselves. You may be right and you will lose the renewal being right. Probes, in roughly this order: - "Take me through those eleven days. What did your tier-1 actually see in the queue?" - "Where did your alerts-per-analyst-per-shift land that fortnight?" - "Did anything get missed in that window, or is that still an open question internally?" *(Ask it. If the answer is yes, everything else on this call is decoration until you've heard it.)* - "Who raised it above you? Did this reach [CISO name]? Did it come up in a board or audit-committee pack?" - "You've got a SOC 2 cycle running — did any of this touch the evidence you had to produce?" - "When your detection engineer heard we'd gone quiet again in Q2, what did he say?" **Follow the emotional word.** They say "we were flying blind" — "tell me about those two weeks." They say "embarrassing" — "embarrassing in front of who?" **Write it down visibly, then read it back:** "So: the eleven-day connector outage and no proactive alerting from us, nine days on 41-882 in the middle of it, the EU shift that never got stood up, and you found out from your own analyst rather than from us. Anything else?" Ask "anything else?" twice.

  4. 4

    One apology, specific, no hedging

    "The eleven days is on us and I want to be precise about why. We had no synthetic health check on customer connectors — we monitored our own side of the API and assumed silence meant clean. Your SIEM upgrade changed an auth path and our pipeline just stopped receiving. We had no way to know and no alarm to tell us. That's an explanation, not an excuse. You pay us to reduce what your analysts read, and for eleven days we increased it while you were mid-investigation. And the nine days on 41-882 — Support was reorganising queues after we split by segment and your ticket sat behind enterprise escalations. You're on a 24-hour first-response SLA. We missed it eleven times last year. I'm not going to characterise that as anything other than a failure." One apology. Then move. Do not apologise again later in the call — repeat apologising reads as a negotiating posture.

  5. 5

    Proof of change: their data, not your company stat

    "I'm not going to tell you we're investing in support. Three things that are already true, and you can check all of them. One — since May 20th we push a synthetic alert through every customer pipeline on a fifteen-minute interval. If enrichment stops, our on-call gets paged, not yours. Your connector has dropped twice since June. Both under twenty minutes. Both times you got a note from us before your analyst noticed. You can pull those two emails. Two — your median first response since September 1st is 3.2 hours across nine tickets. Here's the list with IDs, I'll send it after this. Three — I had the team clear the three open tickets sitting in your queue last week. You'd have seen those close Thursday. I didn't mention it at the time because it shouldn't have needed mentioning. And one number I want you to sit with. In the NA SOC, where we're actually running, your alert-to-incident ratio last month was 41 to 1. In the EU shift, where we were never turned on, it's still north of 300 to 1, and their MTTD on the two confirmed incidents last quarter was more than double NA's. That gap is the reason to stay — and the fact that the gap still exists eleven months in is my failure, not yours." If nothing structural has changed, say so and change what you control instead: your own coverage, a named escalation path, an exec sponsor. Do not manufacture progress. They will check.

  6. 6

    Rebuild on what works — and find the person, not the feature

    "You said the suppression-review workflow is the one thing your team would actually miss. Walk me through it — who built it and what does it replace?" Then quantify it in their language, not yours: - "How many suppression rules is [Marcus] running now? How much of the tuning history sits in there?" - "Last SOC 2 cycle you had a repeat finding on evidence of alert review. Did the reviewer log we produce close that, or did it just make it faster to assemble?" - "If we went away Monday, whose Monday breaks?" That last name is your remaining champion and he is almost certainly not on this call. Get him on the next one. "Here's what I want to say plainly: the switching cost here isn't the licence fee. It's 200-odd suppression rules with fourteen months of tuning behind them, the true-positive labelling your detection engineer has been building against those rules, and the six weeks where your evidence trail for the auditor is split across two systems mid-cycle. I'm not saying that to scare you. I'm saying it because if you do leave, I'd rather you leave with your eyes open than find that out in week three of a migration."

  7. 7

    Handling the competitor (surface it yourself)

    "I'd assume [Competitor] has been in your inbox. I'd be surprised if they hadn't. What did you like about them?" Listen properly. Then find out how far it's actually gone — the answer changes your next four weeks: - "Have they run a replay against your last 30 days of alert metadata, or is this still a demo on their data?" - "Has your GRC team put them through the third-party risk questionnaire yet? Do you have their SOC 2 Type II and pen test in hand?" - "Has anyone scoped the migration — who rebuilds the suppression content and how long do you run both layers in parallel?" - "Is there pricing in writing with procurement, or a conversation?" **Never disparage them.** Reframe: "On price they're probably right and I'm not going to pretend otherwise. What I'd weigh it against: your TPRM review took us six weeks last time and your GRC director will run theirs from zero. Your NA SOC is at 91% weekly active on a workflow they'd have to relearn during your busiest quarter. And the honest risk — you'd be inheriting a new vendor's version of the same support problem, with none of the credit I now owe you." Do not touch price here. Matching before you've re-established value just tells them your list price was always fiction.

  8. 8

    The 90-day plan, built live, both sides named

    "Can we build the next ninety days on this call rather than me sending you a deck? Four fields on every line: what, who by name on both sides, by when, and what done looks like." Example lines — put their names in, out loud: 1. **EU shift stand-up.** Two enablement sessions for the 14 EU seats, run by [named CSM] in the weeks of the 14th and 21st. Done = 10 of 14 weekly active by day 60 and EU alert-to-incident ratio under 100:1 by day 90. 2. **Detection engineering session.** Half-day with [Marcus] and my solutions engineer, the one we rescheduled twice. Date on the calendar before we hang up. 3. **Connector health, contractual.** Synthetic check every 15 minutes, we notify you inside 30 minutes of any enrichment gap. Written into the order form with a service credit if we miss it. 4. **Support.** Named escalation engineer, direct number, 4-hour P1 first response, effective at signature. Cleared internally — I'm not inventing this on the call. 5. **Governance.** 30/60/90 reviews with a written report: alert-to-incident ratio by shift, alerts per analyst per shift, MTTD on confirmed incidents, and suppression-rule review evidence for your auditor. First one dated [date]. 6. **What I can't do.** The direct write-back into your SOAR case management is not on the roadmap before Q3. It's in the plan as a no so you don't have to ask me again in February. "What's yours? Because adoption failed partly because nobody on your side owned the EU rollout. I need a named shift lead, two hours of their analysts' time, and [CISO] saying out loud that the EU team is expected to use it. A plan where only the vendor has obligations is a wish list."

  9. 9

    Only now: the commercial conversation

    Earn the transition explicitly: **"If you're willing to say that plan is real, can I walk you through what renewal would look like?"** Structure before number: - "Right-sizing first. You're paying for 60 seats and using 34. I'd rather renew you at what you actually use than discount 60 seats you don't. That kills the shelfware conversation permanently and it's a bigger reduction on your invoice than the discount I could get approved." - "Term: I'll give you a break clause at six months tied to the EU adoption milestone in the plan. If we haven't hit 10 of 14 weekly active by day 90 and you want out at month six, you're out. I'd rather sign that than argue about it." - "For the eleven days and the SLA misses, service credits for Q2 — that's the honest instrument. A price cut isn't an apology and I don't want you reading it as one." - "If you want more on price than that, I'll trade for it: a two-year term, a reference call with [named prospect], or a case study on the EU rollout once it's live. Not for free — that would tell you I was overcharging you all year." **Never offer the discount as the apology.** It reframes a year of operational failure as a pricing dispute and resets your floor forever.

  10. 10

    Multi-thread and close — six weeks is tight

    "Before we finish, walk me through what actually happens between here and signature. Does this go to procurement? Does [Director of GRC] need to re-run the third-party risk questionnaire, or does last year's cover us? Is [CISO] signing or approving?" Then: - "I'd like [CISO] and [Marcus] in a 30-minute plan review, with my VP of Customer Success on the line. Not a sales meeting — she's going to say the same thing about the eleven days that I just did, and she's the person who owns whether the named engineer sticks." - "Does procurement already have [Competitor]'s quote? Since when?" *(Ask it directly. Most stalled renewals die in procurement, not in the SOC.)* - Book the next meeting on the call. Never "I'll follow up." **Temperature check, honestly:** "On a scale where 1 is you've already decided to leave and 10 is you're signing — where are we right now, and what specifically moves it up two?" Take the honest answer over the polite one. If they say 3, ask what a 6 looks like and write that down too. **Within 24 hours, send four things:** the written 90-day plan with names and dates; the ticket data and connector-drop timeline you referenced; the intro to the reference customer who had the same outage and stayed; and a one-page summary of what they told you went wrong, in their words. That last document does more work than any proposal you'll ever send.

How the call actually sounds

Prospect on the left, the rep on the right.

  1. Rep

    Priya, thanks for the thirty minutes. Contract's up on the 14th of next month and I'm not going to open with the order form. I want to talk about this year, because from where I'm sitting it wasn't the year we sold you. Our connector broke on your 9.1 cutover April 3rd and stayed broken eleven days — your tier-1 was reading raw uncollapsed alerts through the tail of the credential-stuffing investigation. Ticket 41-882, nine days to a substantive response. Your EU shift has never logged in, fourteen seats, zero. And you've had two CSMs in fourteen months. That's my list. What am I missing, and what did it cost you?

  2. Buyer

    You're missing that my analyst found it, not you. Devon opened that ticket at 11pm his time because the enrichment fields went empty and he thought he'd broken something. He spent two shifts thinking it was his tuning. And I'll be straight with you — procurement has had a quote from your competitor since the second week of October, and it's twenty-seven percent under what you're asking.

  3. Rep

    That he thought it was his own tuning is the part I hadn't heard, and it's worse than what I had written down. Tell me about those two shifts. What did the queue actually look like for him?

  4. Buyer

    It looked like it did before we bought you. Twelve thousand a day, three noisy rules doing most of it, four people. Alerts per analyst per shift went back over three thousand and we bulk-closed Friday afternoon to get to zero, which is exactly the behaviour we bought you to stop. And I don't actually know if we missed something in that window. That's an open question. I've got a purple team engagement in January that might answer it for me, and I'm not looking forward to it.

  5. Rep

    Then that's the thing I'd want to solve first, ahead of anything commercial. Who else knows it's an open question — did this get above you?

  6. Buyer

    Dave knows. Our CISO. He asked me in a leadership review why the thing we spent budget on to fix dwell time was the thing that added eleven days to it. I didn't have a good answer. And frankly the second half of the year our MDR provider has been telling us they now do alert consolidation natively as part of the co-managed tier we already pay for. So I've got a cheaper alternative on one side and a free one on the other.

  7. Rep

    Both of those are real and I'm not going to talk you out of either one. On the MDR — genuine question, because it changes what I'd propose. Are they consolidating at ingest before their analysts look, or are they collapsing after triage on their side and billing you the same volume? Because those are very different things for your GB-per-day number.

  8. Buyer

    I don't know yet. They've offered a scoping session. But here's my problem with you specifically. Even where you did work — NA — Marcus has built about two hundred suppression rules in your platform and he's now telling me he could write the same logic natively in our SIEM with enough time. So I'm paying you for something my detection engineer thinks he could rebuild.

  9. Rep

    He probably could. He's good. What I'd ask him is how long the tuning took to get from a 340-to-1 alert-to-incident ratio down to the 41-to-1 you were running last month in NA, and whether he wants to spend the next two quarters redoing it while he's also the only person who can write your new cloud detections. But I'd rather he answers that than me — is he on the next call?

  10. Buyer

    He can be. He'll be blunt with you. He's also the one who said your Q2 silence was the second time, not the first — apparently there was a stretch in January where a ticket sat five days and I never heard about it.

  11. Rep

    I'll take blunt. And you're right about January, it was 39-514, five days. I should have led with two silences, not one. Here's the only thing I'd put against that, and it's their data not mine: since May 20th we run a synthetic alert through your pipeline every fifteen minutes and page our on-call if enrichment stops. Your connector has dropped twice since June, both under twenty minutes, and both times you got a note from us before Devon noticed. Those two emails are in his inbox — I'd ask him to check rather than take my word for it.

  12. Buyer

    Fine. That's something. But the EU shift is the thing that actually annoys me, because I've been paying for fourteen seats that have never been used, all year, while EU is still running north of 300-to-1 and their MTTD is double NA's. That's just money I lit on fire, and it's the number Dave will ask about.

  13. Rep

    Then I'd rather fix it two ways. First, I'm not renewing you on 60 seats. I'll renew at actual usage and add the EU seats back only as they go live — that's a bigger cut to your invoice than any discount I could get signed off, and it means you never have that conversation with Dave again. Second, the EU stand-up goes in the plan with a name and a date on it: two sessions run by Anna, weeks of the 14th and 21st, done means 10 of 14 weekly active by day 60. And I'll put a break clause at month six tied to that milestone. If we miss it, you're out, no argument.

  14. Buyer

    You'd sign the break clause? Because everyone offers me a success plan and none of them attach a consequence to it.

  15. Rep

    I'd sign the break clause and the connector-notification SLA with a service credit attached, and I've already cleared both internally — I'm not inventing them on this call. What I need from your side in the plan is a named EU shift lead, two hours of their analysts' time, and Dave saying out loud that EU is expected to use it. Last year the plan only had my name on it, and that's part of why we're having this conversation. Can I get you, Dave and Marcus in a room for thirty minutes next week, with my VP of CS on the line to say the eleven-days part herself?

  16. Buyer

    Next Thursday afternoon. Bring the ticket timeline, not slides. And be ready for Marcus.

  17. Rep

    Thursday. Ticket timeline, connector-drop log, the plan with names in it, and the no on the SOAR write-back written down so nobody has to ask. Last thing, honestly — on a scale where 1 is you've already decided to leave, where are we right now?

  18. Buyer

    Four. It was a two when I joined this call. Get EU standing up and get Marcus comfortable and it's a seven.

Objections you will hear

What they say, and what you say back.

ObjectionHow to answer it
Your connector was down eleven days during a live investigation and we found it, not you. Why would I trust you during the next incident?You shouldn't trust the version of us that was running in April. Here's what's structurally different: since May 20th there's a synthetic alert through your pipeline every fifteen minutes and our on-call gets paged if enrichment stops. Two drops since June, both under twenty minutes, both notified to you before your analyst saw it — those emails are in Devon's inbox, don't take my word for it. And I'll put the notification window in the order form with a service credit attached, because a promise you can't invoice against is just a sentence.
Their quote is 27% lower and procurement's had it since October.On the number they're probably right, and I'm not going to match it — matching now would just tell you I was overcharging you all year. What I'll do instead is renew you at your actual seat count rather than the 60 you're paying for, which is a bigger cut than the discount I could get approved. On the comparison: your GRC team ran our third-party risk questionnaire over about six weeks last time and they'd start theirs from zero, Marcus rebuilds two hundred suppression rules and fourteen months of tuning history, and you run two triage layers in parallel through your Q1 purple team engagement. If you weigh all that and still choose them, that's a legitimate answer. I just don't want the licence line to be the only number in the comparison.
Our MDR says alert consolidation is now included in the co-managed tier we already pay for.Then get them to scope it, seriously — if it's real, it's real. The question I'd put to them: are they collapsing at ingest before their analysts look, or after triage on their side? Because if it's after, your GB-per-day and your billable volume don't change, and the consolidation is for their benefit, not your queue's. The other one worth asking is who owns the suppression rules — if they do, you've handed your detection content to the vendor you'd have to argue with the next time something gets suppressed that shouldn't have been.
My detection engineer says he could write this logic natively in the SIEM himself.He might be right, and I'd want him on the call to say it to me directly. What I'd ask him: how many months of tuning took NA from roughly 340-to-1 down to 41-to-1, and does he want to spend the next two quarters rebuilding that while he's also the only person writing your cloud detections and prepping for the January purple team? The build-versus-buy answer here isn't capability, it's what else stops if he's doing this. If he says he's got the room, I'll take that seriously.
You cost us money on shelfware. Fourteen EU seats never logged in once and I paid for all of them.You did, and that's on my side of the ledger, not yours — the EU rollout was a commitment in the January QBR that nobody on my side ever ran. Two things. Service credits for the unused EU seats, which is the honest instrument rather than a blanket discount. And renewal at real usage, with EU seats added back only as they actually go live. That kills the shelfware conversation permanently and it means when your CISO asks you what happened to those seats, the answer is on the invoice.
Our GRC director wants a fresh SOC 2 Type II, a current pen test summary and the whole TPRM questionnaire re-run before we re-sign. That's six weeks we don't have.Going over today, all three, plus the updated data flow diagram and subprocessor list — there's one new subprocessor since last year and I'd rather flag it than have her find it. Since we're an existing vendor, most GRC teams run a delta review rather than a full re-onboard; worth confirming with her which form this is, because that's the difference between six weeks and ten days. Either way I'd like the technical session with Marcus running in parallel rather than after, so the review isn't the thing that decides this by default.
If we scale you back to actual usage and something gets missed in the EU queue, that's my job on the line. Nobody gets fired for reading too many alerts.People get fired for dwell time, and EU sitting north of 300-to-1 with double NA's MTTD is how dwell time happens. Nothing is deleted or auto-closed — everything stays queryable and retained for your auditor, and the suppression rules are ones your team writes and approves in writing. We change what's presented first, not what exists. And if you want the safety net on paper, the 30/60/90 report includes every suppressed alert with the reviewer log, which is the same evidence that closed your repeat SOC 2 finding on alert review last cycle.

Questions reps ask about this call

How is a cybersecurity renewal call script different from a standard renewal script?

The buyers measure you on operational numbers they report upward — MTTD/MTTR, alert-to-incident ratio, alerts per analyst per shift, EDR and log-source coverage percentages. A generic renewal script asks about satisfaction; a security one arrives with the customer's own metrics segmented by team, plus the integration outage timeline. A Director of Security Operations will forgive a bad quarter. They will not forgive you not knowing your connector was down in their environment for eleven days.

How much of a 30-minute save call should be listening?

Forty to fifty percent, so fifteen minutes minimum. Your opening — the specific failures with ticket numbers and dates — should take about ninety seconds, then you hand them the floor and stop. The instant you say "so what we've done is" while they're still describing the damage, you've retroactively converted your acknowledgement into a sales technique, and a SOC Manager who spends their day spotting pattern deviations will catch it immediately.

Should I offer a discount if the customer had a genuinely bad year?

No. A price cut is not an apology and they will read it as one — it reframes a year of operational failure as a pricing dispute and permanently resets your floor. Service credits for the affected months are the honest instrument: specific, finite, and they don't touch your list price. The bigger and more credible reduction is usually right-sizing seats to actual usage, which also kills the shelfware objection for good.

The competitor is 25-30% cheaper. How do I compete without matching?

First find out how far it's gone — a demo is not a scoped migration and a conversation is not a quote in writing with procurement. Then reframe from licence price to total switching cost in their language: re-running the third-party risk questionnaire through their GRC team, rebuilding the suppression content and tuning history their detection engineer owns, running two triage layers in parallel, and the split evidence trail if the cutover lands mid SOC 2 cycle. Never disparage the competitor — ask what they liked, and mean it.

Who else needs to be on the call besides the person who signed last year?

Assume the signer's authority has changed. You want three people before signature: the CISO or VP of Security Operations as economic buyer, the Head of Detection Engineering or the power user who actually built something on your platform, and whoever in GRC & Compliance controls the vendor review. Most stalled security renewals die in procurement or third-party risk, not in the SOC — and the power user whose Monday breaks if you leave is usually the person who wasn't invited to the save call.

What should the 90-day plan contain to actually change the decision?

Four fields on every line: what, who by name on both sides, by when, and what "done" looks like in a metric they already track — for example "10 of 14 EU seats weekly active by day 60, EU alert-to-incident ratio under 100:1 by day 90." Include at least one thing you cannot do, written as a no. Include obligations for their side, because adoption failed partly because nobody there owned it. Then attach a commercial consequence — a break clause at six months or an SLA credit in the contract is worth more than any discount, because it proves you expect to be held to it.